Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
CVE-2026-43977High· 7.5wger Vulnerable to IDOR: Authenticated Users Can Read Any User's Private Workout Session Data via Template Routine API
wger Vulnerable to IDOR: Authenticated Users Can Read Any User's Private Workout Session Data via Template Routine API
CVE-2026-44899Medium· 4.7Mistune Image Directive CSS Injection Vulnerability
Mistune Image Directive CSS Injection Vulnerability
CVE-2026-43978High· 8.1wger: Privilege escalation via trainer-login session chaining allows gym trainer to impersonate gym manager
wger: Privilege escalation via trainer-login session chaining allows gym trainer to impersonate gym manager
CVE-2026-45400High· 8.5Open WebUI has a Server-Side Request Forgery (SSRF) bypass in `validate_url`
Open WebUI has a Server-Side Request Forgery (SSRF) bypass in `validate_url`
CVE-2026-45399High· 7.1Open WebUI: Low-privilege authenticated users can enumerate and stop global background tasks, causing system-wide chat disruption
Open WebUI: Low-privilege authenticated users can enumerate and stop global background tasks, causing system-wide chat disruption
CVE-2026-44969Low· 2.5dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Logging Is Enabled
dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Logging Is Enabled
CVE-2026-45299Medium· 5.4Open WebUI has Stored Cross-Site Scripting In Profile Picture
Open WebUI has Stored Cross-Site Scripting In Profile Picture
CVE-2026-45397Medium· 5.3PoCOpen WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure
Open WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure
CVE-2026-44898Medium· 6.1Mistune TOC Anchor Injection XSS
Mistune TOC Anchor Injection XSS
CVE-2026-45370High· 7.7python-utcp: Full Process Environment Exposed to CLI Subprocess - Secrets Leakage via Command Injection
python-utcp: Full Process Environment Exposed to CLI Subprocess - Secrets Leakage via Command Injection
CVE-2026-44541Highethyca-fides has a DOM-based XSS vulnerability in fides.js via fides_description override
ethyca-fides has a DOM-based XSS vulnerability in fides.js via fides_description override
CVE-2026-45386Medium· 4.3Open WebUI has an IDOR vulnerability in the pin_channel_message API endpoint
Open WebUI has an IDOR vulnerability in the pin_channel_message API endpoint
CVE-2026-45303High· 7.7Open WebUI has stored XSS via the HTML renedering view
Open WebUI has stored XSS via the HTML renedering view
CVE-2026-45331High· 8.5Open WebUI has a full SSRF Vulnerability in the RAG Web Search Feature
Open WebUI has a full SSRF Vulnerability in the RAG Web Search Feature
CVE-2026-45350High· 7.1Open WebUI's chat completion API allows tool restrictions to be bypassed
Open WebUI's chat completion API allows tool restrictions to be bypassed
CVE-2026-44919Medium· 4.3OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
OpenStack Ironic: Pre-Validation Checksum Calculation allows Denial of Service (DoS) via Infinite Block Devices
CVE-2026-45398High· 7.5Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base Access Controls
Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base Access Controls
CVE-2026-45672High· 8.8Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed
Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed
CVE-2026-45314Medium· 6.1Open WebUI has XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image
Open WebUI has XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image
CVE-2026-45671High· 8.0Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion
Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion
CVE-2026-45338High· 7.7Open WebUI Vulnerable to SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py)
Open WebUI Vulnerable to SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py)
CVE-2026-44681Medium· 6.1Authlib OIDC Implicit/Hybrid Authorization Vulnerable to Open Redirect
Authlib OIDC Implicit/Hybrid Authorization Vulnerable to Open Redirect
CVE-2026-44794Medium· 5.4Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference
Nautobot: REST API permits creation of GenericForeignKey references to objects that the user should not be able to reference
CVE-2026-44796Medium· 6.5Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)
Nautobot: Object bulk rename UI actions vulnerable to denial of service by crafted regular expression (REDoS)
CVE-2026-44798High· 7.1Nautobot: GitRepository.current_head field should not be writable through REST API
Nautobot: GitRepository.current_head field should not be writable through REST API
CVE-2026-44797High· 8.5Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)
Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)
CVE-2026-45134High· 7.1LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
CVE-2026-42266High· 8.8JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions that can be installed from PyPI Extension Manager (allowed_…
CVE-2026-44432High· 7.5urllib3 is an HTTP client library for Python
urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the response was decompressed…
CVE-2026-44431Medium· 5.3PoCurllib3 is an HTTP client library for Python
urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=False) still forward these sensitive hea…