VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

GHSA-4mpj-78p6-rj59Critical· 9.8
3mo ago

Duplicate Advisory: PickleScan's profile.run blocklist mismatch allows exec() bypass

Duplicate Advisory: PickleScan's profile.run blocklist mismatch allows exec() bypass

▾ Midnightpicklescan · picklescanvia GHSA
CVE-2026-55450Critical· 9.3PoC
3mo ago

Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak

Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak

▾ Abyssallangflow · langflowEPSS 1.2%via GHSA
CVE-2026-53870Medium· 5.5
3mo ago

Hermes Agent creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644)

Hermes Agent creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644)

▾ Sunlithermes-agent · hermes-agentEPSS 0.15%via GHSA
CVE-2026-53869High· 7.5
3mo ago

Hermes Agent contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation

Hermes Agent contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation

▾ Twilighthermes-agent · hermes-agentEPSS 0.81%via GHSA
CVE-2026-56258High· 8.1
3mo ago

Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server

Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server

▾ Twilightcrawl4ai · crawl4aiEPSS 0.91%via OSV
CVE-2026-56261Critical· 9.8
3mo ago

Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution

Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution

▾ Midnightcrawl4ai · crawl4aiEPSS 0.51%via OSV
MAL-2026-5878None
3mo ago

Malicious code in cache-compat-utils (PyPI)

Malicious code in cache-compat-utils (PyPI)

▾ Sunlitcache-compat-utils · cache-compat-utilsvia OSV
MAL-2026-5876None
3mo ago

Malicious code in temp-development-package-test (PyPI)

Malicious code in temp-development-package-test (PyPI)

▾ Sunlittemp-development-package-test · temp-development-package-testvia OSV
CVE-2026-55443Medium· 5.1
3mo ago

LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders

LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders

▾ Sunlitlangchain · langchainEPSS 0.21%via OSV
CVE-2026-56262Critical· 9.8
3mo ago

Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution

Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution

▾ Midnightcrawl4ai · crawl4aiEPSS 0.76%via OSV
CVE-2026-48735Medium
3mo ago

pypdf: Manipulated XMP metadata streams can exhaust RAM

pypdf: Manipulated XMP metadata streams can exhaust RAM

▾ Sunlitpypdf · pypdfEPSS 0.18%via GHSA
CVE-2026-49460Medium
3mo ago

pypdf: Inefficient decoding of FlateDecode PNG predictor streams

pypdf: Inefficient decoding of FlateDecode PNG predictor streams

▾ Sunlitpypdf · pypdfEPSS 0.17%via GHSA
CVE-2026-49461Medium
3mo ago

pypdf: Possible large memory usage for form XObjects during text extraction

pypdf: Possible large memory usage for form XObjects during text extraction

▾ Sunlitpypdf · pypdfEPSS 0.17%via GHSA
CVE-2026-54530Medium
3mo ago

pypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction

pypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction

▾ Sunlitpypdf · pypdfEPSS 0.17%via OSV
CVE-2026-54531Medium
3mo ago

pypdf: Possible infinite loop when processing outlines/bookmarks in writer

pypdf: Possible infinite loop when processing outlines/bookmarks in writer

▾ Sunlitpypdf · pypdfEPSS 0.17%via OSV
GHSA-8rfp-98v4-mmr6Low· 0.0
3mo ago

Bleach: URI sanitization allows disallowed URI schemes with Unicode > U+00A0 in output

Bleach: URI sanitization allows disallowed URI schemes with Unicode > U+00A0 in output

▾ Sunlitbleach · bleachvia OSV
GHSA-g75f-g53v-794xMedium· 4.3
3mo ago

Bleach linkify(parse_email=True) CPU exhaustion via unbounded email regex scanning

Bleach linkify(parse_email=True) CPU exhaustion via unbounded email regex scanning

▾ Sunlitbleach · bleachvia GHSA
GHSA-gj48-438w-jh9vMedium· 6.1
3mo ago

Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributes

Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributes

▾ Sunlitbleach · bleachvia OSV
GHSA-gr75-jv2w-4656Medium· 5.1
3mo ago

LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders

LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders

▾ Sunlitlangchain · langchainvia GHSA
CVE-2026-12398High· 7.5
3mo ago

Galaxy NG: command injection vulnerability

Galaxy NG: command injection vulnerability

▾ Twilightgalaxy-ng · galaxy-ngEPSS 0.89%via GHSA
CVE-2026-33760High· 8.8
3mo ago

Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints

Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints

▾ Twilightlangflow · langflowEPSS 0.50%via GHSA
CVE-2026-42867Medium· 6.5
3mo ago

Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint

Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint

▾ Sunlitlangflow · langflowEPSS 0.47%via GHSA
CVE-2026-48519Critical· 9.6PoC
3mo ago

Langflow: Unauthenticated RCE in Shareable Playgrounds

Langflow: Unauthenticated RCE in Shareable Playgrounds

▾ Abyssallangflow · langflowEPSS 0.78%via GHSA
CVE-2026-48520Medium· 6.1
3mo ago

Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read

Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read

▾ Sunlitlangflow · langflowEPSS 0.44%via GHSA
CVE-2026-53753Critical· 9.8PoC
3mo ago

Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API

Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API

▾ Abyssalcrawl4ai · crawl4aiEPSS 2.9%via GHSA
CVE-2026-56266Critical· 9.8
3mo ago

Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution

Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution

▾ Midnightcrawl4ai · crawl4aiEPSS 0.48%via GHSA
CVE-2026-50019Medium· 6.1
3mo ago

yt-dlp: File Downloader cookie leak with curl

yt-dlp: File Downloader cookie leak with curl

▾ Sunlityt-dlp · yt-dlpEPSS 0.32%via GHSA
CVE-2026-50023High· 8.3
3mo ago

yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)

yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)

▾ Twilightyt-dlp · yt-dlpEPSS 0.66%via GHSA
CVE-2026-53754High· 7.5
3mo ago

Crawl4AI: SSRF filter bypass in Docker server via IPv6 transition forms (NAT64 / 6to4 / unspecified / v4-mapped)

Crawl4AI: SSRF filter bypass in Docker server via IPv6 transition forms (NAT64 / 6to4 / unspecified / v4-mapped)

▾ Twilightcrawl4ai · crawl4aiEPSS 0.43%via GHSA
GHSA-f989-c77f-r2cqHigh· 8.2
3mo ago

Crawl4AI: LLM credential exfiltration in Docker server via request base_url and env: token resolution

Crawl4AI: LLM credential exfiltration in Docker server via request base_url and env: token resolution

▾ Twilightcrawl4ai · crawl4aivia GHSA
CVEs tagged “pip” — page 47 · VulnSea