Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-14524
  • PyPI/bigquery-agent-analytics-tracing
Malicious code in bigquery-agent-analytics-tracing (PyPI) 26 Aug
  • No fix available
PYSEC-2026-3576
  • PyPI/hermes-agent
hermes-agent has an Uncontrolled Resource Consumption issue 04 Aug
  • No fix available
  • Severity - 5.5 (Medium)
PYSEC-2026-3575
  • PyPI/hermes-agent
hermes-agent has an Injection issue 04 Aug
  • Fix available
  • Severity - 2.1 (Low)
PYSEC-2026-3577
  • PyPI/hermes-agent
hermes-agent has an Injection issue 04 Aug
  • No fix available
  • Severity - 5.5 (Medium)
PYSEC-2026-3061
  • PyPI/serena-agent
Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE 13 Jul
  • Fix available
  • Severity - 8.3 (High)
PYSEC-2026-2510
  • PyPI/hermes-agent
Hermes Agent contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validation 13 Jul
  • Fix available
  • Severity - 8.7 (High)
PYSEC-2026-2511
  • PyPI/hermes-agent
Hermes Agent creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644) 13 Jul
  • Fix available
  • Severity - 6.8 (Medium)
PYSEC-2026-2513
  • PyPI/hermes-agent
hermes-agent has an Injection issue 13 Jul
  • Fix available
  • Severity - 2.9 (Low)
PYSEC-2026-2512
  • PyPI/hermes-agent
hermes-agent has an Incorrect Comparison 13 Jul
  • Fix available
  • Severity - 1.9 (Low)
PYSEC-2026-2515
  • PyPI/hermes-agent
hermes-agent has a sandbox issue 13 Jul
  • Fix available
  • Severity - 5.5 (Medium)
PYSEC-2026-2514
  • PyPI/hermes-agent
hermes-agent has an Injection issue 13 Jul
  • Fix available
  • Severity - 5.5 (Medium)
PYSEC-2026-2509
  • PyPI/hermes-agent
hermes-agent has an Injection issue 13 Jul
  • Fix available
  • Severity - 5.5 (Medium)
PYSEC-2026-2526
  • PyPI/ironic-python-agent
OpenStack Ironic has an Incorrect Resource Transfer Between Spheres 13 Jul
  • Fix available
  • Severity - 7.7 (High)
PYSEC-2026-2668
  • PyPI/ms-agent
MS-Agent vulnerable to Command Injection 13 Jul
  • No fix available
  • Severity - 6.5 (Medium)
MAL-2026-10195
  • PyPI/eth-agent
Malicious code in eth-agent (PyPI) 12 Jul
  • No fix available
GHSA-37h2-6p4f-mp3q
  • PyPI/serena-agent
Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE 08 Jul
  • Fix available
  • Severity - 8.3 (High)