PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-X462-JJPC-Q4Q4Highpraisonaiagents: PraisonAI: Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI EndpointCVE-2026-40159MediumPraisonAI: PraisonAI Vulnerable to Sensitive Environment Variable Exposure via Untrusted MCP Subprocess ExecutionCVE-2026-40157CriticalPraisonAI: PraisonAI vulnerable to arbitrary file write via path traversal in `praisonai recipe unpack`CVE-2026-40156Highpraisonai: PraisonAI Vulnerable to Implicit Execution of Arbitrary Code via Automatic `tools.py` LoadingCVE-2026-40148MediumPraisonAI: PraisonAI Vulnerable to Decompression Bomb DoS via Recipe Bundle Extraction Without Size LimitsCVE-2026-40154CriticalPraisonAI: PraisonAI Vulnerable Untrusted Remote Template Code ExecutionGHSA-QWGJ-RRPJ-75XMHighPraisonAI: PraisonAI: Hardcoded `approval_mode="auto"` in Chainlit UI Overrides Administrator Configuration, Enabling Unapproved Shell Command…CVE-2026-40158HighPraisonAI: PraisonAI Vulnerable to Code Injection and Protection Mechanism FailureCVE-2026-40152Mediumpraisonaiagents: PraisonAIAgents: Path Traversal via Unvalidated Glob Pattern in list_files Bypasses Workspace BoundaryCVE-2026-40153Highpraisonaiagents: PraisonAIAgents: Environment Variable Secret Exfiltration via os.path.expandvars() Bypassing shell=False in Shell ToolCVE-2026-40151MediumPraisonAI: PraisonAI: Unauthenticated Information Disclosure of Agent Instructions via /api/agents in AgentOSCVE-2026-40149HighPraisonAI: PraisonAI: Unauthenticated Allow-List Manipulation Bypasses Agent Tool Approval Safety ControlsCVE-2026-40150Highpraisonaiagents: PraisonAIAgents has SSRF and Local File Read via Unvalidated URLs in web_crawl ToolCVE-2026-40117Mediumpraisonaiagents: PraisonAIAgents: Arbitrary File Read via read_skill_file Missing Workspace Boundary and Approval GateCVE-2026-40115MediumPraisonAI: PraisonAI has Unrestricted Upload Size in WSGI Recipe Registry Server that Enables Memory Exhaustion DoSCVE-2026-40116HighPraisonAI: PraisonAI: Unauthenticated WebSocket Endpoint Proxies to Paid OpenAI Realtime API Without Rate LimitsCVE-2026-40113HighPraisonAI: PraisonAI Vulnerable to Argument Injection into Cloud Run Environment Variables via Unsanitized Comma in gcloud --set-env-varsCVE-2026-40112MediumPraisonAI: PraisonAI Vulnerable to Stored XSS via Unsanitized Agent Output in HTML Rendering (nh3 Not a Required Dependency)CVE-2026-40111Criticalpraisonaiagents: PraisonAIAgents has an OS Command Injection via shell=True in Memory Hooks Executor (memory/hooks.py)GHSA-C9VM-HV86-F23RMediumjusthtml: justhtml includes multiple security fixesCVE-2026-1115Criticallollms: parisneo/lollms vulnerable to stored XSS in the social featureCVE-2026-33551Lowkeystone: OpenStack Keystone: Restricted application credentials can create EC2 credentialsCVE-2026-5972Mediummetagpt: FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_commandCVE-2026-5973Mediummetagpt: FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.pyCVE-2026-5974Mediummetagpt: FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py

Stop the waste.
Protect your environment with Kodem.