PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-9GJV-JVM7-VV2VMediumgramps-webapi: Gramps Web API: Private Sub-Object Data in Non-Private Objects Exposed to Guest UsersCVE-2026-5971Mediummetagpt: FoundationAgents MetaGPT vulnerable to eval injectionCVE-2026-5970Mediummetagpt: MetaGPT has an Injection issueCVE-2025-57735Criticalapache-airflow: Apache Airflow: JWT token still valid after logoutCVE-2026-34538Mediumapache-airflow: Apache Airflow has an authorization bypass in DagRun wait endpointCVE-2026-40088CriticalPraisonAI: PraisonAI Vulnerable to OS Command InjectionCVE-2026-40087Mediumlangchain-core: LangChain has incomplete f-string validation in prompt templatesCVE-2026-39987Criticalmarimo: Marimo: Pre-Auth Remote Code Execution via Terminal WebSocket Authentication BypassCVE-2026-39981Highagixt: AGiXT Vulnerable to Path Traversal in safe_join()CVE-2026-39892Mediumcryptography: Cryptography vulnerable to buffer overflow if non-contiguous buffers were passed to APIsCVE-2026-56078Mediumpraisonaiagents: PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context HandlingCVE-2026-39891Highpraisonai: PraisonAI has Template Injection in Agent Tool DefinitionsCVE-2026-39889Highpraisonai: PraisonAI Has Unauthenticated SSE Event Stream that Exposes All Agent Activity in A2U ServerCVE-2026-39888Criticalpraisonaiagents: PraisonAI has sandbox escape via exception frame traversal in `execute_code` (subprocess mode)CVE-2026-39890Criticalpraisonai: PraisonAI Vulnerable to Remote Code Execution via YAML Deserialization in Agent Definition LoadingCVE-2026-31040Highstata-mcp: stata-mcp has insufficient validation of user-supplied Stata do-file content that can lead to command executionCVE-2026-5600Mediumpretix: pretix: API leaks check-in data between events of the same organizerCVE-2026-34589HighOpenEXR: OpenEXR: DWA Lossy Decoder Heap Out-of-Bounds WriteCVE-2026-34588HighOpenEXR: OpenEXR has a signed 32-bit Overflow in PIZ Decoder Leads to OOB Read/WriteCVE-2026-39844Mediumnicegui: NiceGUI: Upload filename sanitization bypass via backslashes allows path traversal on WindowsCVE-2026-33753Mediumrfc3161-client: rfc3161-client Has Improper Certificate ValidationCVE-2026-1163Mediumlollms: parisneo/lollms has an insufficient session expiration vulnerabilityCVE-2026-39847Highemmett: Emmett has a path traversal in internal assets handlerCVE-2026-40071Mediumpyload-ng: pyload-ng has a WebUI JSON permission mismatch that lets ADD/DELETE users invoke MODIFY-only actionsCVE-2026-39413Mediumlightrag-hku: lightrag-hku: JWT Algorithm Confusion Vulnerability

Stop the waste.
Protect your environment with Kodem.