Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-16421
  • PyPI/kerokwis
Malicious code in kerokwis (PyPI) 3 hours ago
  • No fix available
MAL-2026-16410
  • PyPI/auclean
Malicious code in auclean (PyPI) 6 hours ago
  • No fix available
GHSA-wx4m-69m9-gx3m
  • PyPI/homeassistant
Home Assistant: XSS in Statistics Graph Card 7 hours ago
  • Fix available
  • Severity - 9.3 (Critical)
GHSA-4ghv-53cq-7wp3
  • PyPI/homeassistant
Home Assistant: mDNS Server-Side Request Forgery 7 hours ago
  • Fix available
  • Severity - 5.4 (Medium)
GHSA-xpjq-3w4w-w5wr
  • PyPI/lightrag-hku
lightrag-hku: Stored Cross-Site Scripting (XSS) in the LightRAG WebUI chat/answer renderer via ingested content 7 hours ago
  • Fix available
  • Severity - 6.1 (Medium)
GHSA-vv3m-f8x4-7377
  • PyPI/lightrag-hku
lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard 7 hours ago
  • Fix available
  • Severity - 7.1 (High)
GHSA-frch-4w6v-q5xx
  • PyPI/lightrag-hku
lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks 7 hours ago
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-c759-cx9p-mrwq
  • PyPI/lightrag-hku
lightrag-hku: Plaintext Passwords Compared Without Constant-Time Function 7 hours ago
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-hrmj-7rvj-4hg8
  • PyPI/lightrag-hku
lightrag-hku: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses 7 hours ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-q4c5-2j6f-r476
  • PyPI/nautobot
Nautobot: Authorization bypass in approval workflow REST API allows self-approval and unauthorized activation of scheduled jobs 7 hours ago
  • Fix available
  • Severity - 6.4 (Medium)
GHSA-56v6-2fhr-wxgq
  • PyPI/nautobot
Nautobot: Stored cross-site scripting (XSS) in object create/edit form help text 7 hours ago
  • Fix available
  • Severity - 5.4 (Medium)
GHSA-hxp9-w8x3-p566
  • PyPI/autobahn
  • PyPI/crossbar
Autobahn Python permessage-deflate bypasses maxMessagePayloadSize after inflation 7 hours ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-93xw-j965-9mx3
  • PyPI/mcp-atlassian
MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path() 7 hours ago
  • Fix available
  • Severity - 7.7 (High)
GHSA-g5xv-mhgm-v5f6
  • PyPI/mcp-atlassian
MCP Atlassian: OAuth fallback token storage writes plaintext access and refresh tokens with group-readable permissions 7 hours ago
  • Fix available
  • Severity - 6.1 (Medium)
GHSA-v9m3-wfh8-5646
  • PyPI/mcp-atlassian
MCP Atlassian: Incomplete fix for GHSA-7r34-79r5-rcc9: redirect-based SSRF via unhooked requests session in Jira user-permission lookup 7 hours ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-f6pj-qv47-g96w
  • PyPI/mcp-atlassian
MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters 7 hours ago
  • Fix available