Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
CVE-2026-31233Critical· 9.8Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
Guardrails AI contains a code injection vulnerability in its Hub package installation mechanism
CVE-2026-31240High· 7.5mem0 server lacks authentication and authorization controls for its memory management API endpoints
mem0 server lacks authentication and authorization controls for its memory management API endpoints
CVE-2026-31241Medium· 6.5mem0 server lacks authentication and authorization controls for its memory deletion API endpoint
mem0 server lacks authentication and authorization controls for its memory deletion API endpoint
CVE-2026-31224High· 8.8Snorkel MultitaskClassifier.load uses an unsafe torch.load
Snorkel MultitaskClassifier.load uses an unsafe torch.load
CVE-2026-31223High· 8.8Snorkel BaseLabeler.load uses an unsafe pickle.load
Snorkel BaseLabeler.load uses an unsafe pickle.load
CVE-2026-31245Medium· 5.3mem0 server lacks authentication and authorization controls for its memory creation API endpoint
mem0 server lacks authentication and authorization controls for its memory creation API endpoint
CVE-2026-31222High· 8.8Snorkel Trainer.load uses an unsafe torch.load
Snorkel Trainer.load uses an unsafe torch.load
CVE-2026-31221High· 8.0pytorch-lightning: PyTorch-Lightning: Arbitrary code execution via insecure deserialization of checkpoint files (CVE-2026-31221)
A flaw was found in PyTorch-Lightning. This vulnerability, categorized as insecure deserialization (CWE-502), exists in the checkpoint loading mechanism. A remote attacker can exploit this by providing a maliciously crafted checkpoint file…
CVE-2026-31225High· 8.8Superduper: Remote code execution via unsafe eval in superduper query parsing
Superduper: Remote code execution via unsafe eval in superduper query parsing
CVE-2026-44223Medium· 6.5vLLM is an inference and serving engine for large language models (LLMs)
vLLM is an inference and serving engine for large language models (LLMs). From 0.18.0 to before 0.20.0, the extract_hidden_states speculative decoding proposer in vLLM returns a tensor with an incorrect shape after the first decode step,…
CVE-2026-7813Critical· 9.9pgAdmin 4 server mode has an authorization vulnerability affecting Server Groups, Servers, Shared Servers, Background Processes, and Debu…
pgAdmin 4 server mode has an authorization vulnerability affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules
CVE-2026-41018Medium· 6.5Apache Airflow Providers Elasticsearch: Elasticsearch task-log handlers leak credentials embedded in the host URL
Apache Airflow Providers Elasticsearch: Elasticsearch task-log handlers leak credentials embedded in the host URL
CVE-2026-45017High· 7.5python-liquid: Absolute paths escape filesystem loader search path
python-liquid: Absolute paths escape filesystem loader search path
CVE-2026-56400High· 8.3Open WebUI has a CORS misconfiguration and session validation issue
Open WebUI has a CORS misconfiguration and session validation issue
CVE-2026-40217High· 8.8PoCLiteLLM has a sandbox escape in custom-code guardrail
LiteLLM has a sandbox escape in custom-code guardrail
CVE-2026-7817Medium· 6.5pgAdmin 4 contains local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities
pgAdmin 4 contains local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities
CVE-2026-31246Medium· 6.5GPT-Pilot contains a command injection vulnerability in the Executor.run() method
GPT-Pilot contains a command injection vulnerability in the Executor.run() method
CVE-2026-44972Medium· 5.0GuardDog: Unsanitized human-readable scan output allows terminal escape injection from malicious package content
GuardDog: Unsanitized human-readable scan output allows terminal escape injection from malicious package content
CVE-2026-44569High· 7.1Open WebUI's Insecure Message Access Breaks Authorization
Open WebUI's Insecure Message Access Breaks Authorization
CVE-2026-44571Medium· 6.5Open WebUI's Improper Authorization in Standard Channels Allows Message Updates with Read Permission
Open WebUI's Improper Authorization in Standard Channels Allows Message Updates with Read Permission
CVE-2026-7816High· 8.8pgAdmin 4: OS command injection vulnerability in Import/Export query export
pgAdmin 4: OS command injection vulnerability in Import/Export query export
CVE-2026-44565High· 8.1Open WebUI Arbitrary File Write, Delete via Path Traversal
Open WebUI Arbitrary File Write, Delete via Path Traversal
CVE-2026-7820Medium· 6.5pgAdmin 4: Improper restriction of excessive authentication attempts
pgAdmin 4: Improper restriction of excessive authentication attempts
CVE-2026-7819High· 8.1pgAdmin 4 File Manager has symbolic-link path traversal
pgAdmin 4 File Manager has symbolic-link path traversal
CVE-2026-7815High· 8.8SQL injection vulnerability in pgAdmin 4 Maintenance Tool
SQL injection vulnerability in pgAdmin 4 Maintenance Tool
CVE-2026-44570High· 8.3Open WebUI has inconsistent authorization controls within memories API
Open WebUI has inconsistent authorization controls within memories API
CVE-2026-44339High· 8.6PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute
PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute
CVE-2026-43979Medium· 5.0local-deep-research is Vulnerable to HTML Injection via Unescaped User Input in PDF Export (`pdf_service.py:_markdown_to_html`)
local-deep-research is Vulnerable to HTML Injection via Unescaped User Input in PDF Export (`pdf_service.py:_markdown_to_html`)
CVE-2026-31247High· 7.5Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks
Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks
CVE-2026-8319Medium· 5.3aiwaves-cn agents is vulnerable to resource consumption in the recall_relevant_memories_to_working_memory function
aiwaves-cn agents is vulnerable to resource consumption in the recall_relevant_memories_to_working_memory function