Tagged “pip”
CVEs tagged pip, newest first.
4643 CVEsRSS
CVE-2025-53890Critical· 9.8pyLoad vulnerable to XSS through insecure CAPTCHA
pyLoad vulnerable to XSS through insecure CAPTCHA
CVE-2025-29606Medium· 4.3py-libp2p is vulnerable to DoS attacks through use of large RSA keys
py-libp2p is vulnerable to DoS attacks through use of large RSA keys
CVE-2025-53640MediumPoCIndico vulnerability allows attackers to bulk dump user details
Indico vulnerability allows attackers to bulk dump user details
CVE-2025-53643LowAIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections
AIOHTTP is vulnerable to HTTP Request/Response Smuggling through incorrect parsing of chunked trailer sections
CVE-2025-30402High· 8.1ExecuTorch vulnerable to Heap-based Buffer Overflow attack
ExecuTorch vulnerable to Heap-based Buffer Overflow attack
CVE-2025-3933Medium· 5.3Transformers is vulnerable to ReDoS attack through its DonutProcessor class
Transformers is vulnerable to ReDoS attack through its DonutProcessor class
CVE-2025-6211Medium· 6.5LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class
LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class
CVE-2025-7346High· 7.5pyLoad is vulnerable to attacks that bypass localhost restrictions, enabling the creation of arbitrary packages
pyLoad is vulnerable to attacks that bypass localhost restrictions, enabling the creation of arbitrary packages
CVE-2025-3225High· 7.5LlamaIndex has an XML Entity Expansion vulnerability in its sitemap parser
LlamaIndex has an XML Entity Expansion vulnerability in its sitemap parser
CVE-2023-51232High· 7.5Dagster vulnerable to Path Traversal attack through its /logs endpoint
Dagster vulnerable to Path Traversal attack through its /logs endpoint
CVE-2025-3263Medium· 5.3Transformers's ReDoS vulnerability in get_configuration_file can lead to catastrophic backtracking
Transformers's ReDoS vulnerability in get_configuration_file can lead to catastrophic backtracking
CVE-2025-3777Low· 3.5Transformers's Improper Input Validation vulnerability can be exploited through username injection
Transformers's Improper Input Validation vulnerability can be exploited through username injection
CVE-2025-3044Medium· 5.3LlamaIndex vulnerability in ArxivReader class can cause MD5 hash collisions
LlamaIndex vulnerability in ArxivReader class can cause MD5 hash collisions
CVE-2025-3108Medium· 5.0LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component
LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component
CVE-2025-3264Medium· 5.3Transformers vulnerable to ReDoS attack through its get_imports() function
Transformers vulnerable to ReDoS attack through its get_imports() function
CVE-2025-6386High· 7.5Lord of Large Language Models vulnerable to Observable Discrepancy attack via authenticate_user function
Lord of Large Language Models vulnerable to Observable Discrepancy attack via authenticate_user function
CVE-2025-53539Mediumfastapi-guard is vulnerable to ReDoS through inefficient regex
fastapi-guard is vulnerable to ReDoS through inefficient regex
CVE-2025-3046High· 7.5LlamaIndex is vulnerable to Path Traversal attack through its ObsidianReader class
LlamaIndex is vulnerable to Path Traversal attack through its ObsidianReader class
CVE-2025-3262Medium· 5.3Transformers vulnerable to ReDoS attack through its SETTING_RE variable
Transformers vulnerable to ReDoS attack through its SETTING_RE variable
CVE-2025-5472Medium· 6.5LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing
LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing
CVE-2025-6210Medium· 6.2LlamaIndex vulnerability in its ObsidianReader class can lead to Path Traversal exploit
LlamaIndex vulnerability in its ObsidianReader class can lead to Path Traversal exploit
CVE-2025-6209High· 7.5LlamaIndex vulnerable to Path Traversal attack through its encode_image function
LlamaIndex vulnerable to Path Traversal attack through its encode_image function
CVE-2025-53365HighMCP Python SDK has Unhandled Exception in Streamable HTTP Transport, Leading to Denial of Service
MCP Python SDK has Unhandled Exception in Streamable HTTP Transport, Leading to Denial of Service
CVE-2025-53366HighMCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS
MCP Python SDK vulnerability in the FastMCP Server causes validation error, leading to DoS
CVE-2025-6853Medium· 6.3Langchain-Chatchat has a Path Traversal vulnerability
Langchain-Chatchat has a Path Traversal vulnerability
CVE-2025-6855Medium· 5.5Langchain-Chatchat vulnerable to path traversal
Langchain-Chatchat vulnerable to path traversal
CVE-2025-6854Medium· 4.3Langchain-Chatchat vulnerable to path traversal
Langchain-Chatchat vulnerable to path traversal
CVE-2025-53002High· 8.3LLaMA-Factory allows Code Injection through improper vhead_file safeguards
LLaMA-Factory allows Code Injection through improper vhead_file safeguards
CVE-2025-6773Medium· 5.3HKUDS LightRAG allows Path Traversal via function upload_to_input_dir
HKUDS LightRAG allows Path Traversal via function upload_to_input_dir
CVE-2025-52558HighChangeDetection.io XSS in watch overview
ChangeDetection.io XSS in watch overview