VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2026-48775Medium· 6.8
3mo ago

LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading

LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading

▾ Sunlitlanggraph-checkpoint · langgraph-checkpointEPSS 0.69%via GHSA
CVE-2026-48776Medium· 4.2
3mo ago

LangGraph SDK has unsafe URL path construction

LangGraph SDK has unsafe URL path construction

▾ Sunlitlanggraph-sdk · langgraph-sdkEPSS 0.29%via GHSA
CVE-2026-9291High· 7.1
3mo ago

amazon-braket-sdk vulnerable to Insecure Deserialization via pickle.loads()

amazon-braket-sdk vulnerable to Insecure Deserialization via pickle.loads()

▾ Twilightamazon-braket-sdk · amazon-braket-sdkEPSS 0.65%via GHSA
CVE-2026-50221Medium· 5.4
3mo ago

OpenStack Swift vulnerable to authenticated server-side request forgery

OpenStack Swift vulnerable to authenticated server-side request forgery

▾ Sunlitswift · swiftEPSS 0.22%via OSV
GHSA-g7vj-qw6x-g3p8Critical· 9.8
3mo ago

Duplicate Advisory: PickleScan has multiple stdlib modules with direct RCE not in blocklist

Duplicate Advisory: PickleScan has multiple stdlib modules with direct RCE not in blocklist

▾ Midnightpicklescan · picklescanvia GHSA
GHSA-q8qp-8jq6-78mcHigh· 8.1
3mo ago

Duplicate Advisory: Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper

Duplicate Advisory: Picklescan missing detection when calling pytorch function torch.jit.unsupported_tensor_ops.execWrapper

▾ Twilightpicklescan · picklescanvia GHSA
GHSA-gq8p-2329-gh3xHigh· 8.1
3mo ago

Duplicate Advisory: Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions

Duplicate Advisory: Picklescan has a missing detection when calling built-in python idlelib.autocomplete.AutoComplete.fetch_completions

▾ Twilightpicklescan · picklescanvia GHSA
GHSA-x36p-c636-788xHigh· 8.1
3mo ago

Duplicate Advisory: Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval

Duplicate Advisory: Picklescan is vulnerable to RCE through missing detection when calling numpy.f2py.crackfortran.myeval

▾ Twilightpicklescan · picklescanvia GHSA
GHSA-mg57-j93w-g3c7High· 8.1
3mo ago

Duplicate Advisory: Picklescan has a missing detection when calling built-in python profile.Profile.runctx

Duplicate Advisory: Picklescan has a missing detection when calling built-in python profile.Profile.runctx

▾ Twilightpicklescan · picklescanvia GHSA
CVE-2026-56695Medium· 6.5
3mo ago

OpenHarness remote resume commands expose other users' saved session snapshots

OpenHarness remote resume commands expose other users' saved session snapshots

▾ Sunlitopenharness-ai · openharness-aiEPSS 0.40%via OSV
CVE-2026-56696Medium· 5.4
3mo ago

OpenHarness remote project-context commands allow persistent prompt poisoning

OpenHarness remote project-context commands allow persistent prompt poisoning

▾ Sunlitopenharness-ai · openharness-aiEPSS 0.37%via OSV
MAL-2026-6327None
3mo ago

Malicious code in security-alerts-sdk (PyPI)

Malicious code in security-alerts-sdk (PyPI)

▾ Sunlitsecurity-alerts-sdk · security-alerts-sdkvia OSV
CVE-2026-9073Medium· 6.2
3mo ago

A flaw was found in foreman-mcp-server

A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitive session and authentication data. One mechanism logs session identifiers, which are treated as authentication creden…

▾ Sunlitredhat · satelliteEPSS 0.21%via NVD
CVE-2026-53925High· 7.8
3mo ago

Glances has arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configuration

Glances has arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configuration

▾ Twilightglances · glancesEPSS 0.18%via GHSA
CVE-2026-54134High
3mo ago

OctoPrint has possible file exfiltration via query parameters on upload endpoints

OctoPrint has possible file exfiltration via query parameters on upload endpoints

▾ TwilightOctoPrint · OctoPrintEPSS 0.32%via GHSA
CVE-2026-55488High
3mo ago

motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read

motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read

▾ Twilightmotioneye · motioneyeEPSS 0.62%via GHSA
GHSA-qxvg-h7q2-hcxhCritical· 9.8
3mo ago

motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)

motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE)

▾ Midnightmotioneye · motioneyevia GHSA
GHSA-phv5-334h-mxcwCritical
3mo ago

motionEye Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal

motionEye Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal

▾ Midnightmotioneye · motioneyevia GHSA
GHSA-w2j7-f3c6-g8cwMedium· 4.7
3mo ago

Flask-Security has an Open Redirect issue

Flask-Security has an Open Redirect issue

▾ SunlitFlask-Security · Flask-Securityvia GHSA
CVE-2026-56104High· 7.4
3mo ago

Chainlit contains a session hijacking vulnerability

Chainlit contains a session hijacking vulnerability

▾ Twilightchainlit · chainlitEPSS 0.42%via OSV
CVE-2025-66336High· 8.1
3mo ago

Apache Doris MCP Server is vulnerable to SQL Injection via metadata query path

Apache Doris MCP Server is vulnerable to SQL Injection via metadata query path

▾ Twilightdoris-mcp-server · doris-mcp-serverEPSS 0.56%via OSV
CVE-2026-12479Medium· 6.1
3mo ago

Keras: DiskIOStore permits path traversal through crafted layer names

Keras: DiskIOStore permits path traversal through crafted layer names

▾ Sunlitkeras · kerasEPSS 0.38%via OSV
CVE-2026-47155Medium· 6.5
3mo ago

vllm: vLLM: Supply-chain integrity issue due to inconsistent revision pinning controls (CVE-2026-47155)

A flaw was found in vLLM, an inference and serving engine for large language models (LLMs). The revision pinning controls in vLLM do not consistently apply to all artifacts loaded for a model. This allows a deployment configured with speci…

▾ SunlitRed Hat · Red Hat Enterprise Linux AI 3.3EPSS 0.25%via CSAF
CVE-2026-54276Medium· 6.1
3mo ago

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware can send an authentication response after following a cross-origin redirect. This likely requires an open redirect vuln…

▾ Sunlitaiohttp · aiohttpEPSS 0.31%via NVD
CVE-2026-54280High· 7.5⚖ disputed
3mo ago

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are not closed correctly when a client disconnects in the middle of a write. If a payload is using an open file or similar…

▾ Twilightaiohttp · aiohttpEPSS 0.46%via NVD
CVE-2026-54283High· 7.5
3mo ago

starlette: Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS (CVE-2026-54283)

A flaw was found in Starlette where the request.form() method silently ignores configured resource limits (max_fields and max_part_size) when parsing application/x-www-form-urlencoded data. An unauthenticated attacker can exploit this by s…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.48%via CSAF
CVE-2026-54293High· 7.5PoC
3mo ago

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing

NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Prior to 3.10.0-rc1, nltk.data.load() in NLTK is vulnerable to path tr…

▾ Midnightnltk · nltkEPSS 0.63%via NVD
CVE-2026-41523High· 7.5
3mo ago

vllm: vLLM: Arbitrary code execution via malicious HuggingFace model (CVE-2026-41523)

A flaw was found in vLLM, an inference and serving engine for large language models (LLMs). An unauthenticated attacker can exploit an assert-based security check during activation function loading. By publishing a malicious HuggingFace mo…

▾ TwilightRed Hat · Red Hat AI Inference Server 3.4EPSS 0.91%via CSAF
CVE-2026-48746Critical· 9.1PoC
3mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API Authenti…

▾ Abyssalvllm · vllmEPSS 1.2%via NVD
CVE-2024-37155Medium· 6.5
3mo ago

OpenCTI May Bypass Introspection Restriction

OpenCTI May Bypass Introspection Restriction

▾ Sunlitpycti · pyctiEPSS 0.46%via GHSA
CVEs tagged “pip” — page 40 · VulnSea