Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
CVE-2026-40114High· 7.2PraisonAI Vulnerable to Server-Side Request Forgery via Unvalidated webhook_url in Jobs API
PraisonAI Vulnerable to Server-Side Request Forgery via Unvalidated webhook_url in Jobs API
CVE-2026-40150High· 7.7PraisonAIAgents has SSRF and Local File Read via Unvalidated URLs in web_crawl Tool
PraisonAIAgents has SSRF and Local File Read via Unvalidated URLs in web_crawl Tool
CVE-2026-40178Medium· 5.9ajenti.plugin.core has race conditions in 2FA
ajenti.plugin.core has race conditions in 2FA
CVE-2026-40152Medium· 5.3PraisonAIAgents: Path Traversal via Unvalidated Glob Pattern in list_files Bypasses Workspace Boundary
PraisonAIAgents: Path Traversal via Unvalidated Glob Pattern in list_files Bypasses Workspace Boundary
CVE-2026-40149High· 7.9PraisonAI: Unauthenticated Allow-List Manipulation Bypasses Agent Tool Approval Safety Controls
PraisonAI: Unauthenticated Allow-List Manipulation Bypasses Agent Tool Approval Safety Controls
CVE-2026-40086Medium· 5.3Rembg has a Path Traversal via Custom Model Loading
Rembg has a Path Traversal via Custom Model Loading
CVE-2026-40260Medium· 5.3pypdf: Manipulated XMP metadata entity declarations can exhaust RAM
pypdf: Manipulated XMP metadata entity declarations can exhaust RAM
CVE-2026-40158High· 8.6PraisonAI Vulnerable to Code Injection and Protection Mechanism Failure
PraisonAI Vulnerable to Code Injection and Protection Mechanism Failure
CVE-2026-40115Medium· 6.2PraisonAI has Unrestricted Upload Size in WSGI Recipe Registry Server that Enables Memory Exhaustion DoS
PraisonAI has Unrestricted Upload Size in WSGI Recipe Registry Server that Enables Memory Exhaustion DoS
CVE-2026-40156High· 7.8PraisonAI Vulnerable to Implicit Execution of Arbitrary Code via Automatic `tools.py` Loading
PraisonAI Vulnerable to Implicit Execution of Arbitrary Code via Automatic `tools.py` Loading
CVE-2026-56075High· 8.8PraisonAI: Hardcoded `approval_mode="auto"` in Chainlit UI Overrides Administrator Configuration, Enabling Unapproved Shell Command Execu…
PraisonAI: Hardcoded `approval_mode="auto"` in Chainlit UI Overrides Administrator Configuration, Enabling Unapproved Shell Command Execution
CVE-2026-34538Medium· 6.5Apache Airflow has an authorization bypass in DagRun wait endpoint
Apache Airflow has an authorization bypass in DagRun wait endpoint
CVE-2025-57735Critical· 9.1Apache Airflow: JWT token still valid after logout
Apache Airflow: JWT token still valid after logout
CVE-2026-39980High· 7.2OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.5, the safeEjs.ts file …
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.5, the safeEjs.ts file does not properly sanitize EJS templates. Users with the Manage customization capability can run arb…
CVE-2026-5972High· 7.3FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
CVE-2026-5973High· 7.3FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
CVE-2026-5970High· 7.3MetaGPT has an Injection issue
MetaGPT has an Injection issue
CVE-2026-5974High· 7.3FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
CVE-2026-5971High· 7.3FoundationAgents MetaGPT vulnerable to eval injection
FoundationAgents MetaGPT vulnerable to eval injection
GHSA-69x8-hrgq-fjj8HighLiteLLM: Password hash exposure and pass-the-hash authentication bypass
LiteLLM: Password hash exposure and pass-the-hash authentication bypass
CVE-2026-5751Lowjusthtml: Mutation XSS with custom foreign-namespace sanitization policies
justhtml: Mutation XSS with custom foreign-namespace sanitization policies
CVE-2026-39844Medium· 5.9NiceGUI: Upload filename sanitization bypass via backslashes allows path traversal on Windows
NiceGUI: Upload filename sanitization bypass via backslashes allows path traversal on Windows
CVE-2026-40071Medium· 5.4pyload-ng has a WebUI JSON permission mismatch that lets ADD/DELETE users invoke MODIFY-only actions
pyload-ng has a WebUI JSON permission mismatch that lets ADD/DELETE users invoke MODIFY-only actions
CVE-2026-34589Medium· 5.0OpenEXR: DWA Lossy Decoder Heap Out-of-Bounds Write
OpenEXR: DWA Lossy Decoder Heap Out-of-Bounds Write
CVE-2026-31040Highstata-mcp has insufficient validation of user-supplied Stata do-file content that can lead to command execution
stata-mcp has insufficient validation of user-supplied Stata do-file content that can lead to command execution
CVE-2026-39891High· 8.8PraisonAI has Template Injection in Agent Tool Definitions
PraisonAI has Template Injection in Agent Tool Definitions
CVE-2026-39889High· 7.5PraisonAI Has Unauthenticated SSE Event Stream that Exposes All Agent Activity in A2U Server
PraisonAI Has Unauthenticated SSE Event Stream that Exposes All Agent Activity in A2U Server
CVE-2026-40087Medium· 5.3LangChain has incomplete f-string validation in prompt templates
LangChain has incomplete f-string validation in prompt templates
CVE-2026-1163Medium· 4.1parisneo/lollms has an insufficient session expiration vulnerability
parisneo/lollms has an insufficient session expiration vulnerability
CVE-2026-39413Medium· 4.2lightrag-hku: JWT Algorithm Confusion Vulnerability
lightrag-hku: JWT Algorithm Confusion Vulnerability