Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-q986-4x7x-gx39
  • PyPI/scbe-aethermoore
SCBE-AETHERMOORE Unauthenticated AetherBrowser Ops API Exposes Operator Email Digests 3 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-62mm-xwmv-crhg
  • PyPI/khoj
khoj has an unauthenticated path traversal in /home/ endpoint that allows file read from server filesystem 3 hours ago
  • Fix available
  • Severity - 8.7 (High)
MAL-2026-17188
  • PyPI/sherpy
Malicious code in sherpy (PyPI) 3 hours ago
  • No fix available
MAL-2026-17183
  • PyPI/tego-managed-agents-test
Malicious code in tego-managed-agents-test (PyPI) 14 hours ago
  • No fix available
MAL-2026-17181
  • PyPI/reqparser
Malicious code in reqparser (PyPI) 18 hours ago
  • No fix available
MAL-2026-17180
  • PyPI/my-private-pkg
Malicious code in my-private-pkg (PyPI) yesterday
  • No fix available
MAL-2026-17168
  • PyPI/vercel-runtime-python
Malicious code in vercel-runtime-python (PyPI) yesterday
  • No fix available
MAL-2026-17167
  • PyPI/prosocks
Malicious code in prosocks (PyPI) yesterday
  • No fix available
GHSA-vqg6-3fw6-j9jg
  • PyPI/social-auth-core
social-auth-core has a Session Fixation issue yesterday
  • Fix available
  • Severity - 4.2 (Medium)
GHSA-3c93-f73f-qc9h
  • PyPI/social-auth-core
social-auth-core: VK App backend accepts unsigned callback data when auth_key is missing yesterday
  • Fix available
  • Severity - 7.4 (High)
GHSA-x7qq-23vw-7pfg
  • PyPI/social-auth-core
social-auth-core has Login CSRF via Missing State Parameter in LoginRadius Backend yesterday
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-fp7w-m676-w7gc
  • PyPI/social-auth-core
social-auth-core Vulnerable to Account Takeover via Identity Binding Flaw in Vend Backend yesterday
  • Fix available
  • Severity - 6.8 (Medium)
GHSA-vq6g-g6c7-5f2j
  • PyPI/social-auth-core
social-auth-core has an Improper Authentication issue yesterday
  • Fix available
  • Severity - 6.4 (Medium)
GHSA-r4vp-3vw6-r2x5
  • PyPI/compliance-trestle
Trestle is vulnerable to arbitrary file write via path traversal in author generate commands (Incomplete fix of CVE-2026-46345) yesterday
  • Fix available
  • Severity - 8.4 (High)
GHSA-mr95-65j8-9mxp
  • PyPI/compliance-trestle
Trestle SSTI in Jinja2 include tags allows arbitrary code execution (Incomplete fix of CVE-2026-46439) yesterday
  • Fix available
  • Severity - 7.8 (High)
GHSA-8v8h-hg4w-mvq2
  • PyPI/hpack
hpack: Unbounded variable integer decoding can cause run-away computation on malformed input yesterday
  • Fix available
  • Severity - 6.3 (Medium)