Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
CVE-2026-3198Medium· 6.5MLflow: Any authenticated user can enumerate all gateway secrets, endpoints, and model definitions
MLflow: Any authenticated user can enumerate all gateway secrets, endpoints, and model definitions
CVE-2026-5422Medium· 6.8Jupyter Server vulnerable to Path Traversal via incorrect root directory boundary check in _get_os_path()
Jupyter Server vulnerable to Path Traversal via incorrect root directory boundary check in _get_os_path()
CVE-2026-3514High· 7.5Prefect has an Authentication Middleware Bypass when URL paths are appended with 'health' or 'ready'
Prefect has an Authentication Middleware Bypass when URL paths are appended with 'health' or 'ready'
CVE-2026-10300Low· 3.7SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
SGLang: Reachable Assertion via lora_path in LoRAManager enables remote Denial of Dervice
CVE-2026-10566Medium· 5.3FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()
MAL-2026-5160NoneMalicious code in bt-signal-utils (PyPI)
Malicious code in bt-signal-utils (PyPI)
CVE-2026-10224Medium· 5.3hermes-agent has an Uncontrolled Resource Consumption issue
hermes-agent has an Uncontrolled Resource Consumption issue
CVE-2026-10223Medium· 6.3hermes-agent has an Injection issue
hermes-agent has an Injection issue
CVE-2026-10221High· 7.3hermes-agent has an Injection issue
hermes-agent has an Injection issue
CVE-2026-49138Medium· 5.0Nanobot contains a server-side request forgery vulnerability in the web_fetch tool
Nanobot contains a server-side request forgery vulnerability in the web_fetch tool
CVE-2026-47415High· 8.3praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, cross-workspace read/update/delete IDOR
praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, cross-workspace read/update/delete IDOR
CVE-2026-47411Medium· 6.5praisonai-platform: Any workspace member can rewrite workspace name, description, and settings via PATCH /workspaces/{id}
praisonai-platform: Any workspace member can rewrite workspace name, description, and settings via PATCH /workspaces/{id}
CVE-2026-47412High· 8.1praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}
praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}
CVE-2026-47417High· 8.1praisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDOR
praisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDOR
CVE-2026-47418High· 8.1praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR
praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR
CVE-2026-45426Low· 3.1Apache Airflow has an Incorrect Authorization issue
Apache Airflow has an Incorrect Authorization issue
CVE-2026-41014Medium· 4.3Apache Airflow has a Missing Authorization issue
Apache Airflow has a Missing Authorization issue
CVE-2026-42359High· 8.8Apache Airflow has a Deserialization of Untrusted Data vulnerability
Apache Airflow has a Deserialization of Untrusted Data vulnerability
CVE-2026-46764Medium· 4.3Apache Airflow has an Authorization Bypass Through User-Controlled Key
Apache Airflow has an Authorization Bypass Through User-Controlled Key
CVE-2026-41084High· 7.5Apache Airflow Vulnerable to Authorization Bypass Through User-Controlled Key
Apache Airflow Vulnerable to Authorization Bypass Through User-Controlled Key
CVE-2026-10222Medium· 5.6hermes-agent has an Injection issue
hermes-agent has an Injection issue
CVE-2026-40963Low· 3.1Apache Airflow has an Improper Authorization issue
Apache Airflow has an Improper Authorization issue
CVE-2026-42360Medium· 6.5Apache Airflow vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Apache Airflow vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
CVE-2026-42252Critical· 9.1Apache Airflow vulnerable to Improper Neutralization of Special Elements Used in a Template Engine
Apache Airflow vulnerable to Improper Neutralization of Special Elements Used in a Template Engine
CVE-2026-41017Medium· 5.9Apache Airflow has a Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
Apache Airflow has a Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
CVE-2026-40861Medium· 6.5Apache Airflow has a Link Following issue
Apache Airflow has a Link Following issue
CVE-2026-49267Medium· 5.9Apache Airflow has no certificate validation on SMTP STARTTLS connections
Apache Airflow has no certificate validation on SMTP STARTTLS connections
CVE-2026-42358Medium· 6.5Apache Airflow Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Apache Airflow Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
CVE-2026-45360High· 7.3Apache Airflow Vulnerable to Deserialization of Untrusted Data
Apache Airflow Vulnerable to Deserialization of Untrusted Data
CVE-2026-48726Medium· 6.5Apache Airflow: Auth manager doesn't invalidate JWT tokens after users click logout
Apache Airflow: Auth manager doesn't invalidate JWT tokens after users click logout