PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-45350Highopen-webui: Open WebUI's chat completion API allows tool restrictions to be bypassedCVE-2026-45349Highopen-webui: Open WebUI has Broken Access Control for Completions APICVE-2026-45348Highpyload-ng: pyLoad is vulnerable to stored XSS in Downloads view via unsanitized link URL in packages.js template literalCVE-2026-45347Mediumopen-webui: Open WebUI vulnerable to blind server side request forgery (SSRF) via the PDF generate functionCVE-2026-45345Mediumopen-webui: Open WebUI missing authorization check at the model update function - models from other users can be updatedCVE-2026-45339Mediumopen-webu: Open WebUI's API key endpoint restrictions bypassed via `x-api-key` header — full message processing on restricted endpointsCVE-2026-45338Highopen-webui: Open WebUI Vulnerable to SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py)CVE-2026-45331Highopen-webui: Open WebUI has a full SSRF Vulnerability in the RAG Web Search FeatureCVE-2026-45317Mediumopen-webui: Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF) via Image URL ManipulationCVE-2026-45318Mediumopen-webui: Open WebUI has stored XSS via unsanitized Office/Excel/DOCX file preview rendering ({@html} without DOMPurify)CVE-2026-45316Lowopen-webui: Open WebUI: Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access)CVE-2026-45314Highopen-webui: Open WebUI has XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/imageCVE-2026-45315Highopen-webui: Open WebUI has stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptionsCVE-2026-45306Mediumpyload-ng: pyLoad Has Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory in pyLoadGHSA-G39V-CVJH-8FPFMediumha-mcp: Home Assistant MCP Server: YAML config backups written under www/ are served unauthenticated at /local/CVE-2026-45303Highopen-webui: Open WebUI has stored XSS via the HTML renedering viewCVE-2026-45301Highopen-webui: Open WebUI: Missing permission check in files API allows authenticated users to list, access and delete every uploaded fileCVE-2026-45299Mediumopen-webui: Open WebUI has Stored Cross-Site Scripting In Profile PictureCVE-2026-44541Highethyca-fides: ethyca-fides has a DOM-based XSS vulnerability in fides.js via fides_description overrideCVE-2026-44970Lowdbt-mcp: dbt MCP Server Transmits All MCP Tool Arguments Including Raw SQL and --vars Credentials to dbt Labs Telemetry by Default Without RedactionCVE-2026-44969Lowdbt-mcp: dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Logging Is EnabledCVE-2026-44968Mediumdbt-mcp: dbt MCP Server has an Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type ParametersCVE-2026-44899Mediummistune: Mistune Image Directive CSS Injection VulnerabilityCVE-2026-44898Mediummistune: Mistune TOC Anchor Injection XSSCVE-2026-45076Mediummatrix-synapse: Synapse pagination Denial of Service

Stop the waste.
Protect your environment with Kodem.