Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-54fq-v6x8-244g
  • PyPI/smolagents
Hugging Face Smolagents has an Injection issue 27 Mar
  • No fix available
  • Severity - 2.1 (Low)
GHSA-jxgv-6j54-wwc7
  • PyPI/smolagents
Hugging Face Smolagents has a Server-Side Request Forgery issue 18 Feb
  • No fix available
  • Severity - 2.1 (Low)
GHSA-q9r5-6hrr-9ph7
  • PyPI/smolagents
Hugging Face smolagents: Unsafe deserialization in Remote Python Executor leads to RCE 23 Dec 2025
  • No fix available
  • Severity - 10.0 (Critical)
GHSA-8mf9-rmgw-33qc
  • PyPI/smolagents
Hugging Face Smolagents XPath injection vulnerability in the search_item_ctrl_f function 22 Oct 2025
  • Fix available
  • Severity - 5.4 (Medium)
GHSA-6v92-r5mx-h5fx
  • PyPI/smolagents
smolagents has Sandbox Escape Vulnerability in the local_python_executor.py Module 27 Jul 2025
  • Fix available
  • Severity - 9.9 (Critical)