Open Source Vulnerabilities

    Dashboard / Open Source Vulnerabilities

    PYSEC-2026-3900
    Fix available
    Packages

    praisonaiagents

    Summary

    praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets

    Published
    10 Sept 2026
    PYSEC-2026-3891
    Fix available
    Packages

    praisonai

    Summary

    PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code

    Published
    10 Sept 2026
    PYSEC-2026-3903
    Fix available
    Packages

    praisonaiagents

    Summary

    PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code

    Published
    10 Sept 2026
    PYSEC-2026-3898
    Fix available
    Packages

    praisonaiagents

    Summary

    praisonaiagents web_crawl vulnerable to SSRF via redirect-following

    Published
    10 Sept 2026
    PYSEC-2026-3824
    Fix available
    Packages

    django-cms

    Summary

    django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning)

    Published
    10 Sept 2026
    PYSEC-2026-3822
    Fix available
    Packages

    django-cms

    Summary

    django CMS: Plugin move endpoint allows cyclic reparenting (DoS)

    Published
    10 Sept 2026
    PYSEC-2026-3862
    Fix available
    Packages

    mcp-contextforge-gateway

    Summary

    mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server

    Published
    10 Sept 2026
    PYSEC-2026-3867
    Fix available
    Packages

    nltk

    Summary

    NLTK AllowlistUnpickler dotted-name validation bypass allows remote code execution

    Published
    10 Sept 2026
    PYSEC-2026-3850
    Fix available
    Packages

    hydra-core

    Summary

    Hydra: hydra.utils.instantiate with untrusted config can lead to code execution

    Published
    10 Sept 2026
    PYSEC-2026-3946
    Fix available
    Packages

    xinference

    Summary

    Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing

    Published
    10 Sept 2026
    PYSEC-2026-3870
    Fix available
    Packages

    nltk

    Summary

    NLTK TweetTokenizer vulnerable to denial of service through catastrophic regex backtracking

    Published
    10 Sept 2026
    PYSEC-2026-3823
    Fix available
    Packages

    django-cms

    Summary

    django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff

    Published
    10 Sept 2026
    PYSEC-2026-3821
    Fix available
    Packages

    django-cms

    Summary

    django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)

    Published
    10 Sept 2026
    PYSEC-2026-3825
    Fix available
    Packages

    django-cms

    Summary

    django CMS: Stored XSS in edit-mode plugin exception rendering

    Published
    10 Sept 2026
    PYSEC-2026-3939
    Fix available
    Packages

    wagtail

    Summary

    Wagtail: Improper restriction handling on Pages admin API

    Published
    10 Sept 2026
    PYSEC-2026-3826
    Fix available
    Packages

    django-cms

    Summary

    django CMS: Structure endpoint bypasses page-view permission

    Published
    10 Sept 2026
    PYSEC-2026-3820
    Fix available
    Packages

    django-cms

    Summary

    django CMS: Clipboard copy IDOR discloses unauthorized plugin content

    Published
    10 Sept 2026
    PYSEC-2026-3860
    Fix available
    Packages

    langgraph-store-mongodb

    Summary

    LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure

    Published
    10 Sept 2026
    PYSEC-2026-3859
    Fix available
    Packages

    langgraph-checkpoint-mongodb

    Summary

    LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposure

    Published
    10 Sept 2026
    PYSEC-2026-3807
    Fix available
    Packages

    asteval

    Summary

    asteval has a Sandbox Escape via BaseException Subclasses

    Published
    10 Sept 2026
    PYSEC-2026-3830
    Fix available
    Packages

    document-merge-service

    Summary

    Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)

    Published
    10 Sept 2026
    PYSEC-2026-3818
    Fix available
    Packages

    copier

    Summary

    Copier has a trust-prefix bypass via path traversal that runs tasks unprompted

    Published
    10 Sept 2026
    PYSEC-2026-3858
    Fix available
    Packages

    langgraph-api

    Summary

    langgraph-api: Incomplete assistant authorization in LangGraph Server run creation

    Published
    10 Sept 2026
    PYSEC-2026-3857
    Fix available
    Packages

    langgraph-api

    Summary

    langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication

    Published
    10 Sept 2026
    PYSEC-2026-3804
    No fix available
    Packages

    accelerate

    Summary

    Accelerate path traversal and denial of service via sharded checkpoint weight_map entries

    Published
    10 Sept 2026
    PYSEC-2026-3856
    Fix available
    Packages

    keras

    Summary

    Keras model loading is vulnerable to denial of service through HDF5 shape bombs

    Published
    10 Sept 2026
    PYSEC-2026-3843
    Fix available
    Packages

    gitpython

    Summary

    GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution

    Published
    10 Sept 2026
    PYSEC-2026-3841
    Fix available
    Packages

    gitpython

    Summary

    GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

    Published
    10 Sept 2026
    PYSEC-2026-3840
    Fix available
    Packages

    gitpython

    Summary

    GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks

    Published
    10 Sept 2026
    PYSEC-2026-3838
    Fix available
    Packages

    gitpython

    Summary

    GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

    Published
    10 Sept 2026
    PYSEC-2026-3865
    No fix available
    Packages

    mlflow

    Summary

    MLflow AI Gateway permits SSRF through an unvalidated api_base

    Published
    10 Sept 2026
    PYSEC-2026-3929
    Fix available
    Packages

    transformers

    Summary

    Transformers save_pretrained path traversal allows arbitrary file writes through chat template names

    Published
    10 Sept 2026
    PYSEC-2026-3927
    Fix available
    Packages

    thrift

    Summary

    Apache Thrift Python bindings have a Improper Validation of Certificate with Host Mismatch vulnerabilit

    Published
    10 Sept 2026
    PYSEC-2026-3926
    Fix available
    Packages

    thrift

    Summary

    Apache Thrift Python, Go, PHP and Java bindings have an Infinite Loop

    Published
    10 Sept 2026
    PYSEC-2026-3925
    Fix available
    Packages

    thrift

    Summary

    Apache Thrift Python bindings have an Improper Handling of Highly Compressed Data (Data Amplification) vulnerability

    Published
    10 Sept 2026
    PYSEC-2026-3842
    Fix available
    Packages

    gitpython

    Summary

    GitPython: Environment-variable exfiltration via os.path.expandvars() on Repo.clone_from() URL

    Published
    10 Sept 2026
    PYSEC-2026-3839
    Fix available
    Packages

    gitpython

    Summary

    GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`

    Published
    10 Sept 2026
    PYSEC-2026-3836
    Fix available
    Packages

    gitpython

    Summary

    GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist

    Published
    10 Sept 2026
    PYSEC-2026-3920
    Fix available
    Packages

    snowflake-connector-python

    Summary

    Snowflake Connector for Python improperly verifies TLS hostnames

    Published
    10 Sept 2026
    PYSEC-2026-3921
    Fix available
    Packages

    snowflake-sqlalchemy

    Summary

    Snowflake SQLAlchemy affected by SQL injection and local file disclosure vulnerabilities

    Published
    10 Sept 2026
    PYSEC-2026-3819
    Fix available
    Packages

    crewai-tools

    Summary

    crewai-tools SSRF redirect bypass exposes internal services

    Published
    10 Sept 2026
    PYSEC-2026-3909
    Fix available
    Packages

    pyod

    Summary

    PyOD persistence.load deserializes untrusted artifacts before validation

    Published
    10 Sept 2026
    PYSEC-2026-3816
    Fix available
    Packages

    cognee

    Summary

    Cognee allows non-superusers to overwrite global LLM configuration

    Published
    10 Sept 2026
    PYSEC-2026-3806
    Fix available
    Packages

    apache-airflow

    Summary

    Apache Airflow exposes sensitive JSON Variable values through the Bulk Variables API

    Published
    10 Sept 2026
    PYSEC-2026-3881
    No fix available
    Packages

    openharness-ai

    Summary

    OpenHarness remote resume commands expose other users' saved session snapshots

    Published
    10 Sept 2026
    PYSEC-2026-3880
    No fix available
    Packages

    openharness-ai

    Summary

    OpenHarness remote project-context commands allow persistent prompt poisoning

    Published
    10 Sept 2026
    PYSEC-2026-3852
    Fix available
    Packages

    ironic

    Summary

    OpenStack Ironic can return unredacted sensitive information when applying a PATCH to update fields in volume properties

    Published
    10 Sept 2026
    PYSEC-2026-3815
    No fix available
    Packages

    chromadb

    Summary

    ChromaDB's SimpleRBACAuthorizationProvider doesn't check which tenant, database, or collection a permission applies to

    Published
    10 Sept 2026
    PYSEC-2026-3814
    No fix available
    Packages

    chromadb

    Summary

    ChromaDB has a code injection vulnerability

    Published
    10 Sept 2026
    PYSEC-2026-3813
    No fix available
    Packages

    chromadb

    Summary

    ChromaDB allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection

    Published
    10 Sept 2026