Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-15910
  • PyPI/timeweave
Malicious code in timeweave (PyPI) 26 minutes ago
  • No fix available
GHSA-xvg9-69gf-fjrf
  • PyPI/mkdocs-material
Material for MkDocs: DOM XSS in search suggestions via query parameter 9 hours ago
  • Fix available
  • Severity - 5.4 (Medium)
MAL-2026-15864
  • PyPI/asti
Malicious code in asti (PyPI) 10 hours ago
  • No fix available
GHSA-4mvj-m6j5-pmf7
  • PyPI/unstructured
unstructured: Server-Side Request Forgery in the URL-based partitioning 12 hours ago
  • Fix available
  • Severity - 9.3 (Critical)
MAL-2026-15861
  • PyPI/py-1requests
Malicious code in py-1requests (PyPI) 12 hours ago
  • No fix available
MAL-2026-15862
  • PyPI/py-2equests
Malicious code in py-2equests (PyPI) 12 hours ago
  • No fix available
MAL-2026-15860
  • PyPI/py-0requests
Malicious code in py-0requests (PyPI) 12 hours ago
  • No fix available
MAL-2026-15859
  • PyPI/0requests
Malicious code in 0requests (PyPI) 12 hours ago
  • No fix available
MAL-2026-15863
  • PyPI/uvhttp-custom
Malicious code in uvhttp-custom (PyPI) 12 hours ago
  • No fix available
MAL-2026-15858
  • PyPI/trongridi
Malicious code in trongridi (PyPI) 13 hours ago
  • No fix available
MAL-2026-15827
  • PyPI/company-sdk
Malicious code in company-sdk (PyPI) yesterday
  • No fix available
MAL-2026-15828
  • PyPI/env-validator-tool
Malicious code in env-validator-tool (PyPI) yesterday
  • No fix available
MAL-2026-15829
  • PyPI/telemetry-helper
Malicious code in telemetry-helper (PyPI) yesterday
  • No fix available
GHSA-76g3-c3x4-crvx
  • PyPI/scrapy
Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default yesterday
  • Fix available
  • Severity - 7.4 (High)
GHSA-7mqg-cx4g-x2rf
  • PyPI/omnigent
Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py yesterday
  • Fix available
  • Severity - 7.1 (High)
GHSA-p8rw-8qj3-hf33
  • PyPI/omnigent
Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE yesterday
  • Fix available
  • Severity - 8.8 (High)