VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2026-25219Medium· 6.5
5mo ago

Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access

Apache Airlfow: Sensitive Azure Service Bus connection string (and possibly other providers) exposed to users with view access

▾ Sunlitapache-airflow · apache-airflowEPSS 0.55%via OSV
CVE-2026-40192High· 7.5
5mo ago

Pillow is a Python imaging library

Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially crafted FITS file coul…

▾ Twilightpython · pillowEPSS 0.87%via NVD
CVE-2026-7808Low
5mo ago

Multiple security fixes in justhtml

Multiple security fixes in justhtml

▾ Sunlitjusthtml · justhtmlEPSS 0.59%via OSV
CVE-2026-40319Medium· 5.5
5mo ago

Giskard has a Regular Expression Denial of Service (ReDoS) in RegexMatching Check

Giskard has a Regular Expression Denial of Service (ReDoS) in RegexMatching Check

▾ Sunlitgiskard-checks · giskard-checksEPSS 0.16%via OSV
CVE-2026-40683High· 7.7
5mo ago

OpenStack Keystone: OpenStack Keystone: Unauthorized access due to incorrect LDAP user status handling (CVE-2026-40683)

A flaw was found in OpenStack Keystone. When using the LDAP identity backend, the system incorrectly processes the user enabled attribute if the user_enabled_invert configuration option is set to False. This error causes users marked as di…

▾ TwilightRed Hat · Red Hat OpenStack Platform 13 (Queens)EPSS 0.37%via CSAF
CVE-2026-40320High· 7.8
5mo ago

Giskard has Unsandboxed Jinja2 Template Rendering in ConformityCheck

Giskard has Unsandboxed Jinja2 Template Rendering in ConformityCheck

▾ Twilightgiskard-checks · giskard-checksEPSS 0.21%via OSV
CVE-2026-40491Medium· 6.5
5mo ago

gdown Affected by Arbitrary File Write via Path Traversal in gdown.extractall

gdown Affected by Arbitrary File Write via Path Traversal in gdown.extractall

▾ Sunlitgdown · gdownEPSS 0.77%via OSV
CVE-2026-41133High· 8.8
5mo ago

pyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass)

pyLoad has Stale Session Privilege After Role/Permission Change (Privilege Revocation Bypass)

▾ Twilightpyload-ng · pyload-ngEPSS 0.47%via OSV
CVE-2025-66236High· 7.5
5mo ago

Apache Airflow: Secrets from Airflow config file logged in plain text in DAG run logs UI

Before Airflow 3.2.0, it was unclear that secure Airflow deployments require the Deployment Manager to take appropriate actions and pay attention to security details and security model of Airflow. Some assumptions the Deployment Manager …

▾ TwilightApache Software Foundation · apache-airflowEPSS 0.44%via CVEORG
CVE-2026-1462High· 7.8
5mo ago

A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`

A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This bypasses the secu…

▾ Twilightkeras · kerasEPSS 0.40%via NVD
CVE-2026-1116Medium· 6.1
5mo ago

A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in parisneo/lollms pr…

A Cross-site Scripting (XSS) vulnerability was identified in the `from_dict` method of the `AppLollmsMessage` class in parisneo/lollms prior to version 2.2.0. The vulnerability arises from the lack of sanitization or HTML encoding of the…

▾ Sunlitlollms · lollmsEPSS 0.26%via OSV
CVE-2026-6110High· 7.3
5mo ago

MetaGPT has an eval injection in metagpt/strategy/tot.py

MetaGPT has an eval injection in metagpt/strategy/tot.py

▾ Twilightmetagpt · metagptEPSS 0.71%via OSV
CVE-2026-6109Medium· 4.3
5mo ago

MetaGPT has an eval injection via a cross-site request forgery attack

MetaGPT has an eval injection via a cross-site request forgery attack

▾ Sunlitmetagpt · metagptEPSS 0.29%via OSV
CVE-2026-6111Medium· 6.3PoC
5mo ago

MetaGPT affected by server-side request forgery in metagpt/utils/common.py

MetaGPT affected by server-side request forgery in metagpt/utils/common.py

▾ Twilightmetagpt · metagptEPSS 0.37%via OSV
GHSA-x462-jjpc-q4q4High· 8.1
5mo ago

PraisonAI: Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpoint

PraisonAI: Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpoint

▾ Twilightpraisonaiagents · praisonaiagentsvia OSV
GHSA-pjjw-68hj-v9mwLow
5mo ago

uv vulnerable to arbitrary file deletion through RECORD entries

uv vulnerable to arbitrary file deletion through RECORD entries

▾ Sunlituv · uvvia OSV
CVE-2026-5388Medium
5mo ago

justhtml includes multiple security fixes

justhtml includes multiple security fixes

▾ Sunlitjusthtml · justhtmlEPSS 0.59%via OSV
CVE-2026-39921Medium· 6.3
5mo ago

GeoNode versions 4.0 before 4.4.5 and 5.0 before 5.0.2 contain a server-side request forgery vulnerability that allows authenticated user…

GeoNode versions 4.0 before 4.4.5 and 5.0 before 5.0.2 contain a server-side request forgery vulnerability that allows authenticated users with document upload permissions to trigger arbitrary outbound HTTP requests by providing a malici…

▾ Sunlitgeonode · geonodeEPSS 0.37%via OSV
CVE-2026-40315Medium
5mo ago

PraisonAI: SQLiteConversationStore didn't validate table_prefix when constructing SQL queries

PraisonAI: SQLiteConversationStore didn't validate table_prefix when constructing SQL queries

▾ Sunlitpraisonai · praisonaiEPSS 0.40%via OSV
CVE-2026-40153High· 7.4
5mo ago

PraisonAIAgents: Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell Tool

PraisonAIAgents: Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell Tool

▾ Twilightpraisonaiagents · praisonaiagentsEPSS 0.39%via OSV
CVE-2026-40160High
5mo ago

PraisonAIAgents: SSRF via unvalidated URL in `web_crawl` httpx fallback

PraisonAIAgents: SSRF via unvalidated URL in `web_crawl` httpx fallback

▾ Twilightpraisonaiagents · praisonaiagentsEPSS 0.40%via OSV
CVE-2026-40116High· 7.5
5mo ago

PraisonAI: Unauthenticated WebSocket Endpoint Proxies to Paid OpenAI Realtime API Without Rate Limits

PraisonAI: Unauthenticated WebSocket Endpoint Proxies to Paid OpenAI Realtime API Without Rate Limits

▾ Twilightpraisonai · praisonaiEPSS 0.57%via OSV
CVE-2026-40151Medium· 5.3PoC
5mo ago

PraisonAI: Unauthenticated Information Disclosure of Agent Instructions via /api/agents in AgentOS

PraisonAI: Unauthenticated Information Disclosure of Agent Instructions via /api/agents in AgentOS

▾ Twilightpraisonai · praisonaiEPSS 0.84%via OSV
CVE-2026-40159Medium· 5.5
5mo ago

PraisonAI Vulnerable to Sensitive Environment Variable Exposure via Untrusted MCP Subprocess Execution

PraisonAI Vulnerable to Sensitive Environment Variable Exposure via Untrusted MCP Subprocess Execution

▾ Sunlitpraisonai · praisonaiEPSS 0.18%via OSV
CVE-2026-40117Medium· 6.2
5mo ago

PraisonAIAgents: Arbitrary File Read via read_skill_file Missing Workspace Boundary and Approval Gate

PraisonAIAgents: Arbitrary File Read via read_skill_file Missing Workspace Boundary and Approval Gate

▾ Sunlitpraisonaiagents · praisonaiagentsEPSS 0.33%via OSV
CVE-2026-40287High· 8.4
5mo ago

PraisonAI Vulnerable to RCE via Automatic tools.py Import

PraisonAI Vulnerable to RCE via Automatic tools.py Import

▾ Twilightpraisonaiagents · praisonaiagentsEPSS 0.23%via OSV
CVE-2026-40113High· 8.4
5mo ago

PraisonAI Vulnerable to Argument Injection into Cloud Run Environment Variables via Unsanitized Comma in gcloud --set-env-vars

PraisonAI Vulnerable to Argument Injection into Cloud Run Environment Variables via Unsanitized Comma in gcloud --set-env-vars

▾ Twilightpraisonai · praisonaiEPSS 0.33%via OSV
CVE-2026-40148Medium· 6.5
5mo ago

PraisonAI Vulnerable to Decompression Bomb DoS via Recipe Bundle Extraction Without Size Limits

PraisonAI Vulnerable to Decompression Bomb DoS via Recipe Bundle Extraction Without Size Limits

▾ Sunlitpraisonai · praisonaiEPSS 0.38%via OSV
CVE-2026-40112Medium· 5.4
5mo ago

PraisonAI Vulnerable to Stored XSS via Unsanitized Agent Output in HTML Rendering (nh3 Not a Required Dependency)

PraisonAI Vulnerable to Stored XSS via Unsanitized Agent Output in HTML Rendering (nh3 Not a Required Dependency)

▾ Sunlitpraisonai · praisonaiEPSS 0.26%via OSV
CVE-2026-40162High· 7.1
5mo ago

Bugsink affected by authenticated arbitrary file write in artifactbundle/assemble

Bugsink affected by authenticated arbitrary file write in artifactbundle/assemble

▾ Twilightbugsink · bugsinkEPSS 0.51%via OSV
CVEs tagged “pip” — page 67 · VulnSea