VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

MAL-2026-11201None
2mo ago

Malicious code in ml-nps-shared (PyPI)

Malicious code in ml-nps-shared (PyPI)

▾ Sunlitml-nps-shared · ml-nps-sharedvia OSV
MAL-2026-11200None
2mo ago

Malicious code in ml-fdbk-shared (PyPI)

Malicious code in ml-fdbk-shared (PyPI)

▾ Sunlitml-fdbk-shared · ml-fdbk-sharedvia OSV
MAL-2026-11199None
2mo ago

Malicious code in ml-data-shared (PyPI)

Malicious code in ml-data-shared (PyPI)

▾ Sunlitml-data-shared · ml-data-sharedvia OSV
MAL-2026-11198None
2mo ago

Malicious code in mcp-search-server (PyPI)

Malicious code in mcp-search-server (PyPI)

▾ Sunlitmcp-search-server · mcp-search-servervia OSV
MAL-2026-11197None
2mo ago

Malicious code in ai-perf-toolkit (PyPI)

Malicious code in ai-perf-toolkit (PyPI)

▾ Sunlitai-perf-toolkit · ai-perf-toolkitvia OSV
MAL-2026-11195None
2mo ago

Malicious code in phabricator-client (PyPI)

Malicious code in phabricator-client (PyPI)

▾ Sunlitphabricator-client · phabricator-clientvia OSV
CVE-2026-67435Medium
2mo ago

linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect

linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect

▾ Sunlitlinuxfabrik-lib · linuxfabrik-libEPSS 0.50%via GHSA
CVE-2026-67429Critical· 10.0
2mo ago

Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)

Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)

▾ Midnightflyto-core · flyto-coreEPSS 0.77%via GHSA
CVE-2026-67427High· 8.6
2mo ago

Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted

Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted

▾ Twilightflyto-core · flyto-coreEPSS 0.59%via GHSA
CVE-2026-67425High· 8.6
2mo ago

Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url

Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url

▾ Twilightflyto-core · flyto-coreEPSS 0.56%via GHSA
CVE-2026-67426Critical· 9.3
2mo ago

Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration

Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration

▾ Midnightflyto-core · flyto-coreEPSS 0.51%via GHSA
CVE-2026-67428High· 8.5
2mo ago

Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)

Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)

▾ Twilightflyto-core · flyto-coreEPSS 0.45%via GHSA
CVE-2026-67424High· 8.5
2mo ago

Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation

Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation

▾ Twilightflyto-core · flyto-coreEPSS 0.41%via GHSA
CVE-2026-13346Medium· 6.5
2mo ago

pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk e…

pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when installing wheels. This vulnerability requires downloading or installing a package from…

▾ Sunlitpip · pipEPSS 0.29%via OSV
GHSA-wchh-9x6h-7f6pMedium
2mo ago

olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193

olm dependency deprecation: CVE-2022-39255 and CVE-2024-45193

▾ Sunlitmatrix-commander · matrix-commandervia GHSA
CVE-2026-54574High· 8.2
2mo ago

`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive

`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive

▾ Twilightproot-distro · proot-distroEPSS 0.19%via GHSA
CVE-2026-54727High· 8.2
2mo ago

proot-distro has a Container Isolation Bypass via Crafted Restore Archive

proot-distro has a Container Isolation Bypass via Crafted Restore Archive

▾ Twilightproot-distro · proot-distroEPSS 0.18%via GHSA
CVE-2026-50558Medium· 5.9
2mo ago

Penelope Shell Handler is a post-exploitation shell handler for authorized security testing

Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix download() implementation in penelope.py used tar.extractall(local_download_folder) on tar archives returned by remote…

▾ Sunlitpenelope-shell-handler · penelope-shell-handlerEPSS 0.37%via NVD
CVE-2026-55415High· 7.5
2mo ago

datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements

datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.49%via OSV
CVE-2026-54690High· 8.2
2mo ago

datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)

datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.39%via OSV
CVE-2026-54656High· 7.8
2mo ago

`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data

`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.25%via GHSA
CVE-2026-55391High· 7.5
2mo ago

datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding

datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.30%via OSV
CVE-2026-54653High· 8.8
2mo ago

`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field

`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.71%via OSV
CVE-2026-55389High· 7.5
2mo ago

datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-…

datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.55%via OSV
CVE-2026-54654High· 7.8
2mo ago

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.21%via OSV
CVE-2026-55390High· 7.5
2mo ago

datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate

datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.53%via GHSA
CVE-2026-54691High· 8.2
2mo ago

datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects

datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.38%via OSV
CVE-2026-55403Low· 3.7
2mo ago

datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas

datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas

▾ Sunlitdatamodel-code-generator · datamodel-code-generatorEPSS 0.34%via OSV
CVE-2026-54655High· 7.8
2mo ago

`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator

`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.21%via GHSA
CVE-2026-54621High· 7.8
2mo ago

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.21%via OSV
CVEs tagged “pip” — page 27 · VulnSea