VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

GHSA-r9mr-m37c-5fr3High· 8.8
2mo ago

GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution

GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution

▾ TwilightGitPython · GitPythonvia GHSA
CVE-2026-59214High· 7.3
2mo ago

Open WebUI: Stored web worker XSS via Pyodide

Open WebUI: Stored web worker XSS via Pyodide

▾ Twilightopen-webui · open-webuiEPSS 0.42%via GHSA
CVE-2026-59218Medium· 5.3
2mo ago

Open WebUI: Account enumeration via observable login timing discrepancy

Open WebUI: Account enumeration via observable login timing discrepancy

▾ Sunlitopen-webui · open-webuiEPSS 0.41%via GHSA
CVE-2026-59226Low· 3.1
2mo ago

Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation

Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation

▾ Sunlitopen-webui · open-webuiEPSS 0.53%via GHSA
CVE-2026-59220Medium· 6.5
2mo ago

Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config

Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config

▾ Sunlitopen-webui · open-webuiEPSS 0.57%via GHSA
CVE-2026-59227Medium· 4.3
2mo ago

Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission

Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission

▾ Sunlitopen-webui · open-webuiEPSS 0.42%via GHSA
CVE-2026-59715Low· 3.1
2mo ago

Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)

Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)

▾ Sunlitopen-webui · open-webuiEPSS 0.36%via GHSA
CVE-2026-59219High· 7.1
2mo ago

Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout

Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout

▾ Twilightopen-webui · open-webuiEPSS 0.46%via GHSA
CVE-2026-59217Medium· 4.3
2mo ago

Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)

Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)

▾ Sunlitopen-webui · open-webuiEPSS 0.37%via GHSA
CVE-2026-59213Low· 3.5
2mo ago

Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)

Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)

▾ Sunlitopen-webui · open-webuiEPSS 0.37%via GHSA
CVE-2026-59222Medium
2mo ago

Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials

Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials

▾ Sunlitopen-webui · open-webuiEPSS 0.46%via GHSA
CVE-2026-13769Medium· 5.5
2mo ago

AWS CLI: Overly permissive File Permissions

AWS CLI: Overly permissive File Permissions

▾ Sunlitawscli · awscliEPSS 0.16%via OSV
CVE-2026-61632Medium· 5.3
2mo ago

PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path

PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path

▾ Sunlitpymdown-extensions · pymdown-extensionsEPSS 0.40%via OSV
GHSA-3rp5-jjmw-4wv2High· 7.0
2mo ago

GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)

GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)

▾ Twilightgitpython · gitpythonvia GHSA
MAL-2026-11031None
2mo ago

Malicious code in govapkg (PyPI)

Malicious code in govapkg (PyPI)

▾ Sunlitgovapkg · govapkgvia OSV
CVE-2026-59936High
2mo ago

pypdf: Possible infinite loop for not terminated inline images

pypdf: Possible infinite loop for not terminated inline images

▾ Twilightpypdf · pypdfEPSS 0.62%via OSV
CVE-2026-59935High
2mo ago

pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)

pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)

▾ Twilightpypdf · pypdfEPSS 0.62%via OSV
CVE-2026-59938Medium
2mo ago

pypdf: Possible large memory usage for wrong image dimensions

pypdf: Possible large memory usage for wrong image dimensions

▾ Sunlitpypdf · pypdfEPSS 0.52%via OSV
CVE-2026-59937Medium
2mo ago

pypdf: Possible long runtimes for repeated malformed cross-reference entries

pypdf: Possible long runtimes for repeated malformed cross-reference entries

▾ Sunlitpypdf · pypdfEPSS 0.62%via OSV
MAL-2026-10993None
2mo ago

Malicious code in torch-musa (PyPI)

Malicious code in torch-musa (PyPI)

▾ Sunlittorch-musa · torch-musavia OSV
MAL-2026-10992None
2mo ago

Malicious code in dev-helper-bg (PyPI)

Malicious code in dev-helper-bg (PyPI)

▾ Sunlitdev-helper-bg · dev-helper-bgvia OSV
MAL-2026-10991None
2mo ago

Malicious code in make-helper (PyPI)

Malicious code in make-helper (PyPI)

▾ Sunlitmake-helper · make-helpervia OSV
GHSA-whvh-wf3x-g77jLow
2mo ago

JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)

JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)

▾ Sunlitjupyterlab · jupyterlabvia GHSA
GHSA-h5v5-8746-g7mmMedium
2mo ago

JupyterLab PluginManager lock-rule enforcement bypass

JupyterLab PluginManager lock-rule enforcement bypass

▾ Sunlitjupyterlab · jupyterlabvia OSV
GHSA-89vp-jrxv-24w8Medium
2mo ago

JupyterLab: PyPI extension blocklist package-name canonicalization bypass

JupyterLab: PyPI extension blocklist package-name canonicalization bypass

▾ Sunlitjupyterlab · jupyterlabvia GHSA
GHSA-gx64-gj6p-pc4cHigh
2mo ago

JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab

JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab

▾ Twilightjupyterlab · jupyterlabvia GHSA
GHSA-pppj-hq3g-57pjHigh
2mo ago

JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)

JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)

▾ Twilightjupyterlab · jupyterlabvia GHSA
CVE-2026-64825Critical· 9.3
2mo ago

Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding

Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding

▾ Midnighthomeassistant · homeassistantEPSS 0.58%via OSV
CVE-2026-47143Medium· 5.9
2mo ago

Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMRequired()` and `d…

Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 and 5.0.8 have a NULL pointer dereference in `modRMRequired()` and `decode()` when disassembling 3DNow! opcodes (`0F 0F`) in builds compiled with `-DCAPSTONE_X86_REDUCE`…

▾ Sunlitcapstone · capstoneEPSS 0.47%via OSV
MAL-2026-10986None
2mo ago

Malicious code in comp-colors (PyPI)

Malicious code in comp-colors (PyPI)

▾ Sunlitcomp-colors · comp-colorsvia OSV
CVEs tagged “pip” — page 29 · VulnSea