Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
GHSA-r9mr-m37c-5fr3High· 8.8GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution
GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution
CVE-2026-59214High· 7.3Open WebUI: Stored web worker XSS via Pyodide
Open WebUI: Stored web worker XSS via Pyodide
CVE-2026-59218Medium· 5.3Open WebUI: Account enumeration via observable login timing discrepancy
Open WebUI: Account enumeration via observable login timing discrepancy
CVE-2026-59226Low· 3.1Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
CVE-2026-59220Medium· 6.5Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
CVE-2026-59227Medium· 4.3Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
CVE-2026-59715Low· 3.1Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
CVE-2026-59219High· 7.1Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
CVE-2026-59217Medium· 4.3Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
CVE-2026-59213Low· 3.5Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
CVE-2026-59222MediumOpen WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
CVE-2026-13769Medium· 5.5AWS CLI: Overly permissive File Permissions
AWS CLI: Overly permissive File Permissions
CVE-2026-61632Medium· 5.3PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path
PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path
GHSA-3rp5-jjmw-4wv2High· 7.0GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
MAL-2026-11031NoneMalicious code in govapkg (PyPI)
Malicious code in govapkg (PyPI)
CVE-2026-59936Highpypdf: Possible infinite loop for not terminated inline images
pypdf: Possible infinite loop for not terminated inline images
CVE-2026-59935Highpypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
CVE-2026-59938Mediumpypdf: Possible large memory usage for wrong image dimensions
pypdf: Possible large memory usage for wrong image dimensions
CVE-2026-59937Mediumpypdf: Possible long runtimes for repeated malformed cross-reference entries
pypdf: Possible long runtimes for repeated malformed cross-reference entries
MAL-2026-10993NoneMalicious code in torch-musa (PyPI)
Malicious code in torch-musa (PyPI)
MAL-2026-10992NoneMalicious code in dev-helper-bg (PyPI)
Malicious code in dev-helper-bg (PyPI)
MAL-2026-10991NoneMalicious code in make-helper (PyPI)
Malicious code in make-helper (PyPI)
GHSA-whvh-wf3x-g77jLowJupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)
GHSA-h5v5-8746-g7mmMediumJupyterLab PluginManager lock-rule enforcement bypass
JupyterLab PluginManager lock-rule enforcement bypass
GHSA-89vp-jrxv-24w8MediumJupyterLab: PyPI extension blocklist package-name canonicalization bypass
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
GHSA-gx64-gj6p-pc4cHighJupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
GHSA-pppj-hq3g-57pjHighJupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
CVE-2026-64825Critical· 9.3Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding
Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding
CVE-2026-47143Medium· 5.9Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMRequired()` and `d…
Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMRequired()` and `decode()` when disassembling 3DNow! opcodes (`0F 0F`) in builds compiled with `-DCAPSTONE_X86_REDUCE`…
MAL-2026-10986NoneMalicious code in comp-colors (PyPI)
Malicious code in comp-colors (PyPI)