Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-17464
  • PyPI/voxcpmui3
Malicious code in voxcpmui3 (PyPI) 2 hours ago
  • No fix available
MAL-2026-17462
  • PyPI/echogen
Malicious code in echogen (PyPI) 8 hours ago
  • No fix available
MAL-2026-17463
  • PyPI/voxcpmtts3
Malicious code in voxcpmtts3 (PyPI) 8 hours ago
  • No fix available
MAL-2026-17461
  • PyPI/voxel-tts
Malicious code in voxel-tts (PyPI) 9 hours ago
  • No fix available
GHSA-h46j-26q3-rggf
  • PyPI/headroom-ai
Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH) 14 hours ago
  • Fix available
  • Severity - 8.8 (High)
GHSA-v2f8-6655-7grj
  • PyPI/vibe-trading-ai
Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain 15 hours ago
  • Fix available
  • Severity - 10.0 (Critical)
GHSA-5rmq-chc7-m22f
  • PyPI/vibe-trading-ai
Vibe-Trading file-read tools expose arbitrary server-readable files 15 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-jqmf-mx4f-hfr6
  • PyPI/vibe-trading-ai
Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRF 15 hours ago
  • Fix available
  • Severity - 10.0 (Critical)
GHSA-mhvh-fq92-pfmr
  • PyPI/geopy
geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point 15 hours ago
  • Fix available
  • Severity - 4.0 (Medium)
MAL-2026-17457
  • PyPI/voxeval
Malicious code in voxeval (PyPI) 16 hours ago
  • No fix available
GHSA-8mcx-5rqc-vhmf
  • PyPI/dulwich
Dulwich: Arbitrary File Write (RCE) on Windows via Unvalidated Drive Letters in Tree Paths 18 hours ago
  • Fix available
  • Severity - 8.8 (High)
GHSA-35mr-4567-66vg
  • PyPI/dulwich
Dulwich: Infinite Loop Denial of Service (DoS) in Packfile Object Resolution 18 hours ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-8w8g-wq8h-fq33
  • PyPI/dulwich
Dulwich: Symlink write-through in checkout(paths=[]) via raw os.open bypasses all symlink protections 18 hours ago
  • Fix available
  • Severity - 8.6 (High)
GHSA-5fqc-mrg8-w798
  • PyPI/dulwich
Dulwich: Symlink directory traversal in filter-branch index_filter via cross-commit state persistence 18 hours ago
  • Fix available
  • Severity - 8.6 (High)
GHSA-cm62-gvxx-vmxx
  • PyPI/dulwich
Dulwich: Symlink directory traversal in stash pop allows arbitrary file write via intermediate directory symlinks 18 hours ago
  • Fix available
  • Severity - 8.6 (High)
MAL-2026-17455
  • PyPI/dedh-devops-automation
Malicious code in dedh-devops-automation (PyPI) 23 hours ago
  • No fix available