Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    PYSEC-2026-3827
    Fix available
    Packages

    djangorestframework

    Summary

    Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`

    Published
    10 Sept 2026
    PYSEC-2026-3828
    Fix available
    Packages

    djangorestframework

    Summary

    Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests

    Published
    10 Sept 2026
    PYSEC-2026-3917
    Fix available
    Packages

    restrictedpython

    Summary

    RestrictedPython guard hooks can be shadowed via positional-only arguments

    Published
    10 Sept 2026
    PYSEC-2026-3883
    Fix available
    Packages

    plone-app-event

    Summary

    plone.app.event vulnerable to denial of service via iCalendar import

    Published
    10 Sept 2026
    PYSEC-2026-3942
    Fix available
    Packages

    weblate

    Summary

    Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project

    Published
    10 Sept 2026
    PYSEC-2026-3941
    Fix available
    Packages

    weblate

    Summary

    Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups

    Published
    10 Sept 2026
    PYSEC-2026-3906
    Fix available
    Packages

    protego

    Summary

    Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching

    Published
    10 Sept 2026
    PYSEC-2026-3884
    Fix available
    Packages

    plone-app-portlets

    Summary

    plone.app.portlets vulnerable to denial of service via RSS feed portlet

    Published
    10 Sept 2026
    PYSEC-2026-3882
    Fix available
    Packages

    piccolo-admin

    Summary

    piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.

    Published
    10 Sept 2026
    PYSEC-2026-3945
    Fix available
    Packages

    wsgidav

    Summary

    WsgiDAV MySQL provider has a blind SQL injection

    Published
    10 Sept 2026
    PYSEC-2026-3817
    Fix available
    Packages

    compliance-trestle

    Summary

    Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data

    Published
    10 Sept 2026
    PYSEC-2026-3805
    Fix available
    Packages

    aiosmtplib

    Summary

    aiosmtplib: STARTTLS response injection

    Published
    10 Sept 2026
    PYSEC-2026-3943
    Fix available
    Packages

    webob

    Summary

    WebOb: Open redirect in Location header normalization via leading C0 control / space characters

    Published
    10 Sept 2026
    PYSEC-2026-3861
    Fix available
    Packages

    litellm

    Summary

    LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint

    Published
    10 Sept 2026
    PYSEC-2026-3808
    Fix available
    Packages

    asyncssh

    Summary

    asyncssh has SCP Path Traversal to Arbitrary File Write

    Published
    10 Sept 2026
    PYSEC-2026-3809
    Fix available
    Packages

    asyncssh

    Summary

    asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution

    Published
    10 Sept 2026
    PYSEC-2026-3919
    No fix available
    Packages

    senaite-core

    Summary

    senaite.core Vulnerable to Eval Injection and Missing Authorization

    Published
    10 Sept 2026
    PYSEC-2026-3855
    Fix available
    Packages

    kas

    Summary

    kas Persistently Disables SSH Host Key Checking

    Published
    10 Sept 2026
    PYSEC-2026-3924
    Fix available
    Packages

    starlette-admin

    Summary

    Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS

    Published
    10 Sept 2026
    PYSEC-2026-3853
    Fix available
    Packages

    jupyterhub

    Summary

    JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login

    Published
    10 Sept 2026
    PYSEC-2026-3851
    Fix available
    Packages

    icalendar

    Summary

    icalendar has Algorithmic Complexity in Equality

    Published
    10 Sept 2026
    PYSEC-2026-3811
    Fix available
    Packages

    chainlit

    Summary

    Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access

    Published
    10 Sept 2026
    PYSEC-2026-3812
    Fix available
    Packages

    chainlit

    Summary

    Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution

    Published
    10 Sept 2026
    PYSEC-2026-3832
    Fix available
    Packages

    eml-parser

    Summary

    eml_parser vulnerable to DoS via deeply nested parens in Received headers

    Published
    10 Sept 2026
    PYSEC-2026-3833
    Fix available
    Packages

    eml-parser

    Summary

    eml_parser has parser DoS via deeply nested parentheses in e-mail headers

    Published
    10 Sept 2026
    PYSEC-2026-3831
    Fix available
    Packages

    eml-parser

    Summary

    eml_parser has a URL extraction bypass via HTML entities in URLs

    Published
    10 Sept 2026
    PYSEC-2026-3916
    Fix available
    Packages

    reachy-mini

    Summary

    reachy_mini Allows Unrestricted Upload of File with Dangerous Type

    Published
    10 Sept 2026
    PYSEC-2026-3914
    Fix available
    Packages

    qwed

    Summary

    qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`

    Published
    10 Sept 2026
    PYSEC-2026-3829
    Fix available
    Packages

    djust

    Summary

    djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls

    Published
    10 Sept 2026
    PYSEC-2026-3866
    Fix available
    Packages

    nextcloud-mcp-server

    Summary

    nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )

    Published
    10 Sept 2026
    PYSEC-2026-3932
    Fix available
    Packages

    utcp-websocket

    Summary

    utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins

    Published
    10 Sept 2026
    PYSEC-2026-3931
    Fix available
    Packages

    utcp-gql

    Summary

    utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins

    Published
    10 Sept 2026
    PYSEC-2026-3915
    Fix available
    Packages

    qwed-mcp

    Summary

    qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input

    Published
    10 Sept 2026
    PYSEC-2026-3886
    Fix available
    Packages

    praisonai

    Summary

    PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)

    Published
    10 Sept 2026
    PYSEC-2026-3892
    Fix available
    Packages

    praisonai

    Summary

    PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server

    Published
    10 Sept 2026
    PYSEC-2026-3889
    Fix available
    Packages

    praisonai

    Summary

    PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret

    Published
    10 Sept 2026
    PYSEC-2026-3885
    Fix available
    Packages

    praisonai

    Summary

    PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete

    Published
    10 Sept 2026
    PYSEC-2026-3902
    Fix available
    Packages

    praisonaiagents

    Summary

    praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location

    Published
    10 Sept 2026
    PYSEC-2026-3893
    Fix available
    Packages

    praisonai

    Summary

    PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced

    Published
    10 Sept 2026
    PYSEC-2026-3890
    Fix available
    Packages

    praisonai

    Summary

    PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation

    Published
    10 Sept 2026
    PYSEC-2026-3895
    Fix available
    Packages

    praisonai

    Summary

    PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114

    Published
    10 Sept 2026
    PYSEC-2026-3894
    Fix available
    Packages

    praisonai

    Summary

    PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated

    Published
    10 Sept 2026
    PYSEC-2026-3888
    Fix available
    Packages

    praisonai

    Summary

    PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks

    Published
    10 Sept 2026
    PYSEC-2026-3901
    Fix available
    Packages

    praisonaiagents

    Summary

    praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool

    Published
    10 Sept 2026
    PYSEC-2026-3904
    Fix available
    Packages

    praisonaiagents

    Summary

    praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)

    Published
    10 Sept 2026
    PYSEC-2026-3887
    Fix available
    Packages

    praisonai

    Summary

    PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution

    Published
    10 Sept 2026
    PYSEC-2026-3905
    Fix available
    Packages

    praisonaiagents

    Summary

    praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)

    Published
    10 Sept 2026
    PYSEC-2026-3897
    Fix available
    Packages

    praisonai

    Summary

    PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)

    Published
    10 Sept 2026
    PYSEC-2026-3899
    Fix available
    Packages

    praisonaiagents

    Summary

    praisonaiagents: AgentServer declares auth_token but never enforces it on any route

    Published
    10 Sept 2026
    PYSEC-2026-3896
    Fix available
    Packages

    praisonai

    Summary

    PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server

    Published
    10 Sept 2026