Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-2wxc-x7rj-hg8f
  • PyPI/asyncssh
asyncssh has SCP Path Traversal to Arbitrary File Write 53 minutes ago
  • Fix available
  • Severity - 8.1 (High)
GHSA-qr67-gv47-xwwh
  • PyPI/asyncssh
asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution 55 minutes ago
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-jrw6-7x4q-w25j
  • PyPI/senaite-core
senaite.core Vulnerable to Eval Injection and Missing Authorization 58 minutes ago
  • No fix available
  • Severity - 9.8 (Critical)
GHSA-x287-5c68-36wp
  • PyPI/openwisp-ipam
OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses 1 hour ago
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-93qj-5q5v-3c2h
  • PyPI/pantheon-agents
Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise) 1 hour ago
  • Fix available
GHSA-mv8m-v9v6-5f94
  • PyPI/kas
kas Persistently Disables SSH Host Key Checking 2 hours ago
  • Fix available
  • Severity - 3.3 (Low)
GHSA-6753-gr46-6wpr
  • PyPI/starlette-admin
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS 2 hours ago
  • Fix available
  • Severity - 5.4 (Medium)
MAL-2026-14525
  • PyPI/0xfighter3
Malicious code in 0xfighter3 (PyPI) 9 hours ago
  • No fix available
MAL-2026-14524
  • PyPI/bigquery-agent-analytics-tracing
Malicious code in bigquery-agent-analytics-tracing (PyPI) 10 hours ago
  • No fix available
MAL-2026-14523
  • PyPI/rce-test
Malicious code in rce-test (PyPI) 11 hours ago
  • No fix available
MAL-2026-14522
  • PyPI/syntaxerror-package-12345
Malicious code in syntaxerror-package-12345 (PyPI) 12 hours ago
  • No fix available
GHSA-p43p-whwx-q52h
  • PyPI/jupyterhub
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login 20 hours ago
  • Fix available
  • Severity - 5.3 (Medium)
MAL-2026-14516
  • PyPI/minecraft-ytreceiver
Malicious code in minecraft-ytreceiver (PyPI) 20 hours ago
  • No fix available
GHSA-cv84-9p8j-fj68
  • PyPI/icalendar
icalendar has Algorithmic Complexity in Equality 21 hours ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-hvfh-5mj3-5f3j
  • PyPI/chainlit
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access 21 hours ago
  • Fix available
  • Severity - 7.2 (High)
GHSA-w3fx-mc44-mf6j
  • PyPI/chainlit
Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution 21 hours ago
  • Fix available
  • Severity - 9.8 (Critical)