Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3968
  • PyPI/lightning
  • github.com/pytorchlightning/pytorch-lightning
See record for full details 2 days ago
  • Fix available
PYSEC-2026-3969
  • PyPI/lightning
  • github.com/pytorchlightning/pytorch-lightning
See record for full details 2 days ago
  • Fix available
PYSEC-2026-2539
  • PyPI/jupyterlab-git
jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories 13 Jul
  • Fix available
  • Severity - 7.1 (High)
PYSEC-2026-2541
  • PyPI/jupyterlab-git-core
jupyterlab-git extension: Stored XSS leading to RCE 13 Jul
  • Fix available
  • Severity - 8.6 (High)
PYSEC-2026-2540
  • PyPI/jupyterlab-git
jupyterlab-git extension: Stored XSS leading to RCE 13 Jul
  • Fix available
  • Severity - 8.6 (High)
PYSEC-2026-2630
  • PyPI/mcp-server-git
mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries 13 Jul
  • Fix available
  • Severity - 6.4 (Medium)
PYSEC-2026-1623
  • PyPI/mcp-server-git
mcp-server-git has missing path validation when using --repository flag 07 Jul
  • Fix available
  • Severity - 6.4 (Medium)
PYSEC-2026-1622
  • PyPI/mcp-server-git
mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files 07 Jul
  • Fix available
  • Severity - 6.3 (Medium)
PYSEC-2026-1621
  • PyPI/mcp-server-git
mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locations 07 Jul
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-1483
  • PyPI/jupyterlab-git
jupyterlab-git has a command injection vulnerability in "Open Git Repository in Terminal" 07 Jul
  • Fix available
  • Severity - 7.4 (High)
PYSEC-2026-1404
  • PyPI/git-url-parse
git-url-parse Regular Expression Denial of Service 07 Jul
  • No fix available
  • Severity - 7.5 (High)
GHSA-436q-jwfr-rm2h
  • PyPI/jupyterlab-git
jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories 19 Jun
  • Fix available
  • Severity - 7.1 (High)
GHSA-f962-v9hr-pfg5
  • PyPI/jupyterlab-git
  • PyPI/jupyterlab-git-core
  • npm/@jupyterlab/git
jupyterlab-git extension: Stored XSS leading to RCE 19 Jun
  • Fix available
  • Severity - 8.6 (High)
MAL-2026-4273
  • PyPI/git-config-sync
Malicious code in git-config-sync (PyPI) 24 May
  • No fix available
GHSA-vjqx-cfc4-9h6v
  • PyPI/mcp-server-git
mcp-server-git : Path traversal in git_add allows staging files outside repository boundaries 26 Feb
  • Fix available
  • Severity - 6.4 (Medium)
GHSA-j22h-9j4x-23w5
  • PyPI/mcp-server-git
mcp-server-git has missing path validation when using --repository flag 17 Dec 2025
  • Fix available
  • Severity - 6.4 (Medium)