PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-94P4-4CQ8-9G67HighGitPython: GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)CVE-2026-59221Highopen-webui: open-webui terminal proxy path traversal guard bypass via 9x encoded traversalCVE-2026-59225Mediumopen-webui: Open WebUI: Arena task endpoints can bypass underlying model access controlsCVE-2026-59212Mediumopen-webui: Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/deleteCVE-2026-59224Highopen-webui: Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal…CVE-2026-59223Mediumopen-webui: Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matchingCVE-2026-55404Highyt-dlp: yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link outputCVE-2026-59222Mediumopen-webui: Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentialsCVE-2026-59215Lowopen-webui: Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id bindingCVE-2026-59213Lowopen-webui: Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)CVE-2026-59217Mediumopen-webui: Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)CVE-2026-59216Highopen-webui: Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_idCVE-2026-59714Highopen-webui: Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)CVE-2026-59219Highopen-webui: Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logoutCVE-2026-59715Lowopen-webui: Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)CVE-2026-59227Mediumopen-webui: Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permissionCVE-2026-59220Mediumopen-webui: Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default configCVE-2026-59226Lowopen-webui: Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocationCVE-2026-59218Mediumopen-webui: Open WebUI: Account enumeration via observable login timing discrepancyCVE-2026-59214Highopen-webui: Open WebUI: Stored web worker XSS via PyodideGHSA-464C-974J-9XM6Lowaws-cdk-lib: AWS CDK CodeBuild S3 Log Encryption Boolean InversionGHSA-R9MR-M37C-5FR3HighGitPython: GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command executionGHSA-6P8H-3WGX-97GFHighGitPython: GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooksGHSA-FJR4-X663-MWXCHighGitPython: GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)GHSA-3RP5-JJMW-4WV2Highgitpython: GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)

Stop the waste.
Protect your environment with Kodem.