Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-17465
  • PyPI/voxcpmeval
Malicious code in voxcpmeval (PyPI) 1 hour ago
  • No fix available
MAL-2026-17466
  • PyPI/voxcpmkit
Malicious code in voxcpmkit (PyPI) 2 hours ago
  • No fix available
MAL-2026-17467
  • PyPI/voxcpmui4
Malicious code in voxcpmui4 (PyPI) 3 hours ago
  • No fix available
MAL-2026-17464
  • PyPI/voxcpmui3
Malicious code in voxcpmui3 (PyPI) 4 hours ago
  • No fix available
MAL-2026-17462
  • PyPI/echogen
Malicious code in echogen (PyPI) 10 hours ago
  • No fix available
MAL-2026-17463
  • PyPI/voxcpmtts3
Malicious code in voxcpmtts3 (PyPI) 10 hours ago
  • No fix available
MAL-2026-17461
  • PyPI/voxel-tts
Malicious code in voxel-tts (PyPI) 10 hours ago
  • No fix available
GHSA-h46j-26q3-rggf
  • PyPI/headroom-ai
Headroom vulnerable to Cross-Site WebSocket Hijacking (CSWSH) 16 hours ago
  • Fix available
  • Severity - 8.8 (High)
GHSA-v2f8-6655-7grj
  • PyPI/vibe-trading-ai
Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain 16 hours ago
  • Fix available
  • Severity - 10.0 (Critical)
GHSA-5rmq-chc7-m22f
  • PyPI/vibe-trading-ai
Vibe-Trading file-read tools expose arbitrary server-readable files 16 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-jqmf-mx4f-hfr6
  • PyPI/vibe-trading-ai
Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRF 16 hours ago
  • Fix available
  • Severity - 10.0 (Critical)
GHSA-mhvh-fq92-pfmr
  • PyPI/geopy
geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point 16 hours ago
  • Fix available
  • Severity - 4.0 (Medium)
MAL-2026-17457
  • PyPI/voxeval
Malicious code in voxeval (PyPI) 17 hours ago
  • No fix available
GHSA-8mcx-5rqc-vhmf
  • PyPI/dulwich
Dulwich: Arbitrary File Write (RCE) on Windows via Unvalidated Drive Letters in Tree Paths 19 hours ago
  • Fix available
  • Severity - 8.8 (High)
GHSA-35mr-4567-66vg
  • PyPI/dulwich
Dulwich: Infinite Loop Denial of Service (DoS) in Packfile Object Resolution 20 hours ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-8w8g-wq8h-fq33
  • PyPI/dulwich
Dulwich: Symlink write-through in checkout(paths=[]) via raw os.open bypasses all symlink protections 20 hours ago
  • Fix available
  • Severity - 8.6 (High)