PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-71322Highpicklescan: Picklescan Bypasses Unsafe Globals Check using pty.spawnGHSA-VQMV-47XG-9WPRHighpicklescan: Picklescan missing detection when calling pty.spawnCVE-2025-71320Highpicklescan: Picklescan has Incomplete List of Disallowed InputsCVE-2025-71323Highpicklescan: Picklescan does not block ctypesCVE-2025-71321Highpicklescan: Picklescan vulnerable to Arbitrary File WritingGHSA-RCFX-77HG-W2WVHighfastmcp: FastMCP updated to MCP 1.23+ due to CVE-2025-66416CVE-2025-67729Highlmdeploy: lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load()CVE-2025-14931Criticalsmolagents: Hugging Face smolagents: Unsafe deserialization in Remote Python Executor leads to RCECVE-2025-68664Criticallangchain-core: LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIsCVE-2025-65713Mediumhomeassistant: Home Assistant Core before is vulnerable to Directory TraversalCVE-2025-67743Mediumlocal-deep-research: Local Deep Research is Vulnerable to Server-Side Request Forgery (SSRF) in Download ServiceCVE-2025-68480Mediummarshmallow: Marshmallow has DoS in Schema.load(many)CVE-2025-34469Mediumcowrie: Cowrie has a SSRF vulnerability in wget/curl emulation enabling DDoS amplificationCVE-2025-68478Highlangflow: External Control of File Name or Path in LangflowCVE-2025-68477Highlangflow: Langflow vulnerable to Server-Side Request ForgeryCVE-2025-68481Mediumfastapi-users: FastAPI Users Vulnerable to 1-click Account Takeover in Apps Using FastAPI SSOCVE-2025-14882Lowpretix: pretix has Broken Access Control Allowing Cross-User File Access via UUIDCVE-2025-14881Lowpretix: pretix has Broken Access Control Allowing Cross-User File Access via UUIDCVE-2025-14546Mediumfastapi-sso: FastAPI SSP is vulnerable to Cross-site Request Forgery (CSRF) through improper OAuth parameter validationCVE-2025-68398CriticalWeblate: Weblate is vulnerable to RCE through Git config file overwriteCVE-2025-68279HighWeblate: Weblate has an arbitrary file read via symbolic linksCVE-2025-53000Highnbconvert: nbconvert has an uncontrolled search path that leads to unauthorized code execution on WindowsCVE-2025-68463Mediumbiopython: Biopython is vulnerable to doctype XML external entity (XXE) injection through Bio.EntrezCVE-2025-68145Mediummcp-server-git: mcp-server-git has missing path validation when using --repository flagCVE-2025-68144Mediummcp-server-git: mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files

Stop the waste.
Protect your environment with Kodem.