PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-57126Highpraisonaiagents: praisonaiagents: SSRF guard validates literal IPs only and never resolves DNSCVE-2026-57125Criticalpraisonai: PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass CVE-2026-57119Highpraisonai: PraisonAI: Unauthenticated Local File Inclusion via agent_file path in PraisonAI Jobs APICVE-2026-57123Criticalpraisonaiagents: PraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired inCVE-2026-57120Mediumpraisonaiagents: PraisonAI: execute_code sandbox bypass: str.format C-level attribute access reads every blocklisted dunderCVE-2026-57115Mediumpraisonaiagents: PraisonAI: SpiderTools redirect-target SSRF protection bypassCVE-2026-57117Highpraisonai: PraisonAI: Compute-bridged file tools allow shell command injectionCVE-2026-56838Highpraisonai: PraisonAI recipe.run_stream skips dangerous-tool policy enforcementCVE-2026-56840Highpraisonai: PraisonAI: HTTPApproval dashboard renders tool arguments as raw HTML, allowing approval-page XSS to approve dangerous toolsCVE-2026-56837Highpraisonai: PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missingCVE-2026-56834Highpraisonai: PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storageCVE-2026-56835Highpraisonai: PraisonAI Slack app_mention bypasses configured user/channel authorizationCVE-2026-56836Highpraisonai: PraisonAI recipe serve Typer command bypasses the non-localhost authentication guardCVE-2026-57112Highpraisonaiagents: PraisonAI ToolsMCPServer legacy SSE transport accepts attacker Host/Origin and exposes registered toolsCVE-2026-56833Highpraisonai: PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversalCVE-2026-56832Highpraisonai: PraisonAI DiscordApproval accepts unrelated channel messages as dangerous-tool approvalsCVE-2026-57128Mediumpraisonaiagents: PraisonAI: Unauthenticated Event Injection via SSE `/publish` EndpointCVE-2026-54386Mediummarimo: marimo contains a reflected cross-site scripting vulnerability in the notebook pageCVE-2026-53869Highhermes-agent: Hermes Agent contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to bypass Host and Origin validationCVE-2026-53870Mediumhermes-agent: Hermes Agent creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644)CVE-2026-55450Criticallangflow: Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leakCVE-2025-26240Highpdfkit: pdfkit: Path traversal in from_stringCVE-2026-55748Mediumhorizon: OpenStack Horizon RC file generation does not escape special characters in project namesCVE-2026-50203Criticalapache-airflow-providers-sftp: Apache Airflow SFTP provider: Path traversal in SFTPHook.retrieve_directoryCVE-2026-54022Mediumopen-webui: Open WebUI: Any authenticated user can read other users' private notes via Socket.IO

Stop the waste.
Protect your environment with Kodem.