Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
CVE-2026-49298High· 8.8Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args
CVE-2026-10212Medium· 6.3AstrBot: Manipulation of astr_main_agent's session_id parameter leads to authorization bypass
AstrBot: Manipulation of astr_main_agent's session_id parameter leads to authorization bypass
CVE-2026-40961High· 7.2Apache Airflow: Authenticated users can bypass the `is_safe_url` check
Apache Airflow: Authenticated users can bypass the `is_safe_url` check
CVE-2026-45192Medium· 6.5Apache Airflow: Incomplete redaction allowlist exposes secrets in Connection `extra` to read-permitted users
Apache Airflow: Incomplete redaction allowlist exposes secrets in Connection `extra` to read-permitted users
CVE-2026-8643Medium· 5.5⚖ disputedpip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed outside the installation directory.
CVE-2026-10177Medium· 6.3Aider has an SSRF vulnerability through its AWS EC2 Metadata Endpoint
Aider has an SSRF vulnerability through its AWS EC2 Metadata Endpoint
CVE-2026-10175Medium· 6.3Aider is vulnerable to Code Injection via editor_coder.run function
Aider is vulnerable to Code Injection via editor_coder.run function
MAL-2026-5086NoneMalicious code in polymarket-data (PyPI)
Malicious code in polymarket-data (PyPI)
CVE-2026-47393Critical· 9.8PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default
PraisonAI `deploy --type api` emits a Flask server with authentication disabled by default
CVE-2026-47213Medium· 6.5BoxLite has a Timeout Bypass Vulnerability
BoxLite has a Timeout Bypass Vulnerability
CVE-2026-47409High· 8.1praisonai-platform: Missing authorization on member removal enables full workspace takeover by any user regardless of role
praisonai-platform: Missing authorization on member removal enables full workspace takeover by any user regardless of role
CVE-2026-47184Medium· 6.5zeroconf has unbounded DNS record cache that allows LAN-local memory exhaustion via multicast flood
zeroconf has unbounded DNS record cache that allows LAN-local memory exhaustion via multicast flood
CVE-2026-47183Medium· 6.5zeroconf: Unbounded exception-dedup state retains packet buffers via traceback frame locals, enabling LAN-local memory exhaustion
zeroconf: Unbounded exception-dedup state retains packet buffers via traceback frame locals, enabling LAN-local memory exhaustion
CVE-2026-47397HighPraisonAI has an Arbitrary File Write in Python API
PraisonAI has an Arbitrary File Write in Python API
CVE-2026-47405High· 8.8PraisonAI Platform: Missing role checks let any workspace member become owner and control workspace membership
PraisonAI Platform: Missing role checks let any workspace member become owner and control workspace membership
CVE-2026-47180Medium· 6.5zeroconf has unbounded recursion in DNS compression-pointer decoder that allows LAN-local denial of service
zeroconf has unbounded recursion in DNS compression-pointer decoder that allows LAN-local denial of service
CVE-2026-47394HighPraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate
PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validate
CVE-2026-47398High· 8.1PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334
PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334
CVE-2026-47399High· 8.8PraisonAI Platform workspace-scoped routes allow cross-workspace object access by global object ID
PraisonAI Platform workspace-scoped routes allow cross-workspace object access by global object ID
CVE-2026-47414High· 7.6praisonai-platform: Label endpoints' unchecked label_id/issue_id enable cross-workspace label IDOR (edit, delete, link)
praisonai-platform: Label endpoints' unchecked label_id/issue_id enable cross-workspace label IDOR (edit, delete, link)
CVE-2026-47395Medium· 5.5PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context
PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model context
CVE-2026-47390Medium· 5.5PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings
PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings
CVE-2026-47406High· 8.1praisonai-platform: IDOR in dependency endpoints allows cross-workspace issue linking, reading, and deletion due to missing ownership checks
praisonai-platform: IDOR in dependency endpoints allows cross-workspace issue linking, reading, and deletion due to missing ownership checks
CVE-2026-47408Medium· 6.5praisonai-platform: list_issue_activity returns activity log for any issue regardless of workspace ownership
praisonai-platform: list_issue_activity returns activity log for any issue regardless of workspace ownership
CVE-2026-49299MediumOpenStack Neutron has an Incorrect Authorization issue
OpenStack Neutron has an Incorrect Authorization issue
CVE-2026-10105High· 8.3agno contains a SQL injection vulnerability
agno contains a SQL injection vulnerability
CVE-2026-10108High· 7.5xiaomusic contains an unauthenticated path traversal vulnerability
xiaomusic contains an unauthenticated path traversal vulnerability
GHSA-qp9x-wp8f-qgjjMedium· 4.0tuf has platform-dependent delegation path matching
tuf has platform-dependent delegation path matching
CVE-2026-47144Medium· 5.5Shamefile has an arbitrary file read via shamefile.yaml in shame next
Shamefile has an arbitrary file read via shamefile.yaml in shame next
CVE-2026-46526Medium· 5.0local-deep-research has an SSRF bypass in `safe_get`
local-deep-research has an SSRF bypass in `safe_get`