PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2025-68143Mediummcp-server-git: mcp-server-git's unrestricted git_init tool allows repository creation at arbitrary filesystem locationsCVE-2025-67895Criticalapache-airflow-providers-edge3: Apache Airflow Providers Edge3 exposes internal API allowing RCE in web server contextCVE-2025-68146Mediumfilelock: filelock has a TOCTOU race condition which allows symlink attacks during lock file creationCVE-2025-68142Lowpymdown-extensions: PyMdown Extensions has a ReDOS bug in its Figure Capture extensionCVE-2025-68113Mediumaltcha-lib: ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and ReplayCVE-2025-67748Highfickling: Fickling has Code Injection vulnerability via pty.spawn()CVE-2025-67747Highfickling: Fickling has missing detection for marshal.loads and types.FunctionType in unsafe modules listCVE-2025-67715MediumWeblate: Weblate has Systematic User and Project Enumeration via Broken Authorization in REST API (IDOR)CVE-2025-67492MediumWeblate: Weblate's over‑permissive webhook endpoint enables mass repository updates and component enumerationCVE-2025-64725LowWeblate: Weblate has improper validation upon invitation acceptanceCVE-2025-65430Mediumdjango-allauth: django-allauth does not reject access tokens for inactive usersCVE-2025-65431Mediumdjango-allauth: django-allauth's Okta and NetIQ implementations used a mutable identifier for authorization decisionsCVE-2025-66388Mediumapache-airflow: Apache Airflow exposes secret values to authenticated UI users via rendered templatesCVE-2025-14692Lowmayan-edms: Mayan EDMS has an Open Redirect through the /authentication/ fileCVE-2025-14691Lowmayan-edms: Mayan EDMS is vulnerable to XSS through the /authentication/ fileCVE-2025-14542Highutcp: Universal Tool Calling Protocol (UTCP) client library for Python vulnerable to Trust Boundary Violation through Manual JSON specificationCVE-2025-13780Criticalpgadmin4: pgadmin4 has a Meta-Command Filter Command ExecutionCVE-2025-67720Mediumpyrofork: Pyrofork has a Path Traversal in download_media MethodCVE-2025-67644Highlanggraph-checkpoint-sqlite: LangGraph's SQLite is vulnerable to SQL injection via metadata filter key in SQLite checkpointer list methodCVE-2025-67511Criticalcai-framework: Cybersecurity AI (CAI) vulnerable to Command Injection in run_ssh_command_with_credentials Agent toolCVE-2025-67485Mediummad-proxy: HTTP/HTTPS Traffic Interception Bypass in mad-proxyCVE-2025-67502Mediumtaguette: Open Redirect Vulnerability in TaguetteCVE-2025-66645Highnicegui: NiceGUI has a path traversal in app.add_media_files() allows arbitrary file readCVE-2025-66470Mediumnicegui: NiceGUI Stored/Reflected XSS in ui.interactive_image via unsanitized SVG contentCVE-2025-66469Mediumnicegui: NiceGUI Reflected XSS in ui.add_css, ui.add_scss, and ui.add_sass via Style Injection

Stop the waste.
Protect your environment with Kodem.