Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-vjqx-cfc4-9h6v
  • PyPI/mcp-server-git
mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries 26 Feb
  • Fix available
  • Severity - 6.4 (Medium)
GHSA-j22h-9j4x-23w5
  • PyPI/mcp-server-git
mcp-server-git has missing path validation when using --repository flag 17 Dec 2025
  • Fix available
  • Severity - 6.4 (Medium)
GHSA-9xwc-hfwc-8w59
  • PyPI/mcp-server-git
mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files 17 Dec 2025
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-5cgr-j3jf-jw3v
  • PyPI/mcp-server-git
mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations 17 Dec 2025
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2025-71
  • PyPI/cadwyn
  • github.com/zmievsa/cadwyn
See record for full details 21 Jul 2025
  • Fix available
PYSEC-2025-65
  • PyPI/llama-index
  • github.com/run-llama/llama_index
See record for full details 07 Jul 2025
  • Fix available
PYSEC-2025-61
  • PyPI/pillow
  • github.com/python-pillow/pillow
See record for full details 01 Jul 2025
  • Fix available
OSV-2025-500
  • PyPI/pyvex
  • github.com/angr/pyvex.git
UNKNOWN READ in getUShort 29 Jun 2025
  • Fix available
PYSEC-2025-70
  • PyPI/langchain-community
  • github.com/langchain-ai/langchain
See record for full details 23 Jun 2025
  • Fix available
  • Severity - 10.0 (Critical)
PYSEC-2025-52
  • PyPI/mlflow
  • github.com/mlflow/mlflow
See record for full details 23 Jun 2025
  • Fix available
PYSEC-2025-64
  • PyPI/python-a2a
  • github.com/themanojdesai/python-a2a
See record for full details 17 Jun 2025
  • Fix available
  • Severity - 9.8 (Critical)
PYSEC-2025-44
  • PyPI/django-helpdesk
  • github.com/django-helpdesk/django-helpdesk
See record for full details 31 May 2025
  • Fix available
PYSEC-2025-54
  • PyPI/vllm
  • github.com/vllm-project/vllm
See record for full details 30 May 2025
  • Fix available
PYSEC-2025-55
  • PyPI/vllm
  • github.com/vllm-project/vllm
See record for full details 30 May 2025
  • Fix available
PYSEC-2025-50
  • PyPI/vllm
  • github.com/vllm-project/vllm
See record for full details 30 May 2025
  • Fix available
PYSEC-2025-43
  • PyPI/vllm
  • github.com/vllm-project/vllm
See record for full details 29 May 2025
  • Fix available