Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
MAL-2026-10985NoneMalicious code in animated-octo-spoon (PyPI)
Malicious code in animated-octo-spoon (PyPI)
MAL-2026-10978NoneMalicious code in reimagined-broccoli (PyPI)
Malicious code in reimagined-broccoli (PyPI)
MAL-2026-10977NoneMalicious code in lebinfmt (PyPI)
Malicious code in lebinfmt (PyPI)
MAL-2026-10976NoneMalicious code in colorstack (PyPI)
Malicious code in colorstack (PyPI)
MAL-2026-10975NoneMalicious code in rasterkit-demo (PyPI)
Malicious code in rasterkit-demo (PyPI)
MAL-2026-10974NoneMalicious code in rasterkit (PyPI)
Malicious code in rasterkit (PyPI)
MAL-2026-10973NoneMalicious code in fluffy-octo-broccoli (PyPI)
Malicious code in fluffy-octo-broccoli (PyPI)
GHSA-rwj8-pgh3-r573High· 7.5GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
GHSA-956x-8gvw-wg5vHigh· 8.4GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
CVE-2026-59890Medium· 6.1setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+
CVE-2026-59884High· 7.5pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
pyasn1 BER/CER/DER decoder denial of service via unbounded long-form tag IDs
GHSA-v396-v7q4-x2qjHighGitPython unsafe clone option gate bypass through joined short options
GitPython unsafe clone option gate bypass through joined short options
GHSA-2f96-g7mh-g2hxHigh· 8.8GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
MAL-2026-10930NoneMalicious code in trongridmy (PyPI)
Malicious code in trongridmy (PyPI)
MAL-2026-10929NoneMalicious code in trongrider (PyPI)
Malicious code in trongrider (PyPI)
MAL-2026-10927NoneMalicious code in roles-royce (PyPI)
Malicious code in roles-royce (PyPI)
MAL-2026-10926NoneMalicious code in defi-kit (PyPI)
Malicious code in defi-kit (PyPI)
MAL-2026-10919NoneMalicious code in ml-core-airflow-auth (PyPI)
Malicious code in ml-core-airflow-auth (PyPI)
MAL-2026-10918NoneMalicious code in automatic-octo-invention (PyPI)
Malicious code in automatic-octo-invention (PyPI)
MAL-2026-10912NoneMalicious code in shark-e2e-bnsneo (PyPI)
Malicious code in shark-e2e-bnsneo (PyPI)
MAL-2026-10911NoneMalicious code in mysuperlicense (PyPI)
Malicious code in mysuperlicense (PyPI)
MAL-2026-10910NoneMalicious code in mysupergoodpython (PyPI)
Malicious code in mysupergoodpython (PyPI)
MAL-2026-10909NoneMalicious code in ibreak (PyPI)
Malicious code in ibreak (PyPI)
MAL-2026-10908NoneMalicious code in hello-world-test-mh3 (PyPI)
Malicious code in hello-world-test-mh3 (PyPI)
MAL-2026-10907NoneMalicious code in hello-world-test-mh2 (PyPI)
Malicious code in hello-world-test-mh2 (PyPI)
CVE-2026-59198Medium· 6.5Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
CVE-2026-61736Critical· 9.3PoCLightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests
CVE-2026-61740CriticalLightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
MAL-2026-10869NoneMalicious code in paperclip-ai (PyPI)
Malicious code in paperclip-ai (PyPI)
MAL-2026-10868NoneMalicious code in neroteam-v1 (PyPI)
Malicious code in neroteam-v1 (PyPI)