Public scan — anyone with this URL can view this analysis. Sign up to track your own repos privately, run scheduled re-scans, and get AI fix prompts via your dashboard.

Shubhamsaboo/awesome-llm-apps

https://github.com/Shubhamsaboo/awesome-llm-apps · scanned 2026-07-23 19:43 UTC (1 month, 2 weeks ago)

2740 raw signals (0 security + 2740 graph)

UNIFIED Repobility · multi-layer engine · AI coders

Complete repo analysis

Last scanned 1 month, 2 weeks ago · v9 · 2727 actionable findings from 1 signal source. 13 repeated signals grouped for readability. Security checks, system graph analysis, and verified AI-agent feedback are merged into one review queue.

JSON
Severity distribution — click a segment to filter
Active filters: excluding tests × Reset all
Corpus Intelligence Cross-corpus context (cohort percentile, top patterns, fix plan) is shown only on repositories you own. Sign up and connect your repo to view it.
Scan summary Repository scanned at 55.5/100 with 100.0% coverage. It contains 7310 nodes across 30 cross-layer flows, written primarily in mixed languages. Engine surfaced 2740 findings — concentrated in security (1771), dependencies (821), quality (54). Risk profile is high: 23 critical, 730 high, 1600 medium. Recommended next step: open the security layer findings first — that's where the highest-impact wins live.

Showing 2700 of 2727 actionable findings. 2740 raw detector signals were grouped into reader-sized issues. Click TP / FP to vote on a finding's accuracy — votes adjust the confidence weighting and improve detection across the platform.

critical System graph security Trivy conf 1.00 CVE-2023-50447: Pillow 10.0.0 — starter_ai_agents/ai_medical_imaging_agent/requirements.txt
pillow: Arbitrary Code Execution via the environment parameter Pillow through 10.1.0 allows PIL.ImageMath.eval Arbitrary Code Execution via the environment parameter, a different vulnerability than CVE-2022-22817 (which was about the expression parameter). Package: Pillow Installed: 10.0.0 Fixed …
VulnCve 2023 50447
critical System graph security Trivy conf 1.00 CVE-2025-14009: nltk 3.9.1 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
nltk: Zip Slip Vulnerability in nltk Leading to Code Execution A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() without performing path validation or security checks. This…
VulnCve 2025 14009
critical System graph security Trivy conf 1.00 CVE-2025-23042: gradio 5.9.1 — advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt
Gradio Blocked Path ACL Bypass Vulnerability Gradio is an open-source Python package that allows quick building of demos and web application for machine learning models, API, or any arbitrary Python function. Gradio's Access Control List (ACL) for file paths can be bypassed by altering the letter …
VulnCve 2025 23042
critical System graph security Trivy conf 1.00 CVE-2025-32434: torch 2.2.2 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
PyTorch is a Python package that provides tensor computation with stro ... PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command Execution (RCE) vulnerab…
VulnCve 2025 32434
critical System graph security Trivy conf 1.00 CVE-2025-43859: h11 0.14.0 — advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
h11: h11 accepts some malformed Chunked-Encoding bodies h11 is a Python implementation of HTTP/1.1. Prior to version 0.16.0, a leniency in h11's parsing of line terminators in chunked-coding message bodies can lead to request smuggling vulnerabilities under certain conditions. This issue has been …
VulnCve 2025 43859
critical System graph security Trivy conf 1.00 CVE-2025-43859: h11 0.14.0 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
h11: h11 accepts some malformed Chunked-Encoding bodies h11 is a Python implementation of HTTP/1.1. Prior to version 0.16.0, a leniency in h11's parsing of line terminators in chunked-coding message bodies can lead to request smuggling vulnerabilities under certain conditions. This issue has been …
VulnCve 2025 43859
critical System graph security Trivy conf 1.00 CVE-2025-47241: browser-use 0.1.26 — starter_ai_agents/ai_meme_generator_agent_browseruse/requirements.txt
Browser Use allows bypassing `allowed_domains` by putting a decoy domain in http auth username portion of a URL In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be placed in the authority component. Package: browser-use Installed: 0…
VulnCve 2025 47241
critical System graph security Trivy conf 1.00 CVE-2025-55182: next 15.3.2 — generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml
next: React Server Components: Pre-authentication remote code execution via unsafe deserialization A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react…
VulnCve 2025 55182
critical System graph security Trivy conf 1.00 CVE-2025-55182: next 15.3.3 — advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml
next: React Server Components: Pre-authentication remote code execution via unsafe deserialization A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react…
VulnCve 2025 55182
critical System graph security Trivy conf 1.00 CVE-2025-68664: langchain-core 0.3.25 — rag_tutorials/rag_agent_cohere/requirements.txt
langchain-core: LangChain: Arbitrary code execution via serialization injection LangChain is a framework for building agents and LLM-powered applications. Prior to versions 0.3.81 and 1.2.5, a serialization injection vulnerability exists in LangChain's dumps() and dumpd() functions. The functions …
VulnCve 2025 68664
critical System graph security Trivy conf 1.00 CVE-2025-68664: langchain-core 0.3.28 — rag_tutorials/corrective_rag/requirements.txt
langchain-core: LangChain: Arbitrary code execution via serialization injection LangChain is a framework for building agents and LLM-powered applications. Prior to versions 0.3.81 and 1.2.5, a serialization injection vulnerability exists in LangChain's dumps() and dumpd() functions. The functions …
VulnCve 2025 68664
critical System graph security Trivy conf 1.00 CVE-2025-68664: langchain-core 0.3.28 — rag_tutorials/rag_database_routing/requirements.txt
langchain-core: LangChain: Arbitrary code execution via serialization injection LangChain is a framework for building agents and LLM-powered applications. Prior to versions 0.3.81 and 1.2.5, a serialization injection vulnerability exists in LangChain's dumps() and dumpd() functions. The functions …
VulnCve 2025 68664
critical System graph security Trivy conf 1.00 CVE-2025-68664: langchain-core 0.3.49 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
langchain-core: LangChain: Arbitrary code execution via serialization injection LangChain is a framework for building agents and LLM-powered applications. Prior to versions 0.3.81 and 1.2.5, a serialization injection vulnerability exists in LangChain's dumps() and dumpd() functions. The functions …
VulnCve 2025 68664
critical System graph security Trivy conf 1.00 CVE-2025-68664: langchain-core 0.3.65 — advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock
langchain-core: LangChain: Arbitrary code execution via serialization injection LangChain is a framework for building agents and LLM-powered applications. Prior to versions 0.3.81 and 1.2.5, a serialization injection vulnerability exists in LangChain's dumps() and dumpd() functions. The functions …
VulnCve 2025 68664
critical System graph security Trivy conf 1.00 CVE-2026-25896: fast-xml-parser 5.2.5 — generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml
fast-xml-parser: fast-xml-parser: Cross-Site Scripting (XSS) due to improper DOCTYPE entity handling fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. From 4.1.3to before 5.3.5, a dot (.) in a DOCTYPE en…
VulnCve 2026 25896
critical System graph security Trivy conf 1.00 CVE-2026-35002: agno 1.4.2 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
Agno is vulnerable to Eval Injection Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that allows attackers to execute arbitrary Python code by manipulating the field_type parameter passed to eval(). Attackers can influence the field_…
VulnCve 2026 35002
critical System graph security Trivy conf 1.00 CVE-2026-35002: agno 1.5.6 — advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock
Agno is vulnerable to Eval Injection Agno versions prior to 2.3.24 contain an arbitrary code execution vulnerability in the model execution component that allows attackers to execute arbitrary Python code by manipulating the field_type parameter passed to eval(). Attackers can influence the field_…
VulnCve 2026 35002
critical System graph security Trivy conf 1.00 CVE-2026-41242: protobufjs 7.5.4 — generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml
protobufjs: protobufjs: Arbitrary code execution via injected protobuf definition type fields protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which will …
VulnCve 2026 41242
critical System graph security Trivy conf 1.00 CVE-2026-4810: google-adk 1.26.0 — generative_ui_agents/ai-financial-coach-agent/agent/uv.lock
Google Agent Development Kit (ADK) has a Code Injection and Missing Authentication vulnerability A Code Injection and Missing Authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.0a1) through 1.28.1 (and 2.0.0a2) on Python (OSS), Cloud Run, and GKE allows an u…
VulnCve 2026 4810
critical System graph security Trivy conf 1.00 CVE-2026-4810: google-adk 1.9.0 — always_on_agents/release_radar_agent/requirements.txt
Google Agent Development Kit (ADK) has a Code Injection and Missing Authentication vulnerability A Code Injection and Missing Authentication vulnerability in Google Agent Development Kit (ADK) versions 1.7.0 (and 2.0.0a1) through 1.28.1 (and 2.0.0a2) on Python (OSS), Cloud Run, and GKE allows an u…
VulnCve 2026 4810
critical System graph security Trivy conf 1.00 CVE-2026-53512: better-auth 1.2.8 — advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth token endpoints whose refresh_token grant auth…
VulnCve 2026 53512
critical System graph security Trivy conf 1.00 CVE-2026-59873: tar 7.5.13 — generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml
tar: node-tar: Denial of Service via crafted gzip bomb node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, a…
VulnCve 2026 59873
critical System graph security Trivy conf 1.00 GHSA-xg6x-h9c9-2m83: better-auth 1.2.8 — advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml
Better Auth Has Two-Factor Authentication Bypass via Premature Session Caching (session.cookieCache) ### Summary Under certain configurations, sessions may be considered valid before two-factor authentication (2FA) is fully completed. This can allow access to authenticated routes without verifyin…
VulnGhsa xg6x h9c9 2m83
high System graph security Trivy conf 1.00 CVE-2023-4863: Pillow 10.0.0 — starter_ai_agents/ai_medical_imaging_agent/requirements.txt
libwebp: Heap buffer overflow in WebP Codec Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical) Package: Pillow Installed: 10.0…
VulnCve 2023 4863
high System graph security Trivy conf 1.00 CVE-2024-28219: Pillow 10.0.0 — starter_ai_agents/ai_medical_imaging_agent/requirements.txt
python-pillow: buffer overflow in _imagingcms.c In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy. Package: Pillow Installed: 10.0.0 Fixed in: 10.3.0 Severity: HIGH Fix: Upgrade Pillow to 10.3.0
VulnCve 2024 28219
high System graph security Trivy conf 1.00 CVE-2024-8966: gradio 5.9.1 — advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt
Gradio DOS in multipart boundry while uploading the file A vulnerability in the file upload process of gradio-app/gradio version @gradio/[email protected] allows for a Denial of Service (DoS) attack. An attacker can append a large number of characters to the end of a multipart boundary, causing the sys…
VulnCve 2024 8966
high System graph security Trivy conf 1.00 CVE-2025-12758: validator 13.15.15 — generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml
Validator is Vulnerable to Incomplete Filtering of One or More Instances of Special Elements Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Special Elements in the isLength() function that does not take into account Unicode vari…
VulnCve 2025 12758
high System graph security Trivy conf 1.00 CVE-2025-12816: node-forge 1.3.1 — generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml
node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yi…
VulnCve 2025 12816
high System graph security Trivy conf 1.00 CVE-2025-4565: protobuf 5.29.3 — advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
python-protobuf: Unbounded recursion in Python Protobuf Any project that uses Protobuf Pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of SGROUP tags can be corrupted by exceeding the Python recursion l…
VulnCve 2025 4565
high System graph security Trivy conf 1.00 CVE-2025-4565: protobuf 6.30.2 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
python-protobuf: Unbounded recursion in Python Protobuf Any project that uses Protobuf Pure-Python backend to parse untrusted Protocol Buffers data containing an arbitrary number of recursive groups, recursive messages or a series of SGROUP tags can be corrupted by exceeding the Python recursion l…
VulnCve 2025 4565
high System graph security Trivy conf 1.00 CVE-2025-47273: setuptools 75.8.0 — advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
setuptools: Path Traversal Vulnerability in setuptools PackageIndex setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be…
VulnCve 2025 47273
high System graph security Trivy conf 1.00 CVE-2025-47287: tornado 6.4.2 — advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
tornado: Tornado Multipart Form-Data Denial of Service Tornado is a Python web framework and asynchronous networking library. When Tornado's ``multipart/form-data`` parser encounters certain errors, it logs a warning but continues trying to parse the remainder of the data. This allows remote attac…
VulnCve 2025 47287
high System graph security Trivy conf 1.00 CVE-2025-48379: pillow 11.2.1 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
python-pillow: pillow: Pillow DDS Heap Buffer Overflow Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a sufficiently large (>64k encoded with default settings) image in the DDS format due to writing into a buffer without checki…
VulnCve 2025 48379
high System graph security Trivy conf 1.00 CVE-2025-48379: pillow 11.2.1 — advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock
python-pillow: pillow: Pillow DDS Heap Buffer Overflow Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a sufficiently large (>64k encoded with default settings) image in the DDS format due to writing into a buffer without checki…
VulnCve 2025 48379
high System graph security Trivy conf 1.00 CVE-2025-58754: axios 1.11.0 — advanced_llm_apps/thinkpath_chatbot_app/package-lock.json
axios: Axios DoS via lack of data size check Axios is a promise based HTTP client for the browser and Node.js. When Axios starting in version 0.28.0 and prior to versions 0.30.2 and 1.12.0 runs on Node.js and is given a URL with the `data:` scheme, it does not perform HTTP. Instead, its Node http …
VulnCve 2025 58754
high System graph security Trivy conf 1.00 CVE-2025-59288: playwright 1.55.0 — generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml
playwright: Playwright Spoofing Vulnerability Improper verification of cryptographic signature in Github: Playwright allows an unauthorized attacker to perform spoofing over an adjacent network. Package: playwright Installed: 1.55.0 Fixed in: 1.55.1 Severity: HIGH Fix: Upgrade playwright to 1.55.1
VulnCve 2025 59288
high System graph security Trivy conf 1.00 CVE-2025-61928: better-auth 1.2.8 — advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml
Better Auth: Unauthenticated API key creation through api-key plugin Better Auth is an authentication and authorization library for TypeScript. In versions prior to 1.3.26, unauthenticated attackers can create or modify API keys for any user by passing that user's id in the request body to the `ap…
VulnCve 2025 61928
high System graph security Trivy conf 1.00 CVE-2025-62727: starlette 0.46.2 — advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock
starlette: Starlette DoS via Range header merging Starlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthenticated attacker can send a crafted HTTP Range header that triggers quadratic-time processing in Starlette's FileResponse Range p…
VulnCve 2025 62727
high System graph security Trivy conf 1.00 CVE-2025-62727: starlette 0.46.2 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
starlette: Starlette DoS via Range header merging Starlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthenticated attacker can send a crafted HTTP Range header that triggers quadratic-time processing in Starlette's FileResponse Range p…
VulnCve 2025 62727
high System graph security Trivy conf 1.00 CVE-2025-62727: starlette 0.46.2 — generative_ui_agents/ai-deep-research-agent/agent/uv.lock
starlette: Starlette DoS via Range header merging Starlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthenticated attacker can send a crafted HTTP Range header that triggers quadratic-time processing in Starlette's FileResponse Range p…
VulnCve 2025 62727
high System graph security Trivy conf 1.00 CVE-2025-62727: starlette 0.46.2 — generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock
starlette: Starlette DoS via Range header merging Starlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthenticated attacker can send a crafted HTTP Range header that triggers quadratic-time processing in Starlette's FileResponse Range p…
VulnCve 2025 62727
high System graph security Trivy conf 1.00 CVE-2025-65106: langchain-core 0.3.25 — rag_tutorials/rag_agent_cohere/requirements.txt
langchain-core: LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates LangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to 1.0.6, a template injection vulnerability exists in LangChain's prompt template…
VulnCve 2025 65106
high System graph security Trivy conf 1.00 CVE-2025-65106: langchain-core 0.3.28 — rag_tutorials/corrective_rag/requirements.txt
langchain-core: LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates LangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to 1.0.6, a template injection vulnerability exists in LangChain's prompt template…
VulnCve 2025 65106
high System graph security Trivy conf 1.00 CVE-2025-65106: langchain-core 0.3.28 — rag_tutorials/rag_database_routing/requirements.txt
langchain-core: LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates LangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to 1.0.6, a template injection vulnerability exists in LangChain's prompt template…
VulnCve 2025 65106
high System graph security Trivy conf 1.00 CVE-2025-65106: langchain-core 0.3.49 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
langchain-core: LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates LangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to 1.0.6, a template injection vulnerability exists in LangChain's prompt template…
VulnCve 2025 65106
high System graph security Trivy conf 1.00 CVE-2025-65106: langchain-core 0.3.65 — advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock
langchain-core: LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates LangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to 1.0.6, a template injection vulnerability exists in LangChain's prompt template…
VulnCve 2025 65106
high System graph security Trivy conf 1.00 CVE-2025-65945: jws 4.0.0 — generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml
node-jws: auth0/node-jws: Improper signature verification in HS256 algorithm auth0/node-jws is a JSON Web Signature implementation for Node.js. In versions 3.2.2 and earlier and version 4.0.0, auth0/node-jws has an improper signature verification vulnerability when using the HS256 algorithm under …
VulnCve 2025 65945
high System graph security Trivy conf 1.00 CVE-2025-66031: node-forge 1.3.1 — generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml
node-forge: node-forge ASN.1 Unbounded Recursion Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled Recursion vulnerability in node-forge versions 1.3.1 and below enables remote, unauthenticated attackers to craft deep ASN.1 struc…
VulnCve 2025 66031
high System graph security Trivy conf 1.00 CVE-2025-66418: urllib3 2.3.0 — advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimi…
VulnCve 2025 66418
high System graph security Trivy conf 1.00 CVE-2025-66418: urllib3 2.4.0 — advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock
urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimi…
VulnCve 2025 66418
high System graph security Trivy conf 1.00 CVE-2025-66418: urllib3 2.4.0 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimi…
VulnCve 2025 66418
high System graph security Trivy conf 1.00 CVE-2025-66418: urllib3 2.4.0 — advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock
urllib3: urllib3: Unbounded decompression chain leads to resource exhaustion urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.24 and prior to 2.6.0, the number of links in the decompression chain was unbounded allowing a malicious server to insert a virtually unlimi…
VulnCve 2025 66418
high System graph security Trivy conf 1.00 CVE-2025-66471: urllib3 2.3.0 — advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
urllib3: urllib3 Streaming API improperly handles highly compressed data urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handlin…
VulnCve 2025 66471
high System graph security Trivy conf 1.00 CVE-2025-66471: urllib3 2.4.0 — advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock
urllib3: urllib3 Streaming API improperly handles highly compressed data urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handlin…
VulnCve 2025 66471
high System graph security Trivy conf 1.00 CVE-2025-66471: urllib3 2.4.0 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
urllib3: urllib3 Streaming API improperly handles highly compressed data urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handlin…
VulnCve 2025 66471
high System graph security Trivy conf 1.00 CVE-2025-66471: urllib3 2.4.0 — advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock
urllib3: urllib3 Streaming API improperly handles highly compressed data urllib3 is a user-friendly HTTP client library for Python. Starting in version 1.0 and prior to 2.6.0, the Streaming API improperly handles highly compressed data. urllib3's streaming API is designed for the efficient handlin…
VulnCve 2025 66471
high System graph security Trivy conf 1.00 CVE-2025-67221: orjson 3.10.16 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
orjson: orjson: Denial of Service due to unbounded recursion with deeply nested JSON documents The orjson.dumps function in orjson thru 3.11.4 does not limit recursion for deeply nested JSON documents. Package: orjson Installed: 3.10.16 Fixed in: 3.11.6 Severity: HIGH Fix: Upgrade orjson to 3.11.6
VulnCve 2025 67221
high System graph security Trivy conf 1.00 CVE-2025-67221: orjson 3.10.18 — advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock
orjson: orjson: Denial of Service due to unbounded recursion with deeply nested JSON documents The orjson.dumps function in orjson thru 3.11.4 does not limit recursion for deeply nested JSON documents. Package: orjson Installed: 3.10.18 Fixed in: 3.11.6 Severity: HIGH Fix: Upgrade orjson to 3.11.6
VulnCve 2025 67221
high System graph security Trivy conf 1.00 CVE-2025-67221: orjson 3.11.5 — generative_ui_agents/ai-deep-research-agent/agent/uv.lock
orjson: orjson: Denial of Service due to unbounded recursion with deeply nested JSON documents The orjson.dumps function in orjson thru 3.11.4 does not limit recursion for deeply nested JSON documents. Package: orjson Installed: 3.11.5 Fixed in: 3.11.6 Severity: HIGH Fix: Upgrade orjson to 3.11.6
VulnCve 2025 67221
high System graph security Trivy conf 1.00 CVE-2025-67221: orjson 3.11.5 — generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock
orjson: orjson: Denial of Service due to unbounded recursion with deeply nested JSON documents The orjson.dumps function in orjson thru 3.11.4 does not limit recursion for deeply nested JSON documents. Package: orjson Installed: 3.11.5 Fixed in: 3.11.6 Severity: HIGH Fix: Upgrade orjson to 3.11.6
VulnCve 2025 67221
high System graph security Trivy conf 1.00 CVE-2025-67725: tornado 6.4.2 — advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
tornado: Tornado Quadratic DoS via Repeated Header Coalescing Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously crafted HTTP request can block the server's event loop for an extended period, caused by the HTTPHeaders.add method…
VulnCve 2025 67725
high System graph security Trivy conf 1.00 CVE-2025-67726: tornado 6.4.2 — advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
tornado: Tornado Quadratic DoS via Crafted Multipart Parameters Tornado is a Python web framework and asynchronous networking library. Versions 6.5.2 and below use an inefficient algorithm when parsing parameters for HTTP header values, potentially causing a DoS. The _parseparam function in httput…
VulnCve 2025 67726
high System graph security Trivy conf 1.00 CVE-2025-69223: aiohttp 3.11.18 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
aiohttp: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a comp…
VulnCve 2025 69223
high System graph security Trivy conf 1.00 CVE-2025-69223: aiohttp 3.12.12 — advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock
aiohttp: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a comp…
VulnCve 2025 69223
high System graph security Trivy conf 1.00 CVE-2025-69223: aiohttp 3.12.6 — advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock
aiohttp: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a comp…
VulnCve 2025 69223
high System graph security Trivy conf 1.00 CVE-2025-6984: langchain-community 0.3.12 — rag_tutorials/corrective_rag/requirements.txt
langchain-community: Langchain-community insecure XML parsing The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etre…
VulnCve 2025 6984
high System graph security Trivy conf 1.00 CVE-2025-6984: langchain-community 0.3.12 — rag_tutorials/rag_agent_cohere/requirements.txt
langchain-community: Langchain-community insecure XML parsing The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etre…
VulnCve 2025 6984
high System graph security Trivy conf 1.00 CVE-2025-6984: langchain-community 0.3.12 — rag_tutorials/rag_database_routing/requirements.txt
langchain-community: Langchain-community insecure XML parsing The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etre…
VulnCve 2025 6984
high System graph security Trivy conf 1.00 CVE-2025-6984: langchain-community 0.3.13 — rag_tutorials/deepseek_local_rag_agent/requirements.txt
langchain-community: Langchain-community insecure XML parsing The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etre…
VulnCve 2025 6984
high System graph security Trivy conf 1.00 CVE-2025-6984: langchain-community 0.3.13 — rag_tutorials/gemini_agentic_rag/requirements.txt
langchain-community: Langchain-community insecure XML parsing The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etre…
VulnCve 2025 6984
high System graph security Trivy conf 1.00 CVE-2025-6984: langchain-community 0.3.25 — advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock
langchain-community: Langchain-community insecure XML parsing The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etre…
VulnCve 2025 6984
high System graph security Trivy conf 1.00 CVE-2025-6985: langchain-text-splitters 0.3.7 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
langchain-text-splitters: XXE Vulnerability in langchain-text-splitters The HTMLSectionSplitter class in langchain-text-splitters version 0.3.8 is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing. This vulnerability arises because the class allows the use of arbitrary XSL…
VulnCve 2025 6985
high System graph security Trivy conf 1.00 CVE-2025-6985: langchain-text-splitters 0.3.8 — advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock
langchain-text-splitters: XXE Vulnerability in langchain-text-splitters The HTMLSectionSplitter class in langchain-text-splitters version 0.3.8 is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing. This vulnerability arises because the class allows the use of arbitrary XSL…
VulnCve 2025 6985
high System graph security Trivy conf 1.00 CVE-2025-7707: llama-index 0.12.33 — rag_tutorials/agentic_rag_math_agent/requirements.txt
llama-index: World-Writable Cache Directory Vulnerability in llama_index The llama_index library version 0.12.33 sets the NLTK data directory to a subdirectory of the codebase by default, which is world-writable in multi-user environments. This configuration allows local users to overwrite, delete…
VulnCve 2025 7707
high System graph security Trivy conf 1.00 CVE-2026-0846: nltk 3.9.1 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
nltk: NLTK: Arbitrary file read via improper path validation in `filestring()` function A vulnerability in the `filestring()` function of the `nltk.util` module in nltk version 3.9.2 allows arbitrary file read due to improper validation of input paths. The function directly opens files specified b…
VulnCve 2026 0846
high System graph security Trivy conf 1.00 CVE-2026-0847: nltk 3.9.1 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
nltk: NLTK: Arbitrary file read via path traversal vulnerability A vulnerability in NLTK versions up to and including 3.9.2 allows arbitrary file read via path traversal in multiple CorpusReader classes, including WordListCorpusReader, TaggedCorpusReader, and BracketParseCorpusReader. These classe…
VulnCve 2026 0847
high System graph security Trivy conf 1.00 CVE-2026-0994: protobuf 5.29.3 — advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
python: protobuf: Protobuf: Denial of Service due to recursion depth bypass A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing rec…
VulnCve 2026 0994
high System graph security Trivy conf 1.00 CVE-2026-0994: protobuf 6.30.2 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
python: protobuf: Protobuf: Denial of Service due to recursion depth bypass A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing rec…
VulnCve 2026 0994
high System graph security Trivy conf 1.00 CVE-2026-0994: protobuf 6.31.1 — advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock
python: protobuf: Protobuf: Denial of Service due to recursion depth bypass A denial-of-service (DoS) vulnerability exists in google.protobuf.json_format.ParseDict() in Python, where the max_recursion_depth limit can be bypassed when parsing nested google.protobuf.Any messages. Due to missing rec…
VulnCve 2026 0994
high System graph security Trivy conf 1.00 CVE-2026-10105: agno 1.4.2 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
agno contains a SQL injection vulnerability agno 2.6.5 contains a SQL injection vulnerability in the ClickHouse vector database backend that allows attackers to inject arbitrary SQL expressions by supplying malicious metadata keys and values to the delete_by_metadata() method. Attackers can exploi…
VulnCve 2026 10105
high System graph security Trivy conf 1.00 CVE-2026-10105: agno 1.5.6 — advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock
agno contains a SQL injection vulnerability agno 2.6.5 contains a SQL injection vulnerability in the ClickHouse vector database backend that allows attackers to inject arbitrary SQL expressions by supplying malicious metadata keys and values to the delete_by_metadata() method. Attackers can exploi…
VulnCve 2026 10105
high System graph security Trivy conf 1.00 CVE-2026-12143: form-data 4.0.4 — advanced_llm_apps/thinkpath_chatbot_app/package-lock.json
form-data: form-data: Form field override via CRLF injection form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header with…
VulnCve 2026 12143
high System graph security Trivy conf 1.00 CVE-2026-12143: form-data 4.0.4 — generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml
form-data: form-data: Form field override via CRLF injection form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header with…
VulnCve 2026 12143
high System graph security Trivy conf 1.00 CVE-2026-12143: form-data 4.0.5 — advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json
form-data: form-data: Form field override via CRLF injection form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header with…
VulnCve 2026 12143
high System graph security Trivy conf 1.00 CVE-2026-12143: form-data 4.0.5 — generative_ui_agents/ai-deep-research-agent/package-lock.json
form-data: form-data: Form field override via CRLF injection form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header with…
VulnCve 2026 12143
high System graph security Trivy conf 1.00 CVE-2026-12143: form-data 4.0.5 — generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml
form-data: form-data: Form field override via CRLF injection form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argument to `FormData#append` and the `filename` option are concatenated verbatim into the `Content-Disposition` header with…
VulnCve 2026 12143
high System graph security Trivy conf 1.00 CVE-2026-13149: brace-expansion 5.0.5 — generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml
brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a…
VulnCve 2026 13149
high System graph security Trivy conf 1.00 CVE-2026-13676: fast-uri 3.1.0 — advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json
fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, …
VulnCve 2026 13676
high System graph security Trivy conf 1.00 CVE-2026-13676: fast-uri 3.1.0 — generative_ui_agents/ai-deep-research-agent/package-lock.json
fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, …
VulnCve 2026 13676
high System graph security Trivy conf 1.00 CVE-2026-13676: fast-uri 3.1.0 — generative_ui_agents/ai-financial-coach-agent/package-lock.json
fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, …
VulnCve 2026 13676
high System graph security Trivy conf 1.00 CVE-2026-13676: fast-uri 3.1.0 — generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml
fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, …
VulnCve 2026 13676
high System graph security Trivy conf 1.00 CVE-2026-13676: fast-uri 3.1.0 — generative_ui_agents/generative-ui-starter-project/package-lock.json
fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, …
VulnCve 2026 13676
high System graph security Trivy conf 1.00 CVE-2026-13676: fast-uri 3.1.0 — generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json
fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, …
VulnCve 2026 13676
high System graph security Trivy conf 1.00 CVE-2026-13676: fast-uri 3.1.0 — generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml
fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, …
VulnCve 2026 13676
high System graph security Trivy conf 1.00 CVE-2026-13676: fast-uri 3.1.2 — generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml
fast-uri: fast-uri: Security policy bypass due to improper Unicode hostname canonicalization fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, …
VulnCve 2026 13676
high System graph security Trivy conf 1.00 CVE-2026-16221: fast-uri 3.1.0 — advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json
Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x ... Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL pa…
VulnCve 2026 16221
high System graph security Trivy conf 1.00 CVE-2026-16221: fast-uri 3.1.0 — generative_ui_agents/ai-deep-research-agent/package-lock.json
Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x ... Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL pa…
VulnCve 2026 16221
high System graph security Trivy conf 1.00 CVE-2026-16221: fast-uri 3.1.0 — generative_ui_agents/ai-financial-coach-agent/package-lock.json
Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x ... Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL pa…
VulnCve 2026 16221
high System graph security Trivy conf 1.00 CVE-2026-16221: fast-uri 3.1.0 — generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml
Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x ... Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL pa…
VulnCve 2026 16221
high System graph security Trivy conf 1.00 CVE-2026-16221: fast-uri 3.1.0 — generative_ui_agents/generative-ui-starter-project/package-lock.json
Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x ... Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL pa…
VulnCve 2026 16221
high System graph security Trivy conf 1.00 CVE-2026-16221: fast-uri 3.1.0 — generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json
Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x ... Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL pa…
VulnCve 2026 16221
high System graph security Trivy conf 1.00 CVE-2026-16221: fast-uri 3.1.0 — generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml
Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x ... Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL pa…
VulnCve 2026 16221
high System graph security Trivy conf 1.00 CVE-2026-16221: fast-uri 3.1.2 — generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml
Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x ... Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL pa…
VulnCve 2026 16221
high System graph security Trivy conf 1.00 CVE-2026-21441: urllib3 2.3.0 — advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loadin…
VulnCve 2026 21441
high System graph security Trivy conf 1.00 CVE-2026-21441: urllib3 2.4.0 — advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock
urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loadin…
VulnCve 2026 21441
high System graph security Trivy conf 1.00 CVE-2026-21441: urllib3 2.4.0 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loadin…
VulnCve 2026 21441
high System graph security Trivy conf 1.00 CVE-2026-21441: urllib3 2.4.0 — advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock
urllib3: urllib3 vulnerable to decompression-bomb safeguard bypass when following HTTP redirects (streaming API) urllib3 is an HTTP client library for Python. urllib3's streaming API is designed for the efficient handling of large HTTP responses by reading the content in chunks, rather than loadin…
VulnCve 2026 21441
high System graph security Trivy conf 1.00 CVE-2026-22817: hono 4.11.3 — generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json
Hono JWT Middleware's JWT Algorithm Confusion via Unsafe Default (HS256) Allows Token Forgery and Auth Bypass Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verification middleware allowed the JWT header…
VulnCve 2026 22817
high System graph security Trivy conf 1.00 CVE-2026-22818: hono 4.11.3 — generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json
Hono JWK Auth Middleware has JWT algorithm confusion when JWK lacks "alg" (untrusted header.alg fallback) Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.11.4, there is a flaw in Hono’s JWK/JWKS JWT verification middleware allowed the algorithm spec…
VulnCve 2026 22818
high System graph security Trivy conf 1.00 CVE-2026-23490: pyasn1 0.6.1 — advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnera…
VulnCve 2026 23490
high System graph security Trivy conf 1.00 CVE-2026-23490: pyasn1 0.6.1 — advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock
pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnera…
VulnCve 2026 23490
high System graph security Trivy conf 1.00 CVE-2026-23490: pyasn1 0.6.1 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
pyasn1: pyasn1: Denial of Service due to memory exhaustion from malformed RELATIVE-OID pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.2, a Denial-of-Service issue has been found that leads to memory exhaustion from malformed RELATIVE-OID with excessive continuation octets. This vulnera…
VulnCve 2026 23490
high System graph security Trivy conf 1.00 CVE-2026-24049: wheel 0.45.1 — advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
wheel: wheel: Privilege Escalation or Arbitrary Code Execution via malicious wheel file unpacking wheel is a command line tool for manipulating Python wheel files, as defined in PEP 427. In versions 0.40.0 through 0.46.1, the unpack function is vulnerable to file permission modification through mi…
VulnCve 2026 24049
high System graph security Trivy conf 1.00 CVE-2026-24486: python-multipart 0.0.20 — advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
python-multipart: Python-Multipart: Arbitrary file write via path traversal vulnerability Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=…
VulnCve 2026 24486
high System graph security Trivy conf 1.00 CVE-2026-24486: python-multipart 0.0.20 — advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock
python-multipart: Python-Multipart: Arbitrary file write via path traversal vulnerability Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=…
VulnCve 2026 24486
high System graph security Trivy conf 1.00 CVE-2026-24486: python-multipart 0.0.20 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
python-multipart: Python-Multipart: Arbitrary file write via path traversal vulnerability Python-Multipart is a streaming multipart parser for Python. Prior to version 0.0.22, a Path Traversal vulnerability exists when using non-default configuration options `UPLOAD_DIR` and `UPLOAD_KEEP_FILENAME=…
VulnCve 2026 24486
high System graph security Trivy conf 1.00 CVE-2026-25087: pyarrow 19.0.1 — advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
apache-arrow: Apache Arrow C++: Denial of Service via Use After Free vulnerability when reading IPC files Use After Free vulnerability in Apache Arrow C++. This issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It can be triggered when reading an Arrow IPC file (but not an IPC stream) wi…
VulnCve 2026 25087
high System graph security Trivy conf 1.00 CVE-2026-25128: fast-xml-parser 5.2.5 — generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml
fast-xml-parser: fast-xml-parser has RangeError DoS Numeric Entities Bug fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 5.0.9 through 5.3.3, a RangeError vulnerability exists in the numeri…
VulnCve 2026 25128
high System graph security Trivy conf 1.00 CVE-2026-25536: @modelcontextprotocol/sdk 1.25.2 — generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json
@modelcontextprotocol/sdk: @modelcontextprotocol/sdk cross-client data leak MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to 1.25.3, cross-client response data leak when a single McpServer/Server and transport instance is reus…
VulnCve 2026 25536
high System graph security Trivy conf 1.00 CVE-2026-25536: @modelcontextprotocol/sdk 1.25.2 — generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml
@modelcontextprotocol/sdk: @modelcontextprotocol/sdk cross-client data leak MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to 1.25.3, cross-client response data leak when a single McpServer/Server and transport instance is reus…
VulnCve 2026 25536
high System graph security Trivy conf 1.00 CVE-2026-25536: @modelcontextprotocol/sdk 1.25.3 — generative_ui_agents/ai-deep-research-agent/package-lock.json
@modelcontextprotocol/sdk: @modelcontextprotocol/sdk cross-client data leak MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. From version 1.10.0 to 1.25.3, cross-client response data leak when a single McpServer/Server and transport instance is reus…
VulnCve 2026 25536
high System graph security Trivy conf 1.00 CVE-2026-25639: axios 1.11.0 — advanced_llm_apps/thinkpath_chatbot_app/package-lock.json
axios: Axios affected by Denial of Service via __proto__ Key in mergeConfig Axios is a promise based HTTP client for the browser and Node.js. Prior to versions 0.30.3 and 1.13.5, the mergeConfig function in axios crashes with a TypeError when processing configuration objects containing __proto__ a…
VulnCve 2026 25639
high System graph security Trivy conf 1.00 CVE-2026-25990: Pillow 10.4.0 — starter_ai_agents/ai_data_visualisation_agent/requirements.txt
pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1. Package: Pillow Installed: 10.4.0 Fixed …
VulnCve 2026 25990
high System graph security Trivy conf 1.00 CVE-2026-25990: Pillow 11.0.0 — advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt
pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1. Package: Pillow Installed: 11.0.0 Fixed …
VulnCve 2026 25990
high System graph security Trivy conf 1.00 CVE-2026-25990: pillow 11.1.0 — advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1. Package: pillow Installed: 11.1.0 Fixed …
VulnCve 2026 25990
high System graph security Trivy conf 1.00 CVE-2026-25990: pillow 11.1.0 — starter_ai_agents/ai_breakup_recovery_agent/requirements.txt
pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1. Package: pillow Installed: 11.1.0 Fixed …
VulnCve 2026 25990
high System graph security Trivy conf 1.00 CVE-2026-25990: pillow 11.2.1 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1. Package: pillow Installed: 11.2.1 Fixed …
VulnCve 2026 25990
high System graph security Trivy conf 1.00 CVE-2026-25990: pillow 11.2.1 — advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock
pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1. Package: pillow Installed: 11.2.1 Fixed …
VulnCve 2026 25990
high System graph security Trivy conf 1.00 CVE-2026-26007: cryptography 45.0.4 — advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock
cryptography: cryptography Subgroup Attack Due to Missing Subgroup Validation for SECT Curves cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 46.0.5, the public_key_from_numbers (or EllipticCurvePublicNumbers.public_key()), EllipticC…
VulnCve 2026 26007
high System graph security Trivy conf 1.00 CVE-2026-26278: fast-xml-parser 5.2.5 — generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml
fast-xml-parser: fast-xml-parser: Denial of Service via unlimited XML entity expansion fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, the XML parser can be forced to d…
VulnCve 2026 26278
high System graph security Trivy conf 1.00 CVE-2026-27459: pyopenssl 25.3.0 — generative_ui_agents/ai-financial-coach-agent/agent/uv.lock
pyOpenSSL: DTLS cookie callback buffer overflow pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 22.0.0 and prior to version 26.0.0, if a user provided callback to `set_cookie_generate_callback` returned a cookie value greater than 256 bytes, pyOpenSSL would overflow a…
VulnCve 2026 27459
high System graph security Trivy conf 1.00 CVE-2026-28414: gradio 5.9.1 — advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt
Gradio is Vulnerable to Absolute Path Traversal on Windows with Python 3.13+ Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.7, Gradio apps running on Window with Python 3.13+ are vulnerable to an absolute path traversal issue that enables unauthenticated…
VulnCve 2026 28414
high System graph security Trivy conf 1.00 CVE-2026-28416: gradio 5.9.1 — advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt
Gradio: Gradio: Server-Side Request Forgery allows access to internal services via malicious Space loading Gradio is an open-source Python package designed for quick prototyping. Prior to version 6.6.0, a Server-Side Request Forgery (SSRF) vulnerability in Gradio allows an attacker to make arbitra…
VulnCve 2026 28416
high System graph security Trivy conf 1.00 CVE-2026-29045: hono 4.11.3 — generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json
Hono vulnerable to arbitrary file access via serveStatic vulnerability Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using serveStatic together with route-based middleware protections (e.g. app.use('/admin/*', ...)), inconsiste…
VulnCve 2026 29045
high System graph security Trivy conf 1.00 CVE-2026-29045: hono 4.11.5 — generative_ui_agents/ai-deep-research-agent/package-lock.json
Hono vulnerable to arbitrary file access via serveStatic vulnerability Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using serveStatic together with route-based middleware protections (e.g. app.use('/admin/*', ...)), inconsiste…
VulnCve 2026 29045
high System graph security Trivy conf 1.00 CVE-2026-29045: hono 4.11.7 — advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json
Hono vulnerable to arbitrary file access via serveStatic vulnerability Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.12.4, when using serveStatic together with route-based middleware protections (e.g. app.use('/admin/*', ...)), inconsiste…
VulnCve 2026 29045
high System graph security Trivy conf 1.00 CVE-2026-29087: @hono/node-server 1.19.8 — generative_ui_agents/mcp-apps-generative-ui-showcase/mcp-server/package-lock.json
@hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware @hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server's static file serving together with route-based middleware p…
VulnCve 2026 29087
high System graph security Trivy conf 1.00 CVE-2026-29087: @hono/node-server 1.19.8 — generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml
@hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware @hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server's static file serving together with route-based middleware p…
VulnCve 2026 29087
high System graph security Trivy conf 1.00 CVE-2026-29087: @hono/node-server 1.19.9 — advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json
@hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware @hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server's static file serving together with route-based middleware p…
VulnCve 2026 29087
high System graph security Trivy conf 1.00 CVE-2026-29087: @hono/node-server 1.19.9 — generative_ui_agents/ai-deep-research-agent/package-lock.json
@hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware @hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server's static file serving together with route-based middleware p…
VulnCve 2026 29087
high System graph security Trivy conf 1.00 CVE-2026-30827: express-rate-limit 8.2.1 — advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json
express-rate-limit: express-rate-limit: Denial of Service for IPv4 clients due to incorrect IPv6 subnet masking express-rate-limit is a basic rate-limiting middleware for Express. In versions starting from 8.0.0 and prior to versions 8.0.2, 8.1.1, 8.2.2, and 8.3.0, the default keyGenerator in expr…
VulnCve 2026 30827
high System graph security Trivy conf 1.00 CVE-2026-30922: pyasn1 0.6.1 — advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An at…
VulnCve 2026 30922
high System graph security Trivy conf 1.00 CVE-2026-30922: pyasn1 0.6.1 — advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock
pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An at…
VulnCve 2026 30922
high System graph security Trivy conf 1.00 CVE-2026-30922: pyasn1 0.6.1 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An at…
VulnCve 2026 30922
high System graph security Trivy conf 1.00 CVE-2026-30922: pyasn1 0.6.2 — generative_ui_agents/ai-deep-research-agent/agent/uv.lock
pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An at…
VulnCve 2026 30922
high System graph security Trivy conf 1.00 CVE-2026-30922: pyasn1 0.6.2 — generative_ui_agents/ai-financial-coach-agent/agent/uv.lock
pyasn1: pyasn1 Vulnerable to Denial of Service via Unbounded Recursion pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.3, the `pyasn1` library is vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding ASN.1 data with deeply nested structures. An at…
VulnCve 2026 30922
high System graph security Trivy conf 1.00 CVE-2026-31240: mem0ai 0.1.102 — advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock
mem0 server lacks authentication and authorization controls for its memory management API endpoints The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are expo…
VulnCve 2026 31240
high System graph security Trivy conf 1.00 CVE-2026-31240: mem0ai 0.1.29 — advanced_ai_agents/single_agent_apps/ai_customer_support_agent/requirements.txt
mem0 server lacks authentication and authorization controls for its memory management API endpoints The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are expo…
VulnCve 2026 31240
high System graph security Trivy conf 1.00 CVE-2026-31240: mem0ai 0.1.29 — advanced_llm_apps/llm_apps_with_memory_tutorials/ai_travel_agent_memory/requirements.txt
mem0 server lacks authentication and authorization controls for its memory management API endpoints The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are expo…
VulnCve 2026 31240
high System graph security Trivy conf 1.00 CVE-2026-31240: mem0ai 0.1.29 — advanced_llm_apps/llm_apps_with_memory_tutorials/llm_app_personalized_memory/requirements.txt
mem0 server lacks authentication and authorization controls for its memory management API endpoints The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are expo…
VulnCve 2026 31240
high System graph security Trivy conf 1.00 CVE-2026-31240: mem0ai 0.1.29 — advanced_llm_apps/llm_apps_with_memory_tutorials/local_chatgpt_with_memory/requirements.txt
mem0 server lacks authentication and authorization controls for its memory management API endpoints The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are expo…
VulnCve 2026 31240
high System graph security Trivy conf 1.00 CVE-2026-31240: mem0ai 0.1.29 — advanced_llm_apps/llm_apps_with_memory_tutorials/multi_llm_memory/requirements.txt
mem0 server lacks authentication and authorization controls for its memory management API endpoints The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are expo…
VulnCve 2026 31240
high System graph security Trivy conf 1.00 CVE-2026-31240: mem0ai 0.1.93 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
mem0 server lacks authentication and authorization controls for its memory management API endpoints The mem0 1.0.0 server lacks authentication and authorization controls for its memory management API endpoints. Critical functions such as updating memory records (PUT /memories/{memory_id}) are expo…
VulnCve 2026 31240
high System graph security Trivy conf 1.00 CVE-2026-31958: tornado 6.4.2 — advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
tornado-python: Tornado: Denial of Service via large multipart bodies Tornado is a Python web framework and asynchronous networking library. In versions of Tornado prior to 6.5.5, the only limit on the number of parts in multipart/form-data is the max_body_size setting (default 100MB). Since parsi…
VulnCve 2026 31958
high System graph security Trivy conf 1.00 CVE-2026-32597: pyjwt 2.11.0 — generative_ui_agents/ai-financial-coach-agent/agent/uv.lock
pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation) PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing exte…
VulnCve 2026 32597
high System graph security Trivy conf 1.00 CVE-2026-32597: PyJWT 2.9.0 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
pyjwt: PyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation) PyJWT is a JSON Web Token implementation in Python. Prior to 2.12.0, PyJWT does not validate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. When a JWS token contains a crit array listing exte…
VulnCve 2026 32597
high System graph security Trivy conf 1.00 CVE-2026-32763: kysely 0.28.2 — advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml
SQL Injection via unsanitized JSON path keys when ignoring/silencing compilation errors or using `Kysely<any>`. Kysely is a type-safe TypeScript SQL query builder. Versions up to and including 0.28.11 has a SQL injection vulnerability in JSON path compilation for MySQL and SQLite dialects. The `vi…
VulnCve 2026 32763
high System graph security Trivy conf 1.00 CVE-2026-33036: fast-xml-parser 5.2.5 — generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml
fast-xml-parser: fast-xml-parser: Denial of Service via XML entity expansion bypass fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Versions 4.0.0-beta.3 through 5.5.5 contain a bypass vulnerability where numeric character references (&#NNN;, …
VulnCve 2026 33036
high System graph security Trivy conf 1.00 CVE-2026-33231: nltk 3.9.1 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
nltk: NLTK: Denial of Service via unauthenticated remote shutdown NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, `nltk.app.wordnet_app` allows unauth…
VulnCve 2026 33231
high System graph security Trivy conf 1.00 CVE-2026-33236: nltk 3.9.1 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
nltk: NLTK: Arbitrary file overwrite and creation via path traversal in XML index files NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. In versions 3.9.3 and prior, the NLTK downl…
VulnCve 2026 33236
high System graph security Trivy conf 1.00 CVE-2026-33468: kysely 0.28.2 — advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml
Kysely has a MySQL SQL Injection via Insufficient Backslash Escaping in `sql.lit(string)` usage or similar methods that append string literal values into the compiled SQL strings Kysely is a type-safe TypeScript SQL query builder. Prior to version 0.28.14, Kysely's `DefaultQueryCompiler.sanitizeSt…
VulnCve 2026 33468
high System graph security Trivy conf 1.00 CVE-2026-33891: node-forge 1.3.1 — generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml
node-forge: node-forge: Denial of Service via infinite loop in BigInteger.modInverse() Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, a Denial of Service (DoS) vulnerability exists in the node-forge library due to an i…
VulnCve 2026 33891
high System graph security Trivy conf 1.00 CVE-2026-33894: node-forge 1.3.1 — generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml
node-forge: Forge: Signature Forgery via Weak RSASSA PKCS#1 v1.5 Verification Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, RSASSA PKCS#1 v1.5 signature verification accepts forged signatures for low public exponent k…
VulnCve 2026 33894
high System graph security Trivy conf 1.00 CVE-2026-33895: node-forge 1.3.1 — generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml
node-forge: Forge: Authentication bypass via forged Ed25519 cryptographic signatures Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, Ed25519 signature verification accepts forged non-canonical signatures where the scala…
VulnCve 2026 33895
high System graph security Trivy conf 1.00 CVE-2026-33896: node-forge 1.3.1 — generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml
node-forge: Forge (node-forge): Certificate validation bypass allows unauthorized certificate issuance Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. Prior to version 1.4.0, `pki.verifyCertificateChain()` does not enforce RFC 5280 basicConstr…
VulnCve 2026 33896
high System graph security Trivy conf 1.00 CVE-2026-34070: langchain-core 0.3.25 — rag_tutorials/rag_agent_cohere/requirements.txt
langchain: path traversal in legacy load_prompt functions in langchain-core LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without v…
VulnCve 2026 34070
high System graph security Trivy conf 1.00 CVE-2026-34070: langchain-core 0.3.28 — rag_tutorials/corrective_rag/requirements.txt
langchain: path traversal in legacy load_prompt functions in langchain-core LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without v…
VulnCve 2026 34070
high System graph security Trivy conf 1.00 CVE-2026-34070: langchain-core 0.3.28 — rag_tutorials/rag_database_routing/requirements.txt
langchain: path traversal in legacy load_prompt functions in langchain-core LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without v…
VulnCve 2026 34070
high System graph security Trivy conf 1.00 CVE-2026-34070: langchain-core 0.3.49 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
langchain: path traversal in legacy load_prompt functions in langchain-core LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without v…
VulnCve 2026 34070
high System graph security Trivy conf 1.00 CVE-2026-34070: langchain-core 0.3.65 — advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock
langchain: path traversal in legacy load_prompt functions in langchain-core LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without v…
VulnCve 2026 34070
high System graph security Trivy conf 1.00 CVE-2026-34070: langchain-core 1.2.16 — generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock
langchain: path traversal in legacy load_prompt functions in langchain-core LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without v…
VulnCve 2026 34070
high System graph security Trivy conf 1.00 CVE-2026-34070: langchain-core 1.2.7 — generative_ui_agents/ai-deep-research-agent/agent/uv.lock
langchain: path traversal in legacy load_prompt functions in langchain-core LangChain is a framework for building agents and LLM-powered applications. Prior to version 1.2.22, multiple functions in langchain_core.prompts.loading read files from paths embedded in deserialized config dicts without v…
VulnCve 2026 34070
high System graph security Trivy conf 1.00 CVE-2026-34077: react-router 7.13.2 — generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml
react-router: React Router: Denial of Service via client-side Cross-Site Scripting in RSC redirect handling React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a potential client-side Cross-Site Scrip…
VulnCve 2026 34077
high System graph security Trivy conf 1.00 CVE-2026-34769: electron 37.2.6 — advanced_llm_apps/thinkpath_chatbot_app/package-lock.json
Electron: Electron: Arbitrary code execution and security bypass via undocumented command-line switches Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, an undocumented commandLineSw…
VulnCve 2026 34769
high System graph security Trivy conf 1.00 CVE-2026-34770: electron 37.2.6 — advanced_llm_apps/thinkpath_chatbot_app/package-lock.json
Electron: Use-after-free in PowerMonitor on Windows and macOS Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.1, 40.8.0, and 41.0.0-beta.8, apps that use the powerMonitor module may be vulnerable to a use-after-…
VulnCve 2026 34770
high System graph security Trivy conf 1.00 CVE-2026-34771: electron 37.2.6 — advanced_llm_apps/thinkpath_chatbot_app/package-lock.json
electron: Electron: Memory corruption or application crash via use-after-free in permission request handling Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.0, 40.7.0, and 41.0.0-beta.8, apps that register an as…
VulnCve 2026 34771
high System graph security Trivy conf 1.00 CVE-2026-34774: electron 37.2.6 — advanced_llm_apps/thinkpath_chatbot_app/package-lock.json
Electron: Electron: Memory corruption and crash due to use-after-free in offscreen rendering Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 39.8.1, 40.7.0, and 41.0.0, apps that use offscreen rendering and allow child windo…
VulnCve 2026 34774
high System graph security Trivy conf 1.00 CVE-2026-35209: defu 6.1.4 — advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml
defu: Prototype pollution via `__proto__` key in defaults argument defu is software that allows uers to assign default properties recursively. Prior to version 6.1.5, applications that pass unsanitized user input (e.g. parsed JSON request bodies, database records, or config files from untrusted so…
VulnCve 2026 35209
high System graph security Trivy conf 1.00 CVE-2026-35536: tornado 6.4.2 — advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
tornado: Tornado: Cookie attribute injection due to improper handling of cookie arguments In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters. Package: tornado Instal…
VulnCve 2026 35536
high System graph security Trivy conf 1.00 CVE-2026-39363: vite 7.3.1 — generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml
Vite: Vite: Information disclosure via WebSocket connection bypasses access control Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fe…
VulnCve 2026 39363
high System graph security Trivy conf 1.00 CVE-2026-39363: vite 8.0.3 — generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml
Vite: Vite: Information disclosure via WebSocket connection bypasses access control Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacker can invoke fe…
VulnCve 2026 39363
high System graph security Trivy conf 1.00 CVE-2026-39364: vite 7.3.1 — generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml
vite: Vite: Information disclosure via query parameter manipulation on the development server Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with …
VulnCve 2026 39364
high System graph security Trivy conf 1.00 CVE-2026-39364: vite 8.0.3 — generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml
vite: Vite: Information disclosure via query parameter manipulation on the development server Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with …
VulnCve 2026 39364
high System graph security Trivy conf 1.00 CVE-2026-40192: Pillow 10.4.0 — starter_ai_agents/ai_data_visualisation_agent/requirements.txt
Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially c…
VulnCve 2026 40192
high System graph security Trivy conf 1.00 CVE-2026-40192: Pillow 11.0.0 — advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt
Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially c…
VulnCve 2026 40192
high System graph security Trivy conf 1.00 CVE-2026-40192: pillow 11.1.0 — advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially c…
VulnCve 2026 40192
high System graph security Trivy conf 1.00 CVE-2026-40192: pillow 11.1.0 — starter_ai_agents/ai_breakup_recovery_agent/requirements.txt
Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially c…
VulnCve 2026 40192
high System graph security Trivy conf 1.00 CVE-2026-40192: pillow 11.2.1 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially c…
VulnCve 2026 40192
high System graph security Trivy conf 1.00 CVE-2026-40192: pillow 11.2.1 — advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock
Pillow: Pillow: Denial of Service via decompression bomb in FITS image processing Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image, making them vulnerable to decompression bomb attacks. A specially c…
VulnCve 2026 40192
high System graph security Trivy conf 1.00 CVE-2026-41066: lxml 5.4.0 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
lxml: python: lxml: Information disclosure via untrusted XML input leading to local file read lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in the default configuration (with resolve_entities=True) allows untrusted XML input t…
VulnCve 2026 41066
high System graph security Trivy conf 1.00 CVE-2026-41205: mako 1.3.10 — generative_ui_agents/ai-financial-coach-agent/agent/uv.lock
mako: Mako: Information disclosure via path traversal vulnerability Mako is a template library written in Python. Prior to 1.3.11, TemplateLookup.get_template() is vulnerable to path traversal when a URI starts with // (e.g., //../../../secret.txt). The root cause is an inconsistency between two s…
VulnCve 2026 41205
high System graph security Trivy conf 1.00 CVE-2026-42033: axios 1.11.0 — advanced_llm_apps/thinkpath_chatbot_app/package-lock.json
axios: Axios: HTTP Transport Hijacking via Prototype Pollution Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has been polluted by any co-dependency with keys that axios reads without a hasOwnProperty guard, an attacker can (a) s…
VulnCve 2026 42033
high System graph security Trivy conf 1.00 CVE-2026-42035: axios 1.11.0 — advanced_llm_apps/thinkpath_chatbot_app/package-lock.json
axios: Axios: Arbitrary HTTP header injection via prototype pollution Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, a prototype pollution gadget exists in the Axios HTTP adapter (lib/adapters/http.js) that allows an attacker to inject arbitrary HTTP …
VulnCve 2026 42035
high System graph security Trivy conf 1.00 CVE-2026-42043: axios 1.11.0 — advanced_llm_apps/thinkpath_chatbot_app/package-lock.json
axios: Axios: NO_PROXY bypass via crafted URL Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence the target URL of an Axios request can use any address in the 127.0.0.0/8 range (other than 127.0.0.1) to completely bypass the …
VulnCve 2026 42043
high System graph security Trivy conf 1.00 CVE-2026-42211: react-router 7.13.2 — generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml
react-router: React Router: Remote Code Execution via prototype pollution in Framework Mode React Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a combination of steps could potentially allow unauthorized remote code execution (RCE) through external requ…
VulnCve 2026 42211
high System graph security Trivy conf 1.00 CVE-2026-42215: gitpython 3.1.44 — advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
GitPython is a python library used to interact with Git repositories. ... GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equival…
VulnCve 2026 42215
high System graph security Trivy conf 1.00 CVE-2026-42215: gitpython 3.1.44 — advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock
GitPython is a python library used to interact with Git repositories. ... GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equival…
VulnCve 2026 42215
high System graph security Trivy conf 1.00 CVE-2026-42215: GitPython 3.1.44 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
GitPython is a python library used to interact with Git repositories. ... GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by default, but the equival…
VulnCve 2026 42215
high System graph security Trivy conf 1.00 CVE-2026-42264: axios 1.11.0 — advanced_llm_apps/thinkpath_chatbot_app/package-lock.json
axios: Axios: Prototype pollution allows information disclosure and request manipulation Axios is a promise based HTTP client for the browser and Node.js. From version 1.0.0 to before version 1.15.2, fFive config properties (auth, baseURL, socketPath, beforeRedirect, and insecureHTTPParser) in the…
VulnCve 2026 42264
high System graph security Trivy conf 1.00 CVE-2026-42284: gitpython 3.1.44 — advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
GitPython is a python library used to interact with Git repositories. ... GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ".join(multi_options)). A string like "--bran…
VulnCve 2026 42284
high System graph security Trivy conf 1.00 CVE-2026-42284: gitpython 3.1.44 — advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock
GitPython is a python library used to interact with Git repositories. ... GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ".join(multi_options)). A string like "--bran…
VulnCve 2026 42284
high System graph security Trivy conf 1.00 CVE-2026-42284: GitPython 3.1.44 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
GitPython is a python library used to interact with Git repositories. ... GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ".join(multi_options)). A string like "--bran…
VulnCve 2026 42284
high System graph security Trivy conf 1.00 CVE-2026-42311: Pillow 10.4.0 — starter_ai_agents/ai_data_visualisation_agent/requirements.txt
Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file processing Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution.…
VulnCve 2026 42311
high System graph security Trivy conf 1.00 CVE-2026-42311: Pillow 11.0.0 — advanced_ai_agents/multi_agent_apps/agent_teams/multimodal_design_agent_team/requirements.txt
Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file processing Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution.…
VulnCve 2026 42311
high System graph security Trivy conf 1.00 CVE-2026-42311: pillow 11.1.0 — advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file processing Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution.…
VulnCve 2026 42311
high System graph security Trivy conf 1.00 CVE-2026-42311: pillow 11.1.0 — starter_ai_agents/ai_breakup_recovery_agent/requirements.txt
Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file processing Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution.…
VulnCve 2026 42311
high System graph security Trivy conf 1.00 CVE-2026-42311: pillow 11.2.1 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file processing Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution.…
VulnCve 2026 42311
high System graph security Trivy conf 1.00 CVE-2026-42311: pillow 11.2.1 — advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock
Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file processing Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution.…
VulnCve 2026 42311
high System graph security Trivy conf 1.00 CVE-2026-42342: react-router 7.13.2 — generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml
react-router: @remix-run/server-runtime: React Router / Remix: Denial of Service via unbounded path expansion in __manifest endpoint React Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 of @remix-run/server-runtime, certain crafted…
VulnCve 2026 42342
high System graph security Trivy conf 1.00 CVE-2026-42561: python-multipart 0.0.20 — advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
python-multipart: python-multipart: Denial of Service via excessive multipart part headers Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service vulnerability in multipart part header parsing. When parsing multipart/form-data, Multip…
VulnCve 2026 42561
high System graph security Trivy conf 1.00 CVE-2026-42561: python-multipart 0.0.20 — advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock
python-multipart: python-multipart: Denial of Service via excessive multipart part headers Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service vulnerability in multipart part header parsing. When parsing multipart/form-data, Multip…
VulnCve 2026 42561
high System graph security Trivy conf 1.00 CVE-2026-42561: python-multipart 0.0.20 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
python-multipart: python-multipart: Denial of Service via excessive multipart part headers Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service vulnerability in multipart part header parsing. When parsing multipart/form-data, Multip…
VulnCve 2026 42561
high System graph security Trivy conf 1.00 CVE-2026-42561: python-multipart 0.0.22 — generative_ui_agents/ai-financial-coach-agent/agent/uv.lock
python-multipart: python-multipart: Denial of Service via excessive multipart part headers Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service vulnerability in multipart part header parsing. When parsing multipart/form-data, Multip…
VulnCve 2026 42561
high System graph security Trivy conf 1.00 CVE-2026-4372: transformers 4.51.3 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
HuggingFace transformers vulnerable to remote code execution A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config.json` file containing the `_attn_impl…
VulnCve 2026 4372
high System graph security Trivy conf 1.00 CVE-2026-44243: gitpython 3.1.44 — advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
GitPython: GitPython: Arbitrary file write via crafted reference paths GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, ov…
VulnCve 2026 44243
high System graph security Trivy conf 1.00 CVE-2026-44243: gitpython 3.1.44 — advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock
GitPython: GitPython: Arbitrary file write via crafted reference paths GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, ov…
VulnCve 2026 44243
high System graph security Trivy conf 1.00 CVE-2026-44243: GitPython 3.1.44 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
GitPython: GitPython: Arbitrary file write via crafted reference paths GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPython allows attackers who can supply a crafted reference path to an application using GitPython to write, ov…
VulnCve 2026 44243
high System graph security Trivy conf 1.00 CVE-2026-44244: gitpython 3.1.44 — advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
GitPython is a python library used to interact with Git repositories. ... GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write() con…
VulnCve 2026 44244
high System graph security Trivy conf 1.00 CVE-2026-44244: gitpython 3.1.44 — advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock
GitPython is a python library used to interact with Git repositories. ... GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write() con…
VulnCve 2026 44244
high System graph security Trivy conf 1.00 CVE-2026-44244: GitPython 3.1.44 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
GitPython is a python library used to interact with Git repositories. ... GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value() passes values to Python's configparser without validating for newlines. GitPython's own _write() con…
VulnCve 2026 44244
high System graph security Trivy conf 1.00 CVE-2026-44289: protobufjs 7.5.4 — generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml
protobufjs: protobufjs: Denial of Service via uncontrolled recursion in protobuf decoding protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs could recurse without a depth limit while decoding nested protobuf data. This affected both skippi…
VulnCve 2026 44289
high System graph security Trivy conf 1.00 CVE-2026-44290: protobufjs 7.5.4 — generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml
protobufjs: protobufjs: Denial of Service via crafted schema protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs allowed certain schema option paths to traverse through inherited object properties while applying options. A crafted protobuf …
VulnCve 2026 44290
high System graph security Trivy conf 1.00 CVE-2026-44291: protobufjs 7.5.4 — generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml
protobufjs: protobufjs: Arbitrary Code Execution via prototype pollution protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs used plain objects with inherited prototypes for internal type lookup tables used by generated encode and decode fu…
VulnCve 2026 44291
high System graph security Trivy conf 1.00 CVE-2026-44293: protobufjs 7.5.4 — generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml
protobufjs: protobufjs: Arbitrary code execution due to unsafe expression generation from crafted protobuf descriptors protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated JavaScript for toObject conversion could include an unsafe …
VulnCve 2026 44293
high System graph security Trivy conf 1.00 CVE-2026-44307: mako 1.3.10 — generative_ui_agents/ai-financial-coach-agent/agent/uv.lock
mako: Mako: Information disclosure via directory traversal Mako is a template library written in Python. Prior to 1.3.12, on Windows, a URI using backslash traversal (e.g. \..\..\ secret.txt) bypasses the directory traversal check in Template.__init__ and the posixpath-based normalization in Templ…
VulnCve 2026 44307
high System graph security Trivy conf 1.00 CVE-2026-44431: urllib3 2.3.0 — advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=Fals…
VulnCve 2026 44431
high System graph security Trivy conf 1.00 CVE-2026-44431: urllib3 2.4.0 — advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock
urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=Fals…
VulnCve 2026 44431
high System graph security Trivy conf 1.00 CVE-2026-44431: urllib3 2.4.0 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=Fals…
VulnCve 2026 44431
high System graph security Trivy conf 1.00 CVE-2026-44431: urllib3 2.4.0 — advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock
urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=Fals…
VulnCve 2026 44431
high System graph security Trivy conf 1.00 CVE-2026-44431: urllib3 2.6.3 — generative_ui_agents/ai-deep-research-agent/agent/uv.lock
urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=Fals…
VulnCve 2026 44431
high System graph security Trivy conf 1.00 CVE-2026-44431: urllib3 2.6.3 — generative_ui_agents/ai-financial-coach-agent/agent/uv.lock
urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=Fals…
VulnCve 2026 44431
high System graph security Trivy conf 1.00 CVE-2026-44431: urllib3 2.6.3 — generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock
urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=Fals…
VulnCve 2026 44431
high System graph security Trivy conf 1.00 CVE-2026-44431: urllib3 2.6.3 — generative_ui_agents/generative-ui-starter-project/agent/uv.lock
urllib3: urllib3: Information disclosure via cross-origin redirects forwarding sensitive headers urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-level API via ProxyManager.connection_from_url().urlopen(..., assert_same_host=Fals…
VulnCve 2026 44431
high System graph security Trivy conf 1.00 CVE-2026-44432: urllib3 2.6.3 — generative_ui_agents/ai-deep-research-agent/agent/uv.lock
urllib3: urllib3: Denial of Service due to excessive HTTP response decompression urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the respo…
VulnCve 2026 44432
high System graph security Trivy conf 1.00 CVE-2026-44432: urllib3 2.6.3 — generative_ui_agents/ai-financial-coach-agent/agent/uv.lock
urllib3: urllib3: Denial of Service due to excessive HTTP response decompression urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the respo…
VulnCve 2026 44432
high System graph security Trivy conf 1.00 CVE-2026-44432: urllib3 2.6.3 — generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock
urllib3: urllib3: Denial of Service due to excessive HTTP response decompression urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the respo…
VulnCve 2026 44432
high System graph security Trivy conf 1.00 CVE-2026-44432: urllib3 2.6.3 — generative_ui_agents/generative-ui-starter-project/agent/uv.lock
urllib3: urllib3: Denial of Service due to excessive HTTP response decompression urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response instead of the requested portion (1) during the second HTTPResponse.read(amt=N) call when the respo…
VulnCve 2026 44432
high System graph security Trivy conf 1.00 CVE-2026-44486: axios 1.11.0 — advanced_llm_apps/thinkpath_chatbot_app/package-lock.json
axios: Axios: Information disclosure of proxy credentials via HTTP redirects Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a request is sent throug…
VulnCve 2026 44486
high System graph security Trivy conf 1.00 CVE-2026-44487: axios 1.11.0 — advanced_llm_apps/thinkpath_chatbot_app/package-lock.json
axios: Axios: Information disclosure of proxy credentials via redirect flows Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during specific proxy-to-direct re…
VulnCve 2026 44487
high System graph security Trivy conf 1.00 CVE-2026-44488: axios 1.11.0 — advanced_llm_apps/thinkpath_chatbot_app/package-lock.json
axios: Axios: Denial of Service due to unenforced request and response size limits Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce configured request and response size limits when requests were sent with the fetch adapter. Appli…
VulnCve 2026 44488
high System graph security Trivy conf 1.00 CVE-2026-44494: axios 1.11.0 — advanced_llm_apps/thinkpath_chatbot_app/package-lock.json
axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototype pollution in the applicatio…
VulnCve 2026 44494
high System graph security Trivy conf 1.00 CVE-2026-44495: axios 1.11.0 — advanced_llm_apps/thinkpath_chatbot_app/package-lock.json
axios: Axios: Information disclosure due to prototype pollution vulnerability Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same Jav…
VulnCve 2026 44495
high System graph security Trivy conf 1.00 CVE-2026-44496: axios 1.11.0 — advanced_llm_apps/thinkpath_chatbot_app/package-lock.json
axios: Axios: Client-side Denial of Service via unescaped regex metacharacters in XSRF cookie name Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF co…
VulnCve 2026 44496
high System graph security Trivy conf 1.00 CVE-2026-44573: next 15.3.2 — generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml
next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authoriza…
VulnCve 2026 44573
high System graph security Trivy conf 1.00 CVE-2026-44573: next 15.3.3 — advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml
next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authoriza…
VulnCve 2026 44573
high System graph security Trivy conf 1.00 CVE-2026-44573: next 15.5.12 — advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json
next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authoriza…
VulnCve 2026 44573
high System graph security Trivy conf 1.00 CVE-2026-44573: next 15.5.15 — agent_skills/self-improving-agent-skills/frontend/package-lock.json
next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authoriza…
VulnCve 2026 44573
high System graph security Trivy conf 1.00 CVE-2026-44573: next 16.1.1 — generative_ui_agents/ai-deep-research-agent/package-lock.json
next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authoriza…
VulnCve 2026 44573
high System graph security Trivy conf 1.00 CVE-2026-44573: next 16.1.1 — generative_ui_agents/ai-financial-coach-agent/package-lock.json
next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authoriza…
VulnCve 2026 44573
high System graph security Trivy conf 1.00 CVE-2026-44573: next 16.1.1 — generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml
next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authoriza…
VulnCve 2026 44573
high System graph security Trivy conf 1.00 CVE-2026-44573: next 16.1.1 — generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml
next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authoriza…
VulnCve 2026 44573
high System graph security Trivy conf 1.00 CVE-2026-44573: next 16.1.6 — advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json
next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authoriza…
VulnCve 2026 44573
high System graph security Trivy conf 1.00 CVE-2026-44573: next 16.1.6 — generative_ui_agents/generative-ui-starter-project/package-lock.json
next.js: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applications using the Pages Router with i18n configured and middleware/proxy-based authoriza…
VulnCve 2026 44573
high System graph security Trivy conf 1.00 CVE-2026-44574: next 15.5.12 — advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json
Next.js: Next.js: Authorization bypass via crafted query parameters Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected…
VulnCve 2026 44574
high System graph security Trivy conf 1.00 CVE-2026-44574: next 15.5.15 — agent_skills/self-improving-agent-skills/frontend/package-lock.json
Next.js: Next.js: Authorization bypass via crafted query parameters Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected…
VulnCve 2026 44574
high System graph security Trivy conf 1.00 CVE-2026-44574: next 16.1.1 — generative_ui_agents/ai-deep-research-agent/package-lock.json
Next.js: Next.js: Authorization bypass via crafted query parameters Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected…
VulnCve 2026 44574
high System graph security Trivy conf 1.00 CVE-2026-44574: next 16.1.1 — generative_ui_agents/ai-financial-coach-agent/package-lock.json
Next.js: Next.js: Authorization bypass via crafted query parameters Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected…
VulnCve 2026 44574
high System graph security Trivy conf 1.00 CVE-2026-44574: next 16.1.1 — generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml
Next.js: Next.js: Authorization bypass via crafted query parameters Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected…
VulnCve 2026 44574
high System graph security Trivy conf 1.00 CVE-2026-44574: next 16.1.1 — generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml
Next.js: Next.js: Authorization bypass via crafted query parameters Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected…
VulnCve 2026 44574
high System graph security Trivy conf 1.00 CVE-2026-44574: next 16.1.6 — advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json
Next.js: Next.js: Authorization bypass via crafted query parameters Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected…
VulnCve 2026 44574
high System graph security Trivy conf 1.00 CVE-2026-44574: next 16.1.6 — generative_ui_agents/generative-ui-starter-project/package-lock.json
Next.js: Next.js: Authorization bypass via crafted query parameters Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applications that rely on middleware to protect dynamic routes can be vulnerable to authorization bypass. In affected…
VulnCve 2026 44574
high System graph security Trivy conf 1.00 CVE-2026-44575: next 15.3.2 — generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml
next.js: Next.js: Unauthorized access to protected content via middleware bypass Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauth…
VulnCve 2026 44575
high System graph security Trivy conf 1.00 CVE-2026-44575: next 15.3.3 — advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml
next.js: Next.js: Unauthorized access to protected content via middleware bypass Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauth…
VulnCve 2026 44575
high System graph security Trivy conf 1.00 CVE-2026-44575: next 15.5.12 — advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json
next.js: Next.js: Unauthorized access to protected content via middleware bypass Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauth…
VulnCve 2026 44575
high System graph security Trivy conf 1.00 CVE-2026-44575: next 15.5.15 — agent_skills/self-improving-agent-skills/frontend/package-lock.json
next.js: Next.js: Unauthorized access to protected content via middleware bypass Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauth…
VulnCve 2026 44575
high System graph security Trivy conf 1.00 CVE-2026-44575: next 16.1.1 — generative_ui_agents/ai-deep-research-agent/package-lock.json
next.js: Next.js: Unauthorized access to protected content via middleware bypass Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauth…
VulnCve 2026 44575
high System graph security Trivy conf 1.00 CVE-2026-44575: next 16.1.1 — generative_ui_agents/ai-financial-coach-agent/package-lock.json
next.js: Next.js: Unauthorized access to protected content via middleware bypass Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauth…
VulnCve 2026 44575
high System graph security Trivy conf 1.00 CVE-2026-44575: next 16.1.1 — generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml
next.js: Next.js: Unauthorized access to protected content via middleware bypass Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauth…
VulnCve 2026 44575
high System graph security Trivy conf 1.00 CVE-2026-44575: next 16.1.1 — generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml
next.js: Next.js: Unauthorized access to protected content via middleware bypass Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauth…
VulnCve 2026 44575
high System graph security Trivy conf 1.00 CVE-2026-44575: next 16.1.6 — advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json
next.js: Next.js: Unauthorized access to protected content via middleware bypass Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauth…
VulnCve 2026 44575
high System graph security Trivy conf 1.00 CVE-2026-44575: next 16.1.6 — generative_ui_agents/generative-ui-starter-project/package-lock.json
next.js: Next.js: Unauthorized access to protected content via middleware bypass Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Router applications that rely on middleware or proxy-based checks for authorization can allow unauth…
VulnCve 2026 44575
high System graph security Trivy conf 1.00 CVE-2026-44578: next 15.3.2 — generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml
Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request…
VulnCve 2026 44578
high System graph security Trivy conf 1.00 CVE-2026-44578: next 15.3.3 — advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml
Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request…
VulnCve 2026 44578
high System graph security Trivy conf 1.00 CVE-2026-44578: next 15.5.12 — advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json
Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request…
VulnCve 2026 44578
high System graph security Trivy conf 1.00 CVE-2026-44578: next 15.5.15 — agent_skills/self-improving-agent-skills/frontend/package-lock.json
Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request…
VulnCve 2026 44578
high System graph security Trivy conf 1.00 CVE-2026-44578: next 16.1.1 — generative_ui_agents/ai-deep-research-agent/package-lock.json
Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request…
VulnCve 2026 44578
high System graph security Trivy conf 1.00 CVE-2026-44578: next 16.1.1 — generative_ui_agents/ai-financial-coach-agent/package-lock.json
Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request…
VulnCve 2026 44578
high System graph security Trivy conf 1.00 CVE-2026-44578: next 16.1.1 — generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml
Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request…
VulnCve 2026 44578
high System graph security Trivy conf 1.00 CVE-2026-44578: next 16.1.1 — generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml
Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request…
VulnCve 2026 44578
high System graph security Trivy conf 1.00 CVE-2026-44578: next 16.1.6 — advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json
Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request…
VulnCve 2026 44578
high System graph security Trivy conf 1.00 CVE-2026-44578: next 16.1.6 — generative_ui_agents/generative-ui-starter-project/package-lock.json
Next.js: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-hosted applications using the built-in Node.js server can be vulnerable to server-side request…
VulnCve 2026 44578
high System graph security Trivy conf 1.00 CVE-2026-44579: next 15.3.2 — generative_ui_agents/ai-dashboard-canvas-agent/pnpm-lock.yaml
next.js: Next.js: Denial of Service via crafted POST requests to server actions Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection ex…
VulnCve 2026 44579
high System graph security Trivy conf 1.00 CVE-2026-44579: next 15.3.3 — advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml
next.js: Next.js: Denial of Service via crafted POST requests to server actions Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection ex…
VulnCve 2026 44579
high System graph security Trivy conf 1.00 CVE-2026-44579: next 15.5.12 — advanced_ai_agents/multi_agent_apps/ai_negotiation_battle_simulator/frontend/package-lock.json
next.js: Next.js: Denial of Service via crafted POST requests to server actions Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection ex…
VulnCve 2026 44579
high System graph security Trivy conf 1.00 CVE-2026-44579: next 15.5.15 — agent_skills/self-improving-agent-skills/frontend/package-lock.json
next.js: Next.js: Denial of Service via crafted POST requests to server actions Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection ex…
VulnCve 2026 44579
high System graph security Trivy conf 1.00 CVE-2026-44579: next 16.1.1 — generative_ui_agents/ai-deep-research-agent/package-lock.json
next.js: Next.js: Denial of Service via crafted POST requests to server actions Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection ex…
VulnCve 2026 44579
high System graph security Trivy conf 1.00 CVE-2026-44579: next 16.1.1 — generative_ui_agents/ai-financial-coach-agent/package-lock.json
next.js: Next.js: Denial of Service via crafted POST requests to server actions Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection ex…
VulnCve 2026 44579
high System graph security Trivy conf 1.00 CVE-2026-44579: next 16.1.1 — generative_ui_agents/ai-mcp-app-builder/pnpm-lock.yaml
next.js: Next.js: Denial of Service via crafted POST requests to server actions Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection ex…
VulnCve 2026 44579
high System graph security Trivy conf 1.00 CVE-2026-44579: next 16.1.1 — generative_ui_agents/mcp-apps-generative-ui-showcase/pnpm-lock.yaml
next.js: Next.js: Denial of Service via crafted POST requests to server actions Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection ex…
VulnCve 2026 44579
high System graph security Trivy conf 1.00 CVE-2026-44579: next 16.1.6 — advanced_llm_apps/multimodal_video_moment_finder/frontend/package-lock.json
next.js: Next.js: Denial of Service via crafted POST requests to server actions Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection ex…
VulnCve 2026 44579
high System graph security Trivy conf 1.00 CVE-2026-44579: next 16.1.6 — generative_ui_agents/generative-ui-starter-project/package-lock.json
next.js: Next.js: Denial of Service via crafted POST requests to server actions Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications using Partial Prerendering through the Cache Components feature can be vulnerable to connection ex…
VulnCve 2026 44579
high System graph security Trivy conf 1.00 CVE-2026-44635: kysely 0.28.2 — advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml
Kysely: JSON-path traversal injection via unsanitized path-leg metacharacters in `JSONPathBuilder.key()` / `.at()` Kysely is a type-safe TypeScript SQL query builder. From 0.26.0 to 0.28.16, DefaultQueryCompiler.visitJSONPathLeg does not escape JSON-path metacharacters (., [, ], *, **, ?). When at…
VulnCve 2026 44635
high System graph security Trivy conf 1.00 CVE-2026-44843: langchain-core 0.3.25 — rag_tutorials/rag_agent_cohere/requirements.txt
langchain: LangChain: Information disclosure and data integrity compromise via insecure deserialization LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run outputs, or oth…
VulnCve 2026 44843
high System graph security Trivy conf 1.00 CVE-2026-44843: langchain-core 0.3.28 — rag_tutorials/corrective_rag/requirements.txt
langchain: LangChain: Information disclosure and data integrity compromise via insecure deserialization LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run outputs, or oth…
VulnCve 2026 44843
high System graph security Trivy conf 1.00 CVE-2026-44843: langchain-core 0.3.28 — rag_tutorials/rag_database_routing/requirements.txt
langchain: LangChain: Information disclosure and data integrity compromise via insecure deserialization LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run outputs, or oth…
VulnCve 2026 44843
high System graph security Trivy conf 1.00 CVE-2026-44843: langchain-core 0.3.49 — advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
langchain: LangChain: Information disclosure and data integrity compromise via insecure deserialization LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run outputs, or oth…
VulnCve 2026 44843
high System graph security Trivy conf 1.00 CVE-2026-44843: langchain-core 0.3.65 — advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock
langchain: LangChain: Information disclosure and data integrity compromise via insecure deserialization LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run outputs, or oth…
VulnCve 2026 44843
high System graph security Trivy conf 1.00 CVE-2026-44843: langchain-core 1.2.16 — generative_ui_agents/ai-shadcn-component-generator/apps/agent/uv.lock
langchain: LangChain: Information disclosure and data integrity compromise via insecure deserialization LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run outputs, or oth…
VulnCve 2026 44843
high System graph security Trivy conf 1.00 CVE-2026-44843: langchain-core 1.2.29 — generative_ui_agents/generative-ui-starter-project/agent/uv.lock
langchain: LangChain: Information disclosure and data integrity compromise via insecure deserialization LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run outputs, or oth…
VulnCve 2026 44843
high System graph security Trivy conf 1.00 CVE-2026-44843: langchain-core 1.2.7 — generative_ui_agents/ai-deep-research-agent/agent/uv.lock
langchain: LangChain: Information disclosure and data integrity compromise via insecure deserialization LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run outputs, or oth…
VulnCve 2026 44843

Showing first 300 of 2700. Refine filters or use the findings page for deep search.

For AI agents: Voting guide (TP/FP) MCP manifest Stdio wrapper SARIF Integrate Findings queue Vote TP/FP on findings to calibrate the engine.
For AI agents + API integrations
Email me when this repo regresses
Free. We re-scan periodically; new criticals → your inbox. No signup required for the scan itself.
API access

This page is publicly accessible at: https://repobility.com/scan/b8f7260d-811b-4566-a173-54eaa034c741/

To check status programmatically (no auth required):

curl -s https://repobility.com/api/v1/public/scan/b8f7260d-811b-4566-a173-54eaa034c741/

Important — please don't re-submit the same URL repeatedly. The submission endpoint is idempotent: re-submitting the same git URL returns this same scan_token, not a new one. To re-scan this repo, sign up free and use the dashboard.