Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-17183
  • PyPI/tego-managed-agents-test
Malicious code in tego-managed-agents-test (PyPI) 25 Sep
  • No fix available
GHSA-93qj-5q5v-3c2h
  • PyPI/pantheon-agents
Trojanized pantheon-agents 0.6.1 and 0.6.2 on PyPI ship a credential stealer (supply-chain account compromise) 26 Aug
  • Fix available
GHSA-j659-8xh6-5pq5
  • PyPI/atomic-agents-stack
atomic-agents-stack: Parallel helper/delegate batch reserves $0 for models absent from the pricing table, bypassing the cost-cap fan-out guard 17 Aug
  • Fix available
  • Severity - 8.7 (High)
GHSA-xhcr-cqfr-m3hv
  • PyPI/atomic-agents-stack
atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE) 17 Aug
  • Fix available
  • Severity - 8.7 (High)
GHSA-rm43-82j9-r4mj
  • PyPI/atomic-agents-stack
atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read 13 Aug
  • Fix available
  • Severity - 8.2 (High)
PYSEC-2026-2334
  • PyPI/ai-agents
aiwaves-cn agents is vulnerable to resource consumption in the recall_relevant_memories_to_working_memory function 13 Jul
  • No fix available
  • Severity - 5.5 (Medium)
PYSEC-2026-2487
  • PyPI/giskard-agents
Giskard Agents have Server-side template injection via ChatWorkflow.chat() using non-sandboxed Jinja2 Environment 13 Jul
  • Fix available
  • Severity - 7.7 (High)
PYSEC-2026-607
  • PyPI/pantheon-agents
Malicious code in pantheon-agents (PyPI) 01 Jul
  • No fix available
MAL-2026-5299
  • PyPI/pantheon-agents
Malicious code in pantheon-agents (PyPI) 06 Jun
  • No fix available
GHSA-ch88-c67q-65r9
  • PyPI/ai-agents
aiwaves-cn agents is vulnerable to resource consumption in the recall_relevant_memories_to_working_memory function 11 May
  • No fix available
  • Severity - 5.5 (Medium)
GHSA-frv4-x25r-588m
  • PyPI/giskard-agents
Giskard Agents have Server-side template injection via ChatWorkflow.chat() using non-sandboxed Jinja2 Environment 27 Mar
  • Fix available
  • Severity - 7.7 (High)
MAL-2026-904
  • PyPI/strands-agents-anthropic
Malicious code in strands-agents-anthropic (PyPI) 15 Feb
  • No fix available
MAL-2025-192928
  • PyPI/livekit-agents-hedra
Malicious code in livekit-agents-hedra (PyPI) 24 Dec 2025
  • No fix available
MAL-2025-2930
  • PyPI/agents-kit
Malicious code in agents-kit (PyPI) 28 Mar 2025
  • No fix available