Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
GHSA-4mpj-78p6-rj59Critical· 9.8Duplicate Advisory: PickleScan's profile.run blocklist mismatch allows exec() bypass
Duplicate Advisory: PickleScan's profile.run blocklist mismatch allows exec() bypass
CVE-2026-55450Critical· 9.3PoCLangflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
CVE-2026-53870Medium· 5.5Hermes Agent creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644)
Hermes Agent creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644)
CVE-2026-53869High· 7.5Hermes Agent contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation
Hermes Agent contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation
CVE-2026-56258High· 8.1Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server
Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server
CVE-2026-56261Critical· 9.8Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution
Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution
MAL-2026-5878NoneMalicious code in cache-compat-utils (PyPI)
Malicious code in cache-compat-utils (PyPI)
MAL-2026-5876NoneMalicious code in temp-development-package-test (PyPI)
Malicious code in temp-development-package-test (PyPI)
CVE-2026-55443Medium· 5.1LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders
LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders
CVE-2026-56262Critical· 9.8Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution
Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution
CVE-2026-48735Mediumpypdf: Manipulated XMP metadata streams can exhaust RAM
pypdf: Manipulated XMP metadata streams can exhaust RAM
CVE-2026-49460Mediumpypdf: Inefficient decoding of FlateDecode PNG predictor streams
pypdf: Inefficient decoding of FlateDecode PNG predictor streams
CVE-2026-49461Mediumpypdf: Possible large memory usage for form XObjects during text extraction
pypdf: Possible large memory usage for form XObjects during text extraction
CVE-2026-54530Mediumpypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction
pypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction
CVE-2026-54531Mediumpypdf: Possible infinite loop when processing outlines/bookmarks in writer
pypdf: Possible infinite loop when processing outlines/bookmarks in writer
GHSA-8rfp-98v4-mmr6Low· 0.0Bleach: URI sanitization allows disallowed URI schemes with Unicode > U+00A0 in output
Bleach: URI sanitization allows disallowed URI schemes with Unicode > U+00A0 in output
GHSA-g75f-g53v-794xMedium· 4.3Bleach linkify(parse_email=True) CPU exhaustion via unbounded email regex scanning
Bleach linkify(parse_email=True) CPU exhaustion via unbounded email regex scanning
GHSA-gj48-438w-jh9vMedium· 6.1Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributes
Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributes
GHSA-gr75-jv2w-4656Medium· 5.1LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders
LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders
CVE-2026-12398High· 7.5Galaxy NG: command injection vulnerability
Galaxy NG: command injection vulnerability
CVE-2026-33760High· 8.8Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints
Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints
CVE-2026-42867Medium· 6.5Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint
Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint
CVE-2026-48519Critical· 9.6PoCLangflow: Unauthenticated RCE in Shareable Playgrounds
Langflow: Unauthenticated RCE in Shareable Playgrounds
CVE-2026-48520Medium· 6.1Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read
Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read
CVE-2026-53753Critical· 9.8PoCCrawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API
Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API
CVE-2026-56266Critical· 9.8Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution
Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution
CVE-2026-50019Medium· 6.1yt-dlp: File Downloader cookie leak with curl
yt-dlp: File Downloader cookie leak with curl
CVE-2026-50023High· 8.3yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)
yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)
CVE-2026-53754High· 7.5Crawl4AI: SSRF filter bypass in Docker server via IPv6 transition forms (NAT64 / 6to4 / unspecified / v4-mapped)
Crawl4AI: SSRF filter bypass in Docker server via IPv6 transition forms (NAT64 / 6to4 / unspecified / v4-mapped)
GHSA-f989-c77f-r2cqHigh· 8.2Crawl4AI: LLM credential exfiltration in Docker server via request base_url and env: token resolution
Crawl4AI: LLM credential exfiltration in Docker server via request base_url and env: token resolution