PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-12566Lowbbot: BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsingCVE-2026-12565Mediumbbot: BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284GHSA-2FJJ-QQG8-FG7XMediumpraisonai-platform: praisonai-platform: Authorization Bypass Through User-Controlled KeyGHSA-JM82-FX9C-MX94Mediumpypdf: pypdf: Missing stream length values ignore defined limitsCVE-2026-47103Criticalpython-statemachine: python-statemachine SCXML <data expr> Eval InjectionCVE-2026-57147Criticalpraisonai-platform: praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgeryCVE-2026-57144Highpraisonai: PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailableCVE-2026-57132Highpraisonai: PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authenticationCVE-2026-57143Highpraisonaiagents: PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameterCVE-2026-57148Criticalpraisonai-platform: praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard)CVE-2026-57145Criticalpraisonai: PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path ValidationCVE-2026-57146Highpraisonai: PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by defaultCVE-2026-57142Highpraisonai: PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yamlCVE-2026-57130Highpraisonaiagents: PraisonAI: IMAP Command Injection via Unsanitized Email Search ParametersCVE-2026-57113Highpraisonai: PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletionCVE-2026-56839Highpraisonai: PraisonAI Code agent tools fail open without a workspace boundaryCVE-2026-57124Criticalpraisonai: PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command…CVE-2026-57122Highpraisonai: PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots)CVE-2026-57121Highpraisonai-platform: PraisonAI: Missing ownership check on DELETE endpoints allows members to delete others' content in Platform APICVE-2026-57116Criticalpraisonai: PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocationCVE-2026-57118Criticalpraisonaiagents: PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpointsCVE-2026-57114Highpraisonai: PraisonAI: Jobs webhook SSRF protection bypass via DNS rebindingCVE-2026-57131Criticalpraisonai: PraisonAI: Jobs API exposes agent-execution endpoints with no authentication CVE-2026-57129Highpraisonaiagents: PraisonAI: Arbitrary File Read via `@file:` Mention Path TraversalCVE-2026-57127Criticalpraisonai: praisonai: recipe serve auth middleware silently disables itself when no secret is set

Stop the waste.
Protect your environment with Kodem.