Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3968
  • PyPI/lightning
  • github.com/pytorchlightning/pytorch-lightning
See record for full details 10 Sep
  • Fix available
PYSEC-2026-3969
  • PyPI/lightning
  • github.com/pytorchlightning/pytorch-lightning
See record for full details 10 Sep
  • Fix available
PYSEC-2026-4010
  • PyPI/local-operator
  • github.com/damianvtran/local-operator
Arbitrary file read via workspace confinement bypass in local-operator /v1/chat/agents/{id}/edit 05 Sep
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-4009
  • PyPI/local-operator
  • github.com/damianvtran/local-operator
Path traversal and arbitrary directory deletion/overwrite via agent profile import in local-operator 05 Sep
  • Fix available
  • Severity - 9.1 (Critical)
OSV-2026-1125
  • PyPI/mrab-regex
  • github.com/mrabarnett/mrab-regex
Segv on unknown address in match_many_CHARACTER_REV 08 Aug
  • Fix available
OSV-2026-1084
  • PyPI/mrab-regex
  • github.com/mrabarnett/mrab-regex
UNKNOWN READ in bytes1_char_at 28 Jul
  • Fix available
OSV-2026-1072
  • PyPI/mrab-regex
  • github.com/mrabarnett/mrab-regex
UNKNOWN READ in _regex.cpython-311-x86_64-linux-gnu.so 28 Jul
  • Fix available
OSV-2026-1070
  • PyPI/mrab-regex
  • github.com/mrabarnett/mrab-regex
UNKNOWN READ in bytes1_char_at 28 Jul
  • Fix available
PYSEC-2026-2539
  • PyPI/jupyterlab-git
jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories 13 Jul
  • Fix available
  • Severity - 7.1 (High)
PYSEC-2026-2541
  • PyPI/jupyterlab-git-core
jupyterlab-git extension: Stored XSS leading to RCE 13 Jul
  • Fix available
  • Severity - 8.6 (High)
PYSEC-2026-2540
  • PyPI/jupyterlab-git
jupyterlab-git extension: Stored XSS leading to RCE 13 Jul
  • Fix available
  • Severity - 8.6 (High)
PYSEC-2026-2630
  • PyPI/mcp-server-git
mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries 13 Jul
  • Fix available
  • Severity - 6.4 (Medium)
PYSEC-2026-1623
  • PyPI/mcp-server-git
mcp-server-git has missing path validation when using --repository flag 07 Jul
  • Fix available
  • Severity - 6.4 (Medium)
PYSEC-2026-1622
  • PyPI/mcp-server-git
mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files 07 Jul
  • Fix available
  • Severity - 6.3 (Medium)
PYSEC-2026-1621
  • PyPI/mcp-server-git
mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations 07 Jul
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-1483
  • PyPI/jupyterlab-git
jupyterlab-git has a command injection vulnerability in "Open Git Repository in Terminal" 07 Jul
  • Fix available
  • Severity - 7.4 (High)