VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2026-40114High· 7.2
5mo ago

PraisonAI Vulnerable to Server-Side Request Forgery via Unvalidated webhook_url in Jobs API

PraisonAI Vulnerable to Server-Side Request Forgery via Unvalidated webhook_url in Jobs API

▾ Twilightpraisonai · praisonaiEPSS 0.34%via OSV
CVE-2026-40150High· 7.7
5mo ago

PraisonAIAgents has SSRF and Local File Read via Unvalidated URLs in web_crawl Tool

PraisonAIAgents has SSRF and Local File Read via Unvalidated URLs in web_crawl Tool

▾ Twilightpraisonaiagents · praisonaiagentsEPSS 0.38%via OSV
CVE-2026-40178Medium· 5.9
5mo ago

ajenti.plugin.core has race conditions in 2FA

ajenti.plugin.core has race conditions in 2FA

▾ Sunlitajenti-plugin-core · ajenti-plugin-coreEPSS 0.28%via OSV
CVE-2026-40152Medium· 5.3
5mo ago

PraisonAIAgents: Path Traversal via Unvalidated Glob Pattern in list_files Bypasses Workspace Boundary

PraisonAIAgents: Path Traversal via Unvalidated Glob Pattern in list_files Bypasses Workspace Boundary

▾ Sunlitpraisonaiagents · praisonaiagentsEPSS 0.40%via OSV
CVE-2026-40149High· 7.9
5mo ago

PraisonAI: Unauthenticated Allow-List Manipulation Bypasses Agent Tool Approval Safety Controls

PraisonAI: Unauthenticated Allow-List Manipulation Bypasses Agent Tool Approval Safety Controls

▾ Twilightpraisonai · praisonaiEPSS 0.16%via OSV
CVE-2026-40086Medium· 5.3
5mo ago

Rembg has a Path Traversal via Custom Model Loading

Rembg has a Path Traversal via Custom Model Loading

▾ Sunlitrembg · rembgEPSS 0.59%via OSV
CVE-2026-40260Medium· 5.3
5mo ago

pypdf: Manipulated XMP metadata entity declarations can exhaust RAM

pypdf: Manipulated XMP metadata entity declarations can exhaust RAM

▾ Sunlitpypdf · pypdfEPSS 0.52%via OSV
CVE-2026-40158High· 8.6
5mo ago

PraisonAI Vulnerable to Code Injection and Protection Mechanism Failure

PraisonAI Vulnerable to Code Injection and Protection Mechanism Failure

▾ Twilightpraisonai · praisonaiEPSS 0.22%via OSV
CVE-2026-40115Medium· 6.2
5mo ago

PraisonAI has Unrestricted Upload Size in WSGI Recipe Registry Server that Enables Memory Exhaustion DoS

PraisonAI has Unrestricted Upload Size in WSGI Recipe Registry Server that Enables Memory Exhaustion DoS

▾ Sunlitpraisonai · praisonaiEPSS 0.41%via OSV
CVE-2026-40156High· 7.8
5mo ago

PraisonAI Vulnerable to Implicit Execution of Arbitrary Code via Automatic `tools.py` Loading

PraisonAI Vulnerable to Implicit Execution of Arbitrary Code via Automatic `tools.py` Loading

▾ Twilightpraisonai · praisonaiEPSS 0.23%via OSV
CVE-2026-56075High· 8.8
5mo ago

PraisonAI: Hardcoded `approval_mode="auto"` in Chainlit UI Overrides Administrator Configuration, Enabling Unapproved Shell Command Execu…

PraisonAI: Hardcoded `approval_mode="auto"` in Chainlit UI Overrides Administrator Configuration, Enabling Unapproved Shell Command Execution

▾ Twilightpraisonai · praisonaiEPSS 0.71%via OSV
CVE-2026-34538Medium· 6.5
5mo ago

Apache Airflow has an authorization bypass in DagRun wait endpoint

Apache Airflow has an authorization bypass in DagRun wait endpoint

▾ Sunlitapache-airflow · apache-airflowEPSS 0.79%via OSV
CVE-2025-57735Critical· 9.1
5mo ago

Apache Airflow: JWT token still valid after logout

Apache Airflow: JWT token still valid after logout

▾ Midnightapache-airflow · apache-airflowEPSS 0.67%via OSV
CVE-2026-39980High· 7.2
5mo ago

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.5, the safeEjs.ts file …

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.5, the safeEjs.ts file does not properly sanitize EJS templates. Users with the Manage customization capability can run arb…

▾ Twilightpycti · pyctiEPSS 0.69%via OSV
CVE-2026-5972High· 7.3
5mo ago

FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command

FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command

▾ Twilightmetagpt · metagptEPSS 3.5%via OSV
CVE-2026-5973High· 7.3
5mo ago

FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py

FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py

▾ Twilightmetagpt · metagptEPSS 3.5%via OSV
CVE-2026-5970High· 7.3
5mo ago

MetaGPT has an Injection issue

MetaGPT has an Injection issue

▾ Twilightmetagpt · metagptEPSS 0.71%via OSV
CVE-2026-5974High· 7.3
5mo ago

FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py

FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py

▾ Twilightmetagpt · metagptEPSS 3.5%via OSV
CVE-2026-5971High· 7.3
5mo ago

FoundationAgents MetaGPT vulnerable to eval injection

FoundationAgents MetaGPT vulnerable to eval injection

▾ Twilightmetagpt · metagptEPSS 0.71%via OSV
GHSA-69x8-hrgq-fjj8High
5mo ago

LiteLLM: Password hash exposure and pass-the-hash authentication bypass

LiteLLM: Password hash exposure and pass-the-hash authentication bypass

▾ Twilightlitellm · litellmvia OSV
CVE-2026-5751Low
5mo ago

justhtml: Mutation XSS with custom foreign-namespace sanitization policies

justhtml: Mutation XSS with custom foreign-namespace sanitization policies

▾ Sunlitjusthtml · justhtmlEPSS 0.26%via OSV
CVE-2026-39844Medium· 5.9
5mo ago

NiceGUI: Upload filename sanitization bypass via backslashes allows path traversal on Windows

NiceGUI: Upload filename sanitization bypass via backslashes allows path traversal on Windows

▾ Sunlitnicegui · niceguiEPSS 0.49%via OSV
CVE-2026-40071Medium· 5.4
5mo ago

pyload-ng has a WebUI JSON permission mismatch that lets ADD/DELETE users invoke MODIFY-only actions

pyload-ng has a WebUI JSON permission mismatch that lets ADD/DELETE users invoke MODIFY-only actions

▾ Sunlitpyload-ng · pyload-ngEPSS 0.32%via OSV
CVE-2026-34589Medium· 5.0
5mo ago

OpenEXR: DWA Lossy Decoder Heap Out-of-Bounds Write

OpenEXR: DWA Lossy Decoder Heap Out-of-Bounds Write

▾ Sunlitopenexr · openexrEPSS 0.48%via OSV
CVE-2026-31040High
5mo ago

stata-mcp has insufficient validation of user-supplied Stata do-file content that can lead to command execution

stata-mcp has insufficient validation of user-supplied Stata do-file content that can lead to command execution

▾ Twilightstata-mcp · stata-mcpEPSS 1.1%via OSV
CVE-2026-39891High· 8.8
5mo ago

PraisonAI has Template Injection in Agent Tool Definitions

PraisonAI has Template Injection in Agent Tool Definitions

▾ Twilightpraisonai · praisonaiEPSS 0.56%via OSV
CVE-2026-39889High· 7.5
5mo ago

PraisonAI Has Unauthenticated SSE Event Stream that Exposes All Agent Activity in A2U Server

PraisonAI Has Unauthenticated SSE Event Stream that Exposes All Agent Activity in A2U Server

▾ Twilightpraisonai · praisonaiEPSS 0.48%via OSV
CVE-2026-40087Medium· 5.3
5mo ago

LangChain has incomplete f-string validation in prompt templates

LangChain has incomplete f-string validation in prompt templates

▾ Sunlitlangchain-core · langchain-coreEPSS 0.45%via OSV
CVE-2026-1163Medium· 4.1
5mo ago

parisneo/lollms has an insufficient session expiration vulnerability

parisneo/lollms has an insufficient session expiration vulnerability

▾ Sunlitlollms · lollmsEPSS 0.23%via OSV
CVE-2026-39413Medium· 4.2
5mo ago

lightrag-hku: JWT Algorithm Confusion Vulnerability

lightrag-hku: JWT Algorithm Confusion Vulnerability

▾ Sunlitlightrag-hku · lightrag-hkuEPSS 0.21%via OSV
CVEs tagged “pip” — page 68 · VulnSea