VulnScope — package-centric CVE lookup- CRITICAL9.6CVE-2026-55447Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit
- HIGH7.5CVE-2026-55446Langflow: Unauthenticated DoS through multipart form boundary file upload
- MEDIUM6.1Langflow: Logout button does not clear session
- CRITICAL9.9Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
- —py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read()
- —py7zr: Decompression bomb (zip bomb) denial of service via unchecked extraction size
- MEDIUM6.8dbt MCP Server: Unauthenticated OAuth Context Endpoint Leaks dbt Platform Tokens
- MEDIUM6.5UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()
- —Python Liquid: Infinite loop when parsing malformed `{% case %}` tags
- HIGH7.1jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories
- —jupyterlab-git extension: Stored XSS leading to RCE
- HIGH7.5Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model Loaders
- HIGH7.6Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN
- HIGH8.0py7zr: Arbitrary File Write Vulnerability
- HIGH7.3Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()
- —PGHoard: Password written to debug log
- HIGH7.5Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
- —Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP
- LOW2.2BBOT: Symlink-Following Arbitrary Write via github_workflows Module
- MEDIUM6.5BBOT: Arbitrary File Write in postman_download Module
- LOW3.1BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing
- MEDIUM5.3BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284
- CRITICAL9.8python-statemachine SCXML <data expr> Eval Injection
- MEDIUM6.1marimo contains a reflected cross-site scripting vulnerability in the notebook page
- MEDIUM5.5Hermes Agent creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644)