PyPI vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-54771Highlangroid: Langroid: handle_message() executes user-supplied tool JSON without sender verification CVE-2026-54769Criticallangroid: Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgentCVE-2026-54760Criticallangroid: Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file callsCVE-2026-53759Lowlinuxfabrik-lib: Linuxfabrik Monitoring Plugins allow insecure creation of SQLite databasesCVE-2026-55786Highflyto-core: flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module`CVE-2026-55787Highflyto-core: flyto-core has SSRF guard bypass via IPv6 transition addresses (IPv4-mapped / 6to4 / NAT64) in validate_url_ssrfCVE-2026-49452Mediumweasyprint: WeasyPrint has CSS Injection via Presentational HintsCVE-2022-46292Highopenbabel: Open Babel has out-of-bounds write in MOPAC translationVectors[] (UNIT CELL TRANSLATION)CVE-2026-49360Highrecce: Recce server has unauthenticated SQL execution that allows local file read/write through DuckDBCVE-2026-49292Lowkiwitcms: Kiwi TCMS's /init-db/ page renders and responds to requests after first useCVE-2026-52830Criticalfast-mcp-telegram: fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protectionCVE-2026-52817Highlinuxfabrik-lib: Linuxfabrik Monitoring Plugins: Sudoers may be able to obtain privilege escalation via /usr/bin/apt-get argumentsCVE-2026-49852Highjoserfc: joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)CVE-2026-52726Highdulwich: Dulwich's submodule path traversal in porcelain.submodule_update / porcelain.clone(recurse_submodules=True) yields RCE via attacker-dropped…CVE-2026-50180Highlangroid: Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file readCVE-2026-50181Highlangroid: Langroid: Path traversal in the file tools allows read/write outside configured current directoryCVE-2026-50027Criticalmcp-memory-service: mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/DeleteCVE-2026-49986Highneuro-cortex-memory: Cortex has Untrusted Project Bootstrap Code Execution via `CLAUDE_PROJECT_DIR`CVE-2022-46295Highopenbabel: Open Babel has out-of-bounds write in MSI translationVectors[]CVE-2022-46294Highopenbabel: Open Babel has out-of-bounds write in MOPAC IN translationVectors[] (Tv atom)CVE-2022-46293Highopenbabel: Open Babel has out-of-bounds write in MOPAC translationVectors[] (FINAL POINT)CVE-2022-46291Highopenbabel: Open Babel has out-of-bounds write in Gaussian translationVectors[]CVE-2022-46290Highopenbabel: Open Babel has out-of-bounds write in ORCA nAtoms parser (second variant)CVE-2022-46289Highopenbabel: Open Babel has out-of-bounds write in ORCA nAtoms parserCVE-2022-46280Highopenbabel: Open Babel has uninitialized pointer dereference in PQS pFormat

Stop the waste.
Protect your environment with Kodem.