Open Source Vulnerabilities
praisonaiagents
praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets
praisonaiagents
praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets
praisonai
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
praisonai
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
praisonaiagents
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
praisonaiagents
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
praisonaiagents
praisonaiagents web_crawl vulnerable to SSRF via redirect-following
praisonaiagents
praisonaiagents web_crawl vulnerable to SSRF via redirect-following
django-cms
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
django-cms
django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)
django-cms
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
django-cms
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
mcp-contextforge-gateway
mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server
mcp-contextforge-gateway
mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server
nltk
NLTK AllowlistUnpickler dotted-name validation bypass allows remote code execution
nltk
NLTK AllowlistUnpickler dotted-name validation bypass allows remote code execution
hydra-core
Hydra: hydra.utils.instantiate with untrusted config can lead to code execution
hydra-core
Hydra: hydra.utils.instantiate with untrusted config can lead to code execution
xinference
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
xinference
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
nltk
NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking
nltk
NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking
django-cms
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
django-cms
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
django-cms
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
django-cms
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
django-cms
django CMS: Stored XSS in edit-mode plugin exception rendering
django-cms
django CMS: Stored XSS in edit-mode plugin exception rendering
wagtail
Wagtail: Improper restriction handling on Pages admin API
wagtail
Wagtail: Improper restriction handling on Pages admin API
django-cms
django CMS: Structure endpoint bypasses page-view permission
django-cms
django CMS: Structure endpoint bypasses page-view permission
django-cms
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
django-cms
django CMS: Clipboard copy IDOR discloses unauthorized plugin content
langgraph-store-mongodb
LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure
langgraph-store-mongodb
LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure
langgraph-checkpoint-mongodb
LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure
langgraph-checkpoint-mongodb
LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure
asteval
asteval has a Sandbox Escape via BaseException Subclasses
asteval
asteval has a Sandbox Escape via BaseException Subclasses
document-merge-service
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
document-merge-service
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
copier
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
copier
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
langgraph-api
langgraph-api: Incomplete assistant authorization in LangGraph Server run creation
langgraph-api
langgraph-api: Incomplete assistant authorization in LangGraph Server run creation
langgraph-api
langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication
langgraph-api
langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication
accelerate
Accelerate path traversal and denial of service via sharded checkpoint weight_map entries
accelerate
Accelerate path traversal and denial of service via sharded checkpoint weight_map entries
keras
Keras model loading is vulnerable to denial of service through HDF5 shape bombs
keras
Keras model loading is vulnerable to denial of service through HDF5 shape bombs
gitpython
GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution
gitpython
GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution
gitpython
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
gitpython
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
gitpython
GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks
gitpython
GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks
gitpython
GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
gitpython
GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
mlflow
MLflow AI Gateway permits SSRF through an unvalidated api_base
mlflow
MLflow AI Gateway permits SSRF through an unvalidated api_base
transformers
Transformers save_pretrained path traversal allows arbitrary file writes through chat template names
transformers
Transformers save_pretrained path traversal allows arbitrary file writes through chat template names
thrift
Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit
thrift
Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit
thrift
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop
thrift
Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop
thrift
Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability
thrift
Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability
gitpython
GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
gitpython
GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL
gitpython
GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
gitpython
GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
gitpython
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
gitpython
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
snowflake-connector-python
Snowflake Connector for Python improperly verifies TLS hostnames
snowflake-connector-python
Snowflake Connector for Python improperly verifies TLS hostnames
snowflake-sqlalchemy
Snowflake SQLAlchemy affected by SQL injection and local file disclosure vulnerabilities
snowflake-sqlalchemy
Snowflake SQLAlchemy affected by SQL injection and local file disclosure vulnerabilities
crewai-tools
crewai-tools SSRF redirect bypass exposes internal services
crewai-tools
crewai-tools SSRF redirect bypass exposes internal services
pyod
PyOD persistence.load deserializes untrusted artifacts before validation
pyod
PyOD persistence.load deserializes untrusted artifacts before validation
cognee
Cognee allows non-superusers to overwrite global LLM configuration
cognee
Cognee allows non-superusers to overwrite global LLM configuration
apache-airflow
Apache Airflow exposes sensitive JSON Variable values through the Bulk Variables API
apache-airflow
Apache Airflow exposes sensitive JSON Variable values through the Bulk Variables API
openharness-ai
OpenHarness remote resume commands expose other users' saved session snapshots
openharness-ai
OpenHarness remote resume commands expose other users' saved session snapshots
openharness-ai
OpenHarness remote project-context commands allow persistent prompt poisoning
openharness-ai
OpenHarness remote project-context commands allow persistent prompt poisoning
ironic
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
ironic
OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties
chromadb
ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to
chromadb
ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to
chromadb
ChromaDB has a code injection vulnerability
chromadb
ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection
chromadb
ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection
