Tagged “pip”
CVEs tagged pip, newest first.
4636 CVEsRSS
MAL-2026-11156NoneMalicious code in vtranalytic (PyPI)
Malicious code in vtranalytic (PyPI)
CVE-2026-54635High· 7.5pytonapi has a Webhook Custom Path Authentication Bypass
pytonapi has a Webhook Custom Path Authentication Bypass
CVE-2026-66053Medium· 5.9Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit
Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit
CVE-2026-43871High· 7.5thrift: Apache Thrift: Denial of Service via infinite loop (CVE-2026-43871)
A flaw was found in Apache Thrift, affecting its Python, Go, PHP, and Java components. This vulnerability, known as an 'Infinite Loop', could allow a remote attacker to disrupt service availability. By exploiting this flaw, an attacker can…
CVE-2026-41608High· 7.5Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability
Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability
MAL-2026-11094NoneMalicious code in cfgzen (PyPI)
Malicious code in cfgzen (PyPI)
MAL-2026-11068NoneMalicious code in random-ua-generator (PyPI)
Malicious code in random-ua-generator (PyPI)
MAL-2026-11067NoneMalicious code in blessclient (PyPI)
Malicious code in blessclient (PyPI)
CVE-2026-66007Medium· 6.5datasets: Datasets: Information disclosure via path traversal vulnerability (CVE-2026-66007)
A flaw was found in datasets. This path traversal vulnerability allows a remote attacker to read arbitrary local files. By providing specially crafted file names in the metadata, an attacker can trick the system into including sensitive lo…
CVE-2026-73622High· 7.5GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
CVE-2025-71408High· 7.0nltk: NLTK: Arbitrary Code Execution via Eval Injection in Collocations Module (CVE-2025-71408)
A flaw was found in NLTK (Natural Language Toolkit). This eval injection vulnerability in the `nltk.collocations` module allows a local attacker to execute arbitrary Python code. By manipulating command-line arguments when `collocations.py…
MAL-2026-11051NoneMalicious code in trongridy (PyPI)
Malicious code in trongridy (PyPI)
MAL-2026-11050NoneMalicious code in discordnv (PyPI)
Malicious code in discordnv (PyPI)
GHSA-94p4-4cq8-9g67High· 7.5GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
GHSA-47w6-gwp4-w6vcHighvantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
CVE-2026-16584High· 7.0AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
GHSA-hmj8-5xmh-5573High· 7.5libp2p: yamux connection DoS via oversized data frame
libp2p: yamux connection DoS via oversized data frame
CVE-2026-16796High· 7.3AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
CVE-2026-59223Medium· 4.3Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
CVE-2026-59224High· 8.0Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
CVE-2026-59212Medium· 5.4Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
CVE-2026-59225Medium· 5.4Open WebUI: Arena task endpoints can bypass underlying model access controls
Open WebUI: Arena task endpoints can bypass underlying model access controls
CVE-2026-59221High· 7.7open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
CVE-2026-55404High· 7.5yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
MAL-2026-11049NoneMalicious code in mrmustard (PyPI)
Malicious code in mrmustard (PyPI)
MAL-2026-11048NoneMalicious code in karpatkit (PyPI)
Malicious code in karpatkit (PyPI)
MAL-2026-11047NoneMalicious code in karpatkey (PyPI)
Malicious code in karpatkey (PyPI)
MAL-2026-11046NoneMalicious code in intel-cicd-repo-infrastructure (PyPI)
Malicious code in intel-cicd-repo-infrastructure (PyPI)
GHSA-fjr4-x663-mwxcHigh· 8.1GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)
GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)
GHSA-6p8h-3wgx-97gfHigh· 7.5GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks
GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks