Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-9hgc-g3w5-67cm
  • PyPI/mcp-contextforge-gateway
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`) yesterday
  • Fix available
  • Severity - 6.6 (Medium)
GHSA-m42h-3232-vpv3
  • PyPI/nltk
nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences 2 days ago
  • Fix available
  • Severity - 7.5 (High)
GHSA-87x5-vmc3-756j
  • PyPI/vllm
vLLM: Completion prompt lists fan out into unbounded engine requests 2 days ago
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-rm43-82j9-r4mj
  • PyPI/atomic-agents-stack
atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read 2 days ago
  • Fix available
  • Severity - 8.2 (High)
GHSA-h7p7-w5gc-xj3w
  • PyPI/pydantic-ai
  • PyPI/pydantic-ai-slim
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials 2 days ago
  • Fix available
  • Severity - 6.8 (Medium)
GHSA-cxgv-hp74-jj7r
  • PyPI/ansible-jailexec
Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv) 3 days ago
  • Fix available
  • Severity - 7.7 (High)
GHSA-49m4-vp58-wgc9
  • PyPI/stata-mcp
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install` 3 days ago
  • Fix available
  • Severity - 8.4 (High)
GHSA-h47f-gmjp-m7rr
  • PyPI/compliance-trestle
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0 3 days ago
  • Fix available
  • Severity - 8.6 (High)
GHSA-gqgw-jghv-mxwx
  • PyPI/tablib
tablib: Stored XSS in the HTML export via unescaped dataset title 4 days ago
  • Fix available
  • Severity - 4.8 (Medium)
MAL-2026-13756
  • PyPI/joule-sbx-poc
Malicious code in joule-sbx-poc (PyPI) 4 days ago
  • No fix available
MAL-2026-13757
  • PyPI/telebot-pro
Malicious code in telebot-pro (PyPI) 4 days ago
  • No fix available
MAL-2026-13732
  • PyPI/joule-btp-extension
Malicious code in joule-btp-extension (PyPI) 4 days ago
  • No fix available
MAL-2026-13730
  • PyPI/euler-sdk
Malicious code in euler-sdk (PyPI) 4 days ago
  • No fix available
MAL-2026-13731
  • PyPI/morpho-sdk
Malicious code in morpho-sdk (PyPI) 4 days ago
  • No fix available
MAL-2026-13729
  • PyPI/dlmm-sdk
Malicious code in dlmm-sdk (PyPI) 5 days ago
  • No fix available
MAL-2026-13728
  • PyPI/dlmm
Malicious code in dlmm (PyPI) 5 days ago
  • No fix available