Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-h46j-26q3-rggf
  • PyPI/headroom-ai
Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH) 5 hours ago
  • Fix available
  • Severity - 8.8 (High)
GHSA-v2f8-6655-7grj
  • PyPI/vibe-trading-ai
Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain 6 hours ago
  • Fix available
  • Severity - 10.0 (Critical)
GHSA-5rmq-chc7-m22f
  • PyPI/vibe-trading-ai
Vibe-Trading file-read tools expose arbitrary server-readable files 6 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-jqmf-mx4f-hfr6
  • PyPI/vibe-trading-ai
Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRF 6 hours ago
  • Fix available
  • Severity - 10.0 (Critical)
GHSA-mhvh-fq92-pfmr
  • PyPI/geopy
geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point 6 hours ago
  • Fix available
  • Severity - 4.0 (Medium)
MAL-2026-17457
  • PyPI/voxeval
Malicious code in voxeval (PyPI) 7 hours ago
  • No fix available
GHSA-8mcx-5rqc-vhmf
  • PyPI/dulwich
Dulwich: Arbitrary File Write (RCE) on Windows via Unvalidated Drive Letters in Tree Paths 9 hours ago
  • Fix available
  • Severity - 8.8 (High)
GHSA-35mr-4567-66vg
  • PyPI/dulwich
Dulwich: Infinite Loop Denial of Service (DoS) in Packfile Object Resolution 10 hours ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-8w8g-wq8h-fq33
  • PyPI/dulwich
Dulwich: Symlink write-through in checkout(paths=[]) via raw os.open bypasses all symlink protections 10 hours ago
  • Fix available
  • Severity - 8.6 (High)
GHSA-5fqc-mrg8-w798
  • PyPI/dulwich
Dulwich: Symlink directory traversal in filter-branch index_filter via cross-commit state persistence 10 hours ago
  • Fix available
  • Severity - 8.6 (High)
GHSA-cm62-gvxx-vmxx
  • PyPI/dulwich
Dulwich: Symlink directory traversal in stash pop allows arbitrary file write via intermediate directory symlinks 10 hours ago
  • Fix available
  • Severity - 8.6 (High)
MAL-2026-17455
  • PyPI/dedh-devops-automation
Malicious code in dedh-devops-automation (PyPI) 14 hours ago
  • No fix available
MAL-2026-17422
  • PyPI/shortneer
Malicious code in shortneer (PyPI) yesterday
  • No fix available
MAL-2026-17421
  • PyPI/spo365-graph
Malicious code in spo365-graph (PyPI) yesterday
  • No fix available
PYSEC-2026-4059
  • PyPI/jupyterlite-core
JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language package (jupyterlab.json) yesterday
  • Fix available
  • Severity - 6.8 (Medium)
PYSEC-2026-4056
  • PyPI/jupyterlab
JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language package (jupyterlab.json) yesterday
  • Fix available
  • Severity - 6.8 (Medium)