VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4636 CVEsRSS

MAL-2026-11156None
2mo ago

Malicious code in vtranalytic (PyPI)

Malicious code in vtranalytic (PyPI)

▾ Sunlitvtranalytic · vtranalyticvia OSV
CVE-2026-54635High· 7.5
2mo ago

pytonapi has a Webhook Custom Path Authentication Bypass

pytonapi has a Webhook Custom Path Authentication Bypass

▾ Twilightpytonapi · pytonapiEPSS 0.71%via GHSA
CVE-2026-66053Medium· 5.9
2mo ago

Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit

Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit

▾ Sunlitthrift · thriftEPSS 0.29%via OSV
CVE-2026-43871High· 7.5
2mo ago

thrift: Apache Thrift: Denial of Service via infinite loop (CVE-2026-43871)

A flaw was found in Apache Thrift, affecting its Python, Go, PHP, and Java components. This vulnerability, known as an 'Infinite Loop', could allow a remote attacker to disrupt service availability. By exploiting this flaw, an attacker can…

▾ TwilightRed Hat · Red Hat Hardened ImagesEPSS 1.0%via CSAF
CVE-2026-41608High· 7.5
2mo ago

Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability

Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability

▾ Twilightthrift · thriftEPSS 1.0%via OSV
MAL-2026-11094None
2mo ago

Malicious code in cfgzen (PyPI)

Malicious code in cfgzen (PyPI)

▾ Sunlitcfgzen · cfgzenvia OSV
MAL-2026-11068None
2mo ago

Malicious code in random-ua-generator (PyPI)

Malicious code in random-ua-generator (PyPI)

▾ Sunlitrandom-ua-generator · random-ua-generatorvia OSV
MAL-2026-11067None
2mo ago

Malicious code in blessclient (PyPI)

Malicious code in blessclient (PyPI)

▾ Sunlitblessclient · blessclientvia OSV
CVE-2026-66007Medium· 6.5
2mo ago

datasets: Datasets: Information disclosure via path traversal vulnerability (CVE-2026-66007)

A flaw was found in datasets. This path traversal vulnerability allows a remote attacker to read arbitrary local files. By providing specially crafted file names in the metadata, an attacker can trick the system into including sensitive lo…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.79%via CSAF
CVE-2026-73622High· 7.5
2mo ago

GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)

GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)

▾ Twilightgitpython · gitpythonEPSS 0.51%via OSV
CVE-2025-71408High· 7.0
2mo ago

nltk: NLTK: Arbitrary Code Execution via Eval Injection in Collocations Module (CVE-2025-71408)

A flaw was found in NLTK (Natural Language Toolkit). This eval injection vulnerability in the `nltk.collocations` module allows a local attacker to execute arbitrary Python code. By manipulating command-line arguments when `collocations.py…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.27%via CSAF
MAL-2026-11051None
2mo ago

Malicious code in trongridy (PyPI)

Malicious code in trongridy (PyPI)

▾ Sunlittrongridy · trongridyvia OSV
MAL-2026-11050None
2mo ago

Malicious code in discordnv (PyPI)

Malicious code in discordnv (PyPI)

▾ Sunlitdiscordnv · discordnvvia OSV
GHSA-94p4-4cq8-9g67High· 7.5
2mo ago

GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)

GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)

▾ TwilightGitPython · GitPythonvia GHSA
GHSA-47w6-gwp4-w6vcHigh
2mo ago

vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review

vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review

▾ Twilightvantage6 · vantage6via GHSA
CVE-2026-16584High· 7.0
2mo ago

AWS API MCP Server Security Policy Bypass via Startup Initialization Failure

AWS API MCP Server Security Policy Bypass via Startup Initialization Failure

▾ Twilightawslabs.aws-api-mcp-server · awslabs.aws-api-mcp-serverEPSS 0.23%via GHSA
GHSA-hmj8-5xmh-5573High· 7.5
2mo ago

libp2p: yamux connection DoS via oversized data frame

libp2p: yamux connection DoS via oversized data frame

▾ Twilightlibp2p · libp2pvia GHSA
CVE-2026-16796High· 7.3
2mo ago

AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()

AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()

▾ Twilightbedrock-agentcore · bedrock-agentcoreEPSS 0.73%via GHSA
CVE-2026-59223Medium· 4.3
2mo ago

Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching

Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching

▾ Sunlitopen-webui · open-webuiEPSS 0.38%via GHSA
CVE-2026-59224High· 8.0
2mo ago

Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)

Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)

▾ Twilightopen-webui · open-webuiEPSS 0.39%via GHSA
CVE-2026-59212Medium· 5.4
2mo ago

Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete

Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete

▾ Sunlitopen-webui · open-webuiEPSS 0.42%via GHSA
CVE-2026-59225Medium· 5.4
2mo ago

Open WebUI: Arena task endpoints can bypass underlying model access controls

Open WebUI: Arena task endpoints can bypass underlying model access controls

▾ Sunlitopen-webui · open-webuiEPSS 0.37%via GHSA
CVE-2026-59221High· 7.7
2mo ago

open-webui terminal proxy path traversal guard bypass via 9x encoded traversal

open-webui terminal proxy path traversal guard bypass via 9x encoded traversal

▾ Twilightopen-webui · open-webuiEPSS 0.48%via GHSA
CVE-2026-55404High· 7.5
2mo ago

yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output

yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output

▾ Twilightyt-dlp · yt-dlpEPSS 0.64%via GHSA
MAL-2026-11049None
2mo ago

Malicious code in mrmustard (PyPI)

Malicious code in mrmustard (PyPI)

▾ Sunlitmrmustard · mrmustardvia OSV
MAL-2026-11048None
2mo ago

Malicious code in karpatkit (PyPI)

Malicious code in karpatkit (PyPI)

▾ Sunlitkarpatkit · karpatkitvia OSV
MAL-2026-11047None
2mo ago

Malicious code in karpatkey (PyPI)

Malicious code in karpatkey (PyPI)

▾ Sunlitkarpatkey · karpatkeyvia OSV
MAL-2026-11046None
2mo ago

Malicious code in intel-cicd-repo-infrastructure (PyPI)

Malicious code in intel-cicd-repo-infrastructure (PyPI)

▾ Sunlitintel-cicd-repo-infrastructure · intel-cicd-repo-infrastructurevia OSV
GHSA-fjr4-x663-mwxcHigh· 8.1
2mo ago

GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)

GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)

▾ TwilightGitPython · GitPythonvia GHSA
GHSA-6p8h-3wgx-97gfHigh· 7.5
2mo ago

GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks

GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks

▾ TwilightGitPython · GitPythonvia GHSA
CVEs tagged “pip” — page 28 · VulnSea