PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-R9MR-M37C-5FR3HighGitPython: GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command executionGHSA-6P8H-3WGX-97GFHighGitPython: GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooksGHSA-FJR4-X663-MWXCHighGitPython: GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)GHSA-3RP5-JJMW-4WV2Highgitpython: GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)CVE-2026-61632Mediumpymdown-extensions: PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_pathCVE-2026-13769Mediumawscli: AWS CLI: Overly permissive File PermissionsCVE-2026-63632Lowonnx: ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input ShapeCVE-2026-57516Highray: Ray: Arbitrary code execution via ray.data.read_webdataset default decoder: pickle.loads(value) and torch.load(weights_only=False)CVE-2026-59939Highhttplib2: httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response HandlingCVE-2026-59935Highpypdf: pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)CVE-2026-59936Highpypdf: pypdf: Possible infinite loop for not terminated inline imagesCVE-2026-59937Mediumpypdf: pypdf: Possible long runtimes for repeated malformed cross-reference entries CVE-2026-59938Mediumpypdf: pypdf: Possible large memory usage for wrong image dimensionsGHSA-PPPJ-HQ3G-57PJHighjupyterlab: JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)GHSA-GX64-GJ6P-PC4CHighjupyterlab: JupyterLab: Image viewer allows XSS when opening malicious image in new browser tabGHSA-89VP-JRXV-24W8Mediumjupyterlab: JupyterLab: PyPI extension blocklist package-name canonicalization bypassGHSA-H5V5-8746-G7MMMediumjupyterlab: JupyterLab PluginManager lock-rule enforcement bypassGHSA-WHVH-WF3X-G77JLowjupyterlab: JupyterLab: Allowlist/blocklist check in `PyPIExtensionManager.install()` not enforced for direct callers (missing `await`)CVE-2026-59821Lowlitellm: LiteLLM: Custom Code Guardrails production endpoints bypass code safety checksCVE-2026-59822Highlitellm: LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough FallbackCVE-2026-59819Lowlitellm: LiteLLM: Local file read via request-supplied OIDC file referencesCVE-2026-59820Mediumlitellm: LiteLLM: Arbitrary file write via path traversal in Skills archive extractionGHSA-RWJ8-PGH3-R573Highgitpython: GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URLGHSA-956X-8GVW-WG5VHighGitPython: GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via…GHSA-2F96-G7MH-G2HXHighGitPython: GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

Stop the waste.
Protect your environment with Kodem.