Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
CVE-2026-44209High· 7.5banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
CVE-2026-44844Mediumeml_parser has recursion DoS via nested message/rfc822 attachments
eml_parser has recursion DoS via nested message/rfc822 attachments
CVE-2026-44568Medium· 4.8Open WebUI has Stored XSS in Pending User Overlay via Incorrect DOMPurify Application Order
Open WebUI has Stored XSS in Pending User Overlay via Incorrect DOMPurify Application Order
CVE-2026-44502Medium· 4.3Bunsink has an SSRF bypass in `validate_webhook_url`
Bunsink has an SSRF bypass in `validate_webhook_url`
CVE-2026-44559Medium· 4.3Open WebUI Missing Access Check on Channel Members Endpoint for Standard Channels
Open WebUI Missing Access Check on Channel Members Endpoint for Standard Channels
CVE-2026-44555High· 7.6Open WebUI's Base Model Routing Bypasses Access Control via Model Chaining
Open WebUI's Base Model Routing Bypasses Access Control via Model Chaining
CVE-2026-44566High· 7.3Open WebUI Vulnerable to Arbitrary File Upload and Path Traversal
Open WebUI Vulnerable to Arbitrary File Upload and Path Traversal
CVE-2026-44708Medium· 6.1Mistune Math Plugin has an XSS Escape Bypass
Mistune Math Plugin has an XSS Escape Bypass
CVE-2026-44558Medium· 5.4Open WebUI's Channel Access Grants Bypass filter_allowed_access_grants
Open WebUI's Channel Access Grants Bypass filter_allowed_access_grants
CVE-2026-44554High· 8.1Open WebUI has Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwrite
Open WebUI has Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwrite
CVE-2026-44557Medium· 4.3Open WebUI vulnerable to Global Knowledge Base Enumeration via knowledge-bases Meta-Collection
Open WebUI vulnerable to Global Knowledge Base Enumeration via knowledge-bases Meta-Collection
CVE-2026-44567High· 7.3Open WebUI has Improper Authorization Control
Open WebUI has Improper Authorization Control
CVE-2026-44553High· 8.1Open WebUI: Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access
Open WebUI: Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access
CVE-2026-44552High· 8.7Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning
Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning
CVE-2026-42271High· 8.8CISA KEVPoCLiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /m…
CVE-2026-42208Critical· 9.8CISA KEV0dayPoCLiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to before version 1.83.7, a database query used during proxy API key checks mixed the caller-supplied key value into the query tex…
CVE-2026-44484Critical· 9.8Compromise of PyTorch Lightning PyPi Package Versions
Compromise of PyTorch Lightning PyPi Package Versions
CVE-2026-8086High· 7.8A vulnerability was identified in OSGeo gdal up to 3.13.0dev-4. This issue affects the function SWnentries of the file frmts/hdf4/hdf-eos…
A vulnerability was identified in OSGeo gdal up to 3.13.0dev-4. This issue affects the function SWnentries of the file frmts/hdf4/hdf-eos/SWapi.c. Such manipulation of the argument DimensionName leads to heap-based buffer overflow. The a…
CVE-2026-8084Medium· 5.5A vulnerability was determined in OSGeo gdal up to 3.13.0dev-4. This vulnerability affects the function memmove of the file frmts/hdf4/hd…
A vulnerability was determined in OSGeo gdal up to 3.13.0dev-4. This vulnerability affects the function memmove of the file frmts/hdf4/hdf-eos/SWapi.c of the component HDF-EOS Grid File Handler. This manipulation causes out-of-bounds rea…
CVE-2026-44641High· 7.1Microsoft APM CLI's plugin.json component paths escape plugin root and copy arbitrary host files during install
Microsoft APM CLI's plugin.json component paths escape plugin root and copy arbitrary host files during install
CVE-2026-42284High· 7.5GitPython: GitPython: Arbitrary code execution via improper validation of clone options (CVE-2026-42284)
A flaw was found in GitPython, a Python library for interacting with Git repositories. A remote attacker could exploit an input validation vulnerability in the `_clone()` function. By crafting a malicious string in the `multi_options` para…
CVE-2026-44244High· 7.3GitPython: GitPython: Arbitrary code execution via injected newlines in Git configuration (CVE-2026-44244)
A flaw was found in GitPython, a Python library used to interact with Git repositories. The `GitConfigParser.set_value()` function does not properly validate input for newlines. This vulnerability allows an attacker to inject malicious con…
CVE-2026-42215High· 7.5GitPython: GitPython: Arbitrary command execution due to bypass of dangerous Git option checks (CVE-2026-42215)
A flaw was found in GitPython, a Python library used to interact with Git repositories. This vulnerability allows an attacker to achieve arbitrary command execution by providing specially crafted arguments (kwargs) to functions such as Rep…
CVE-2026-44742High· 7.2Postorius is vulnerable to XSS
Postorius is vulnerable to XSS
CVE-2026-40610Medium· 5.5BentoML has Information Disclosure in `bentoml build` via symlink traversal in the build context
BentoML has Information Disclosure in `bentoml build` via symlink traversal in the build context
CVE-2026-44504HighAegra has cross-user run injection in /threads/{thread_id}/runs (IDOR)
Aegra has cross-user run injection in /threads/{thread_id}/runs (IDOR)
CVE-2026-8088Low· 3.3OSGeo GDAL vulnerable to out-of-bounds read
OSGeo GDAL vulnerable to out-of-bounds read
CVE-2026-8087Medium· 5.3OSGeo GDAL vulnerable to heap-based buffer overflow
OSGeo GDAL vulnerable to heap-based buffer overflow
CVE-2026-44263Medium· 4.3Weblate Vulnerable to Private Translation Enumeration via Screenshot API
Weblate Vulnerable to Private Translation Enumeration via Screenshot API
CVE-2026-44520Medium· 5.7docling-graph has SSRF via Missing Internal IP Validation in URLInputHandler
docling-graph has SSRF via Missing Internal IP Validation in URLInputHandler