Tagged “pip”
CVEs tagged pip, newest first.
4637 CVEsRSS
MAL-2026-16136Critical⚠ ExploitedMalicious code in transfomers (PyPI)
Malicious code in transfomers (PyPI)
MAL-2026-16135Critical⚠ ExploitedMalicious code in openaii (PyPI)
Malicious code in openaii (PyPI)
MAL-2026-16134Critical⚠ ExploitedMalicious code in ollamaa (PyPI)
Malicious code in ollamaa (PyPI)
MAL-2026-16133Critical⚠ ExploitedMalicious code in langgrap (PyPI)
Malicious code in langgrap (PyPI)
MAL-2026-16131Critical⚠ ExploitedMalicious code in aitextutils-py (PyPI)
Malicious code in aitextutils-py (PyPI)
MAL-2026-16130Critical⚠ ExploitedMalicious code in aitextkit-py (PyPI)
Malicious code in aitextkit-py (PyPI)
MAL-2026-16129Critical⚠ ExploitedMalicious code in web3-eth-account (PyPI)
Malicious code in web3-eth-account (PyPI)
MAL-2026-16128Critical⚠ ExploitedMalicious code in pymem-win (PyPI)
Malicious code in pymem-win (PyPI)
MAL-2026-16127Critical⚠ ExploitedMalicious code in eth-account-web3 (PyPI)
Malicious code in eth-account-web3 (PyPI)
CVE-2026-59151Critical· 9.6Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover
Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover
MAL-2026-16125Critical⚠ ExploitedMalicious code in lucy-python-script-2030 (PyPI)
Malicious code in lucy-python-script-2030 (PyPI)
MAL-2026-16122Critical⚠ ExploitedMalicious code in pylever (PyPI)
Malicious code in pylever (PyPI)
CVE-2026-49836Medium· 4.6PoCpsd-tools: arbitrary file write via smart-object filename
psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.17.1, `SmartObject.save()` writes an embedded smart object to a path taken verbatim from the PSD file. Because that name is attacker-controlled …
MAL-2026-16121Critical⚠ ExploitedMalicious code in websetup (PyPI)
Malicious code in websetup (PyPI)
CVE-2026-59177High· 8.8PoCESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces
ESPHome Device Builder Dashboard: Unauthenticated dashboard access via the HA add-on ingress site bound to all interfaces
CVE-2026-87012Medium· 4.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, backend/open_webui/models/calendar.py stored the calendar event meta.alert_minutes value without type validation and the share…
CVE-2026-87014Medium· 6.5PoCOpen WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, role synchronization in backend/open_webui/routers/auths.py and backend/open_webui/utils/oauth.py updated an administrator's d…
CVE-2026-87818Medium· 6.5PoCGitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands
GitPython 3.1.59 fails to restrict the --no-index option in the high-level diff API, allowing attackers to read arbitrary filesystem paths as repository operands. Attackers can combine --no-index with -I/--ignore-matching-lines to create…
MAL-2026-16099Critical⚠ ExploitedMalicious code in bq-sdist-probe-vrp (PyPI)
Malicious code in bq-sdist-probe-vrp (PyPI)
MAL-2026-16098Critical⚠ ExploitedMalicious code in bq-build-probe-vrp-2026 (PyPI)
Malicious code in bq-build-probe-vrp-2026 (PyPI)
MAL-2026-16080Critical⚠ ExploitedMalicious code in databricks-webapp-navigation-homepage (PyPI)
Malicious code in databricks-webapp-navigation-homepage (PyPI)
CVE-2026-87996High· 7.7Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.1, SafePlaywrightURLLoader in backend/open_webui/retrieval/web/utils.py validated a user-controlled hostname in Python and then l…
CVE-2026-87817High· 8.8GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD
GitPython before 3.1.60 fails to properly validate the git directory location, allowing attackers to impersonate the git directory using tracked files like gitdir, commondir, and HEAD. Attackers can execute arbitrary code by placing a ma…
CVE-2026-87819High· 7.5GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields
GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containi…
CVE-2026-12259Medium· 5.3NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection
NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection
CVE-2026-78675High· 8.4⚖ disputedGitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables…
GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)
CVE-2026-80206HighNLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions
NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions
CVE-2026-78681HighNLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses
NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses
CVE-2026-79676HighNLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement
NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement
CVE-2026-79657CriticalNLTK: Allowlisted pickle loaders still permit code execution in current source
NLTK: Allowlisted pickle loaders still permit code execution in current source