VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2026-44209High· 7.5
4mo ago

banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI

banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI

▾ Twilightbanks · banksEPSS 0.74%via OSV
CVE-2026-44844Medium
4mo ago

eml_parser has recursion DoS via nested message/rfc822 attachments

eml_parser has recursion DoS via nested message/rfc822 attachments

▾ Sunliteml-parser · eml-parserEPSS 0.43%via OSV
CVE-2026-44568Medium· 4.8
4mo ago

Open WebUI has Stored XSS in Pending User Overlay via Incorrect DOMPurify Application Order

Open WebUI has Stored XSS in Pending User Overlay via Incorrect DOMPurify Application Order

▾ Sunlitopen-webui · open-webuiEPSS 0.25%via OSV
CVE-2026-44502Medium· 4.3
4mo ago

Bunsink has an SSRF bypass in `validate_webhook_url`

Bunsink has an SSRF bypass in `validate_webhook_url`

▾ Sunlitbugsink · bugsinkEPSS 0.39%via OSV
CVE-2026-44559Medium· 4.3
4mo ago

Open WebUI Missing Access Check on Channel Members Endpoint for Standard Channels

Open WebUI Missing Access Check on Channel Members Endpoint for Standard Channels

▾ Sunlitopen-webui · open-webuiEPSS 0.30%via OSV
CVE-2026-44555High· 7.6
4mo ago

Open WebUI's Base Model Routing Bypasses Access Control via Model Chaining

Open WebUI's Base Model Routing Bypasses Access Control via Model Chaining

▾ Twilightopen-webui · open-webuiEPSS 0.35%via OSV
CVE-2026-44566High· 7.3
4mo ago

Open WebUI Vulnerable to Arbitrary File Upload and Path Traversal

Open WebUI Vulnerable to Arbitrary File Upload and Path Traversal

▾ Twilightopen-webui · open-webuiEPSS 0.46%via OSV
CVE-2026-44708Medium· 6.1
4mo ago

Mistune Math Plugin has an XSS Escape Bypass

Mistune Math Plugin has an XSS Escape Bypass

▾ Sunlitmistune · mistuneEPSS 0.27%via OSV
CVE-2026-44558Medium· 5.4
4mo ago

Open WebUI's Channel Access Grants Bypass filter_allowed_access_grants

Open WebUI's Channel Access Grants Bypass filter_allowed_access_grants

▾ Sunlitopen-webui · open-webuiEPSS 0.27%via OSV
CVE-2026-44554High· 8.1
4mo ago

Open WebUI has Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwrite

Open WebUI has Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwrite

▾ Twilightopen-webui · open-webuiEPSS 0.43%via OSV
CVE-2026-44557Medium· 4.3
4mo ago

Open WebUI vulnerable to Global Knowledge Base Enumeration via knowledge-bases Meta-Collection

Open WebUI vulnerable to Global Knowledge Base Enumeration via knowledge-bases Meta-Collection

▾ Sunlitopen-webui · open-webuiEPSS 0.30%via OSV
CVE-2026-44567High· 7.3
4mo ago

Open WebUI has Improper Authorization Control

Open WebUI has Improper Authorization Control

▾ Twilightopen-webui · open-webuiEPSS 0.34%via OSV
CVE-2026-44553High· 8.1
4mo ago

Open WebUI: Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access

Open WebUI: Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access

▾ Twilightopen-webui · open-webuiEPSS 0.39%via OSV
CVE-2026-44552High· 8.7
4mo ago

Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning

Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning

▾ Twilightopen-webui · open-webuiEPSS 0.42%via OSV
CVE-2026-42271High· 8.8CISA KEVPoC
4mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /m…

▾ Abyssallitellm · litellmEPSS 13%via NVD
CVE-2026-42208Critical· 9.8CISA KEV0dayPoC
4mo ago

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query tex…

▾ Hadallitellm · litellmEPSS 5.8%via NVD
CVE-2026-44484Critical· 9.8
4mo ago

Compromise of PyTorch Lightning PyPi Package Versions

Compromise of PyTorch Lightning PyPi Package Versions

▾ Midnightpytorch-lightning · pytorch-lightningEPSS 0.67%via OSV
CVE-2026-8086High· 7.8
4mo ago

A vulnerability was identified in OSGeo gdal up to 3.13.0dev-4. This issue affects the function SWnentries of the file frmts/hdf4/hdf-eos…

A vulnerability was identified in OSGeo gdal up to 3.13.0dev-4. This issue affects the function SWnentries of the file frmts/hdf4/hdf-eos/SWapi.c. Such manipulation of the argument DimensionName leads to heap-based buffer overflow. The a…

▾ Twilightgdal · gdalEPSS 0.27%via OSV
CVE-2026-8084Medium· 5.5
4mo ago

A vulnerability was determined in OSGeo gdal up to 3.13.0dev-4. This vulnerability affects the function memmove of the file frmts/hdf4/hd…

A vulnerability was determined in OSGeo gdal up to 3.13.0dev-4. This vulnerability affects the function memmove of the file frmts/hdf4/hdf-eos/SWapi.c of the component HDF-EOS Grid File Handler. This manipulation causes out-of-bounds rea…

▾ Sunlitgdal · gdalEPSS 0.22%via OSV
CVE-2026-44641High· 7.1
4mo ago

Microsoft APM CLI's plugin.json component paths escape plugin root and copy arbitrary host files during install

Microsoft APM CLI's plugin.json component paths escape plugin root and copy arbitrary host files during install

▾ Twilightapm-cli · apm-cliEPSS 0.53%via OSV
CVE-2026-42284High· 7.5
4mo ago

GitPython: GitPython: Arbitrary code execution via improper validation of clone options (CVE-2026-42284)

A flaw was found in GitPython, a Python library for interacting with Git repositories. A remote attacker could exploit an input validation vulnerability in the `_clone()` function. By crafting a malicious string in the `multi_options` para…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.71%via CSAF
CVE-2026-44244High· 7.3
4mo ago

GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration (CVE-2026-44244)

A flaw was found in GitPython, a Python library used to interact with Git repositories. The `GitConfigParser.set_value()` function does not properly validate input for newlines. This vulnerability allows an attacker to inject malicious con…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.22%via CSAF
CVE-2026-42215High· 7.5
4mo ago

GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks (CVE-2026-42215)

A flaw was found in GitPython, a Python library used to interact with Git repositories. This vulnerability allows an attacker to achieve arbitrary command execution by providing specially crafted arguments (kwargs) to functions such as Rep…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.90%via CSAF
CVE-2026-44742High· 7.2
4mo ago

Postorius is vulnerable to XSS

Postorius is vulnerable to XSS

▾ Twilightpostorius · postoriusEPSS 0.33%via OSV
CVE-2026-40610Medium· 5.5
4mo ago

BentoML has Information Disclosure in `bentoml build` via symlink traversal in the build context

BentoML has Information Disclosure in `bentoml build` via symlink traversal in the build context

▾ Sunlitbentoml · bentomlEPSS 0.20%via OSV
CVE-2026-44504High
4mo ago

Aegra has cross-user run injection in /threads/{thread_id}/runs (IDOR)

Aegra has cross-user run injection in /threads/{thread_id}/runs (IDOR)

▾ Twilightaegra-api · aegra-apiEPSS 0.35%via OSV
CVE-2026-8088Low· 3.3
4mo ago

OSGeo GDAL vulnerable to out-of-bounds read

OSGeo GDAL vulnerable to out-of-bounds read

▾ Sunlitgdal · gdalEPSS 0.21%via OSV
CVE-2026-8087Medium· 5.3
4mo ago

OSGeo GDAL vulnerable to heap-based buffer overflow

OSGeo GDAL vulnerable to heap-based buffer overflow

▾ Sunlitgdal · gdalEPSS 0.26%via OSV
CVE-2026-44263Medium· 4.3
4mo ago

Weblate Vulnerable to Private Translation Enumeration via Screenshot API

Weblate Vulnerable to Private Translation Enumeration via Screenshot API

▾ Sunlitweblate · weblateEPSS 0.38%via OSV
CVE-2026-44520Medium· 5.7
4mo ago

docling-graph has SSRF via Missing Internal IP Validation in URLInputHandler

docling-graph has SSRF via Missing Internal IP Validation in URLInputHandler

▾ Sunlitdocling-graph · docling-graphEPSS 0.31%via OSV
CVEs tagged “pip” — page 61 · VulnSea