VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2026-3198Medium· 6.5
3mo ago

MLflow: Any authenticated user can enumerate all gateway secrets, endpoints, and model definitions

MLflow: Any authenticated user can enumerate all gateway secrets, endpoints, and model definitions

▾ Sunlitmlflow · mlflowEPSS 0.36%via OSV
CVE-2026-5422Medium· 6.8
3mo ago

Jupyter Server vulnerable to Path Traversal via incorrect root directory boundary check in _get_os_path()

Jupyter Server vulnerable to Path Traversal via incorrect root directory boundary check in _get_os_path()

▾ Sunlitjupyter-server · jupyter-serverEPSS 0.55%via OSV
CVE-2026-3514High· 7.5
3mo ago

Prefect has an Authentication Middleware Bypass when URL paths are appended with 'health' or 'ready'

Prefect has an Authentication Middleware Bypass when URL paths are appended with 'health' or 'ready'

▾ Twilightprefect · prefectEPSS 0.63%via OSV
CVE-2026-10300Low· 3.7
3mo ago

SGLang: Reachable Assertion via  lora_path  in LoRAManager enables remote Denial of Dervice

SGLang: Reachable Assertion via  lora_path  in LoRAManager enables remote Denial of Dervice

▾ Sunlitsglang · sglangEPSS 0.37%via OSV
CVE-2026-10566Medium· 5.3
3mo ago

FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()

FoundationAgents MetaGPT: Deserialization through flawed argument mapping via Message.check_instruct_content()

▾ Sunlitmetagpt · metagptEPSS 0.12%via OSV
MAL-2026-5160None
3mo ago

Malicious code in bt-signal-utils (PyPI)

Malicious code in bt-signal-utils (PyPI)

▾ Sunlitbt-signal-utils · bt-signal-utilsvia OSV
CVE-2026-10224Medium· 5.3
4mo ago

hermes-agent has an Uncontrolled Resource Consumption issue

hermes-agent has an Uncontrolled Resource Consumption issue

▾ Sunlithermes-agent · hermes-agentEPSS 0.37%via OSV
CVE-2026-10223Medium· 6.3
4mo ago

hermes-agent has an Injection issue

hermes-agent has an Injection issue

▾ Sunlithermes-agent · hermes-agentEPSS 0.23%via OSV
CVE-2026-10221High· 7.3
4mo ago

hermes-agent has an Injection issue

hermes-agent has an Injection issue

▾ Twilighthermes-agent · hermes-agentEPSS 0.30%via OSV
CVE-2026-49138Medium· 5.0
4mo ago

Nanobot contains a server-side request forgery vulnerability in the web_fetch tool

Nanobot contains a server-side request forgery vulnerability in the web_fetch tool

▾ Sunlitnanobot-ai · nanobot-aiEPSS 0.49%via OSV
CVE-2026-47415High· 8.3
4mo ago

praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, cross-workspace read/update/delete IDOR

praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, cross-workspace read/update/delete IDOR

▾ Twilightpraisonai-platform · praisonai-platformEPSS 0.39%via OSV
CVE-2026-47411Medium· 6.5
4mo ago

praisonai-platform: Any workspace member can rewrite workspace name, description, and settings via PATCH /workspaces/{id}

praisonai-platform: Any workspace member can rewrite workspace name, description, and settings via PATCH /workspaces/{id}

▾ Sunlitpraisonai-platform · praisonai-platformEPSS 0.34%via OSV
CVE-2026-47412High· 8.1
4mo ago

praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}

praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}

▾ Twilightpraisonai-platform · praisonai-platformEPSS 0.53%via OSV
CVE-2026-47417High· 8.1
4mo ago

praisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDOR

praisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDOR

▾ Twilightpraisonai-platform · praisonai-platformEPSS 0.36%via OSV
CVE-2026-47418High· 8.1
4mo ago

praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR

praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR

▾ Twilightpraisonai-platform · praisonai-platformEPSS 0.41%via OSV
CVE-2026-45426Low· 3.1
4mo ago

Apache Airflow has an Incorrect Authorization issue

Apache Airflow has an Incorrect Authorization issue

▾ Sunlitapache-airflow · apache-airflowEPSS 0.52%via OSV
CVE-2026-41014Medium· 4.3
4mo ago

Apache Airflow has a Missing Authorization issue

Apache Airflow has a Missing Authorization issue

▾ Sunlitapache-airflow · apache-airflowEPSS 0.57%via OSV
CVE-2026-42359High· 8.8
4mo ago

Apache Airflow has a Deserialization of Untrusted Data vulnerability

Apache Airflow has a Deserialization of Untrusted Data vulnerability

▾ Twilightapache-airflow · apache-airflowEPSS 0.95%via OSV
CVE-2026-46764Medium· 4.3
4mo ago

Apache Airflow has an Authorization Bypass Through User-Controlled Key

Apache Airflow has an Authorization Bypass Through User-Controlled Key

▾ Sunlitapache-airflow · apache-airflowEPSS 0.57%via OSV
CVE-2026-41084High· 7.5
4mo ago

Apache Airflow Vulnerable to Authorization Bypass Through User-Controlled Key

Apache Airflow Vulnerable to Authorization Bypass Through User-Controlled Key

▾ Twilightapache-airflow · apache-airflowEPSS 0.76%via OSV
CVE-2026-10222Medium· 5.6
4mo ago

hermes-agent has an Injection issue

hermes-agent has an Injection issue

▾ Sunlithermes-agent · hermes-agentEPSS 0.27%via OSV
CVE-2026-40963Low· 3.1
4mo ago

Apache Airflow has an Improper Authorization issue

Apache Airflow has an Improper Authorization issue

▾ Sunlitapache-airflow · apache-airflowEPSS 0.52%via OSV
CVE-2026-42360Medium· 6.5
4mo ago

Apache Airflow vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

Apache Airflow vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

▾ Sunlitapache-airflow · apache-airflowEPSS 0.52%via OSV
CVE-2026-42252Critical· 9.1
4mo ago

Apache Airflow vulnerable to Improper Neutralization of Special Elements Used in a Template Engine

Apache Airflow vulnerable to Improper Neutralization of Special Elements Used in a Template Engine

▾ Midnightapache-airflow · apache-airflowEPSS 0.59%via OSV
CVE-2026-41017Medium· 5.9
4mo ago

Apache Airflow has a Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

Apache Airflow has a Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

▾ Sunlitapache-airflow · apache-airflowEPSS 0.38%via OSV
CVE-2026-40861Medium· 6.5
4mo ago

Apache Airflow has a Link Following issue

Apache Airflow has a Link Following issue

▾ Sunlitapache-airflow · apache-airflowEPSS 0.76%via OSV
CVE-2026-49267Medium· 5.9
4mo ago

Apache Airflow has no certificate validation on SMTP STARTTLS connections

Apache Airflow has no certificate validation on SMTP STARTTLS connections

▾ Sunlitapache-airflow · apache-airflowEPSS 0.27%via OSV
CVE-2026-42358Medium· 6.5
4mo ago

Apache Airflow Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

Apache Airflow Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

▾ Sunlitapache-airflow · apache-airflowEPSS 0.52%via OSV
CVE-2026-45360High· 7.3
4mo ago

Apache Airflow Vulnerable to Deserialization of Untrusted Data

Apache Airflow Vulnerable to Deserialization of Untrusted Data

▾ Twilightapache-airflow · apache-airflowEPSS 0.93%via OSV
CVE-2026-48726Medium· 6.5
4mo ago

Apache Airflow: Auth manager doesn't invalidate JWT tokens after users click logout

Apache Airflow: Auth manager doesn't invalidate JWT tokens after users click logout

▾ Sunlitapache-airflow · apache-airflowEPSS 0.60%via OSV
CVEs tagged “pip” — page 53 · VulnSea