PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-40961Highapache-airflow: Apache Airflow: Authenticated users can bypass the `is_safe_url` checkCVE-2026-40861Mediumapache-airflow: Apache Airflow has a Link Following issueCVE-2026-40963Lowapache-airflow: Apache Airflow has an Improper Authorization issueCVE-2026-45192Mediumapache-airflow: Apache Airflow: Incomplete redaction allowlist exposes secrets in Connection `extra`  to read-permitted usersCVE-2026-10222Lowhermes-agent: hermes-agent has an Injection issueCVE-2026-10212LowAstrBot: AstrBot: Manipulation of astr_main_agent's session_id parameter leads to authorization bypassCVE-2026-10177Lowaider-chat: Aider has an SSRF vulnerability through its AWS EC2 Metadata EndpointCVE-2026-10175Lowaider-chat: Aider is vulnerable to Code Injection via editor_coder.run functionCVE-2026-47416Criticalpraisonai-platform: praisonai-platform: Any workspace member can promote themselves or others to owner via PATCH /workspaces/{id}/members/{user_id}CVE-2026-47409Highpraisonai-platform: praisonai-platform: Missing authorization on member removal enables full workspace takeover by any user regardless of roleCVE-2026-47414Highpraisonai-platform: praisonai-platform: Label endpoints' unchecked label_id/issue_id enable cross-workspace label IDOR (edit, delete, link)CVE-2026-47406Highpraisonai-platform: praisonai-platform: IDOR in dependency endpoints allows cross-workspace issue linking, reading, and deletion due to missing ownership checksCVE-2026-47410Criticalpraisonai-platform: praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is…CVE-2026-47405Highpraisonai-platform: PraisonAI Platform: Missing role checks let any workspace member become owner and control workspace membershipCVE-2026-47399Highpraisonai-platform: PraisonAI Platform workspace-scoped routes allow cross-workspace object access by global object IDCVE-2026-47407Criticalpraisonai-platform: PraisonAI Platform has a cross-workspace IDOR + member-role privilege escalationCVE-2026-47408Mediumpraisonai-platform: praisonai-platform: list_issue_activity returns activity log for any issue regardless of workspace ownershipCVE-2026-48169Highpraisonai-platform: PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform APICVE-2026-47397HighPraisonAI: PraisonAI has an Arbitrary File Write in Python APICVE-2026-47391CriticalPraisonAI: PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool executionCVE-2026-47394HighPraisonAI: PraisonAI vulnerable to unauthenticated arbitrary file read via MCP workflow.show, workflow.validate, deploy.validateCVE-2026-47392Criticalpraisonaiagents: PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode)CVE-2026-47395Mediumpraisonaiagents: PraisonAI CLI automatically resolves @url mentions in prompt text and can read loopback URLs into model contextCVE-2026-47393CriticalPraisonAI: PraisonAI `deploy --type api` emits a Flask server with authentication disabled by defaultCVE-2026-47396CriticalPraisonAI: PraisonAI call server exposes unauthenticated agent listing, invocation, and deletion when CALL_SERVER_TOKEN is unset

Stop the waste.
Protect your environment with Kodem.