VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4636 CVEsRSS

CVE-2026-54071High· 7.8
2mo ago

BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py

BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py

▾ TwilightBabelDOC · BabelDOCEPSS 0.38%via GHSA
GHSA-wm45-qh3g-v83fHigh· 7.7
2mo ago

mcp-atlassian: Arbitrary server-side file read via attachment upload

mcp-atlassian: Arbitrary server-side file read via attachment upload

▾ Twilightmcp-atlassian · mcp-atlassianvia OSV
GHSA-g5r6-gv6m-f5jvHigh· 7.7
2mo ago

mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment

mcp-atlassian: Arbitrary file read via missing path validation in confluence_upload_attachment

▾ Twilightmcp-atlassian · mcp-atlassianvia GHSA
GHSA-489g-7rxv-6c8qMedium· 6.5
2mo ago

MCP Atlassian: DNS-rebinding TOCTOU bypass of the SSRF fix (CVE-2026-27826)

MCP Atlassian: DNS-rebinding TOCTOU bypass of the SSRF fix (CVE-2026-27826)

▾ Sunlitmcp-atlassian · mcp-atlassianvia OSV
MAL-2026-10139None
2mo ago

Malicious code in turbocalc (PyPI)

Malicious code in turbocalc (PyPI)

▾ Sunlitturbocalc · turbocalcvia OSV
MAL-2026-10119None
2mo ago

Malicious code in sankislayer (PyPI)

Malicious code in sankislayer (PyPI)

▾ Sunlitsankislayer · sankislayervia OSV
MAL-2026-10100None
2mo ago

Malicious code in proxy-check-i (PyPI)

Malicious code in proxy-check-i (PyPI)

▾ Sunlitproxy-check-i · proxy-check-ivia OSV
CVE-2026-49851High· 7.5
2mo ago

Mistune: Potential DoS via quadratic-time parsing in parse_link_text

Mistune: Potential DoS via quadratic-time parsing in parse_link_text

▾ Twilightmistune · mistuneEPSS 0.63%via OSV
CVE-2026-54651Medium
2mo ago

pypdf: Possible infinite loop when processing threads/articles in writer

pypdf: Possible infinite loop when processing threads/articles in writer

▾ Sunlitpypdf · pypdfEPSS 0.16%via GHSA
MAL-2026-10091None
2mo ago

Malicious code in qlinforge (PyPI)

Malicious code in qlinforge (PyPI)

▾ Sunlitqlinforge · qlinforgevia OSV
MAL-2026-10020None
2mo ago

Malicious code in playwrightr (PyPI)

Malicious code in playwrightr (PyPI)

▾ Sunlitplaywrightr · playwrightrvia OSV
GHSA-52vm-mxx8-f227High· 7.7
2mo ago

Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths

Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths

▾ Twilightphantom-audio · phantom-audiovia GHSA
CVE-2026-49476High· 7.5
2mo ago

Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists

Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists

▾ Twilightsoupsieve · soupsieveEPSS 0.64%via OSV
CVE-2026-14967Low· 3.1
2mo ago

BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory: its path-contai…

BBOT's `github_workflows` module could be induced to write a downloaded artifact outside its configured output directory: its path-containment check did not resolve `..`, so a crafted `CODE_REPOSITORY` URL could traverse out of the inten…

▾ Sunlitbbot · bbotEPSS 0.26%via OSV
CVE-2026-14966Low· 3.1
2mo ago

BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it failed to detect sy…

BBOT's unarchive module rejects archives containing symlink entries before extraction, but for zip and 7z archives it failed to detect symlinks whose listing carries a DOS-attribute prefix before the unix mode, as produced by legacy vers…

▾ Sunlitbbot · bbotEPSS 0.38%via OSV
CVE-2026-59930Medium· 4.3
2mo ago

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the toc plugin and TableOfContents directive generate hea…

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the toc plugin and TableOfContents directive generate heading IDs as predictable toc_N values without slugifying the heading text, allowing attacker-controll…

▾ Sunlitmistune · mistuneEPSS 0.19%via OSV
CVE-2026-59929Medium· 6.1
2mo ago

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the safe_url filter in src/mistune/renderers/html.py bloc…

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the safe_url filter in src/mistune/renderers/html.py blocks only javascript:, vbscript:, file:, and data: schemes, allowing legacy or chained schemes such as…

▾ Sunlitmistune · mistuneEPSS 0.34%via OSV
CVE-2026-59928High· 7.5
2mo ago

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repeated or distinct …

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repeated or distinct reference-link definitions causes quadratic work in src/mistune/block_parser.py and the ref_links en…

▾ Twilightmistune · mistuneEPSS 0.65%via OSV
CVE-2026-59927Medium· 5.3
2mo ago

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the Include directive in src/mistune/directives/include.p…

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the Include directive in src/mistune/directives/include.py detects only direct self-includes and not indirect cycles, allowing two markdown files that includ…

▾ Sunlitmistune · mistuneEPSS 0.53%via OSV
CVE-2026-59926Medium· 6.1
2mo ago

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_admonition() in src/mistune/directives/admonition.…

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_admonition() in src/mistune/directives/admonition.py concatenates the Admonition directive :class: option into the HTML class attribute without escapi…

▾ Sunlitmistune · mistuneEPSS 0.33%via OSV
CVE-2026-59925High· 7.5
2mo ago

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-asterisk or triple-a…

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-asterisk or triple-asterisk emphasis pairs around a character cause quadratic work in src/mistune/inline_parser.py becau…

▾ Twilightmistune · mistuneEPSS 0.64%via OSV
CVE-2026-59924Medium· 5.9
2mo ago

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Include.parse() joins and normalizes user-supplied includ…

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Include.parse() joins and normalizes user-supplied include paths without verifying that the result remains within the intended markdown directory, allowing c…

▾ Sunlitmistune · mistuneEPSS 0.46%via OSV
CVE-2026-59923Medium· 6.1
2mo ago

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, HTMLRenderer.safe_url() does not block percent-encoded ja…

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, HTMLRenderer.safe_url() does not block percent-encoded javascript URIs, allowing attacker-supplied Markdown links or images to bypass URL protections and exe…

▾ Sunlitmistune · mistuneEPSS 0.35%via OSV
CVE-2026-59922High· 7.5
2mo ago

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or caret marker pairs…

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or caret marker pairs around a character causes quadratic work in src/mistune/plugins/formatting.py when the strikethroug…

▾ Twilightmistune · mistuneEPSS 0.64%via OSV
CVE-2026-59822High· 8.2CISA KEVPoC
2mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAut…

▾ Abyssallitellm · litellmEPSS 0.84%via NVD
CVE-2026-59821High· 7.2
2mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's Custom Code Guardrails production create and update paths did not apply the same sandboxing and validation used by th…

▾ Twilightlitellm · litellmEPSS 0.90%via NVD
CVE-2026-59939High· 7.5
2mo ago

httplib2 is a comprehensive HTTP client library for Python

httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate in _decompressContent in httplib2/init.py, allo…

▾ Twilighthttplib2_project · httplib2EPSS 0.66%via NVD
CVE-2026-59820Medium· 6.5
2mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Skills archive extraction did not sufficiently validate file paths from uploaded skill ZIP archives, allowing an authen…

▾ Sunlitlitellm · litellmEPSS 0.59%via NVD
CVE-2026-59819Medium· 4.9
2mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.10-stable, LiteLLM's /health/test_connection endpoint resolved request-supplied environment and OIDC file references in litellm_params, a…

▾ Sunlitlitellm · litellmEPSS 0.57%via NVD
CVE-2026-15035High· 7.8
2mo ago

A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function async_run_command of the file src/openllm/common.py of the…

A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function async_run_command of the file src/openllm/common.py of the component Model Repository Directory Name Handler. Performing a manipulation of the argument cmd re…

▾ Twilightbentoml · bentomlEPSS 2.2%via OSV
CVEs tagged “pip” — page 34 · VulnSea