Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-rm43-82j9-r4mj
  • PyPI/atomic-agents-stack
atomic-agents-stack: Dashboard HTTP server path traversal allows arbitrary file read 33 minutes ago
  • Fix available
  • Severity - 8.2 (High)
GHSA-h7p7-w5gc-xj3w
  • PyPI/pydantic-ai
  • PyPI/pydantic-ai-slim
Pydantic AI: Unvalidated UploadedFile references in UI adapters allow server-side file access using the application's credentials 34 minutes ago
  • Fix available
  • Severity - 6.8 (Medium)
GHSA-48p8-g2fx-3wwm
  • Go/github.com/argoproj/argo-workflows
  • Go/github.com/argoproj/argo-workflows/v3
  • Go/github.com/argoproj/argo-workflows/v4
Argo Workflows: ArtifactGC.PodSpecPatch bypasses Strict/Secure template reference allow-list (Incomplete fix for CVE-2026-31892) 34 minutes ago
  • Fix available
  • Severity - 8.9 (High)
GHSA-5pq8-3ffp-7w5m
  • npm/hashi-vault-js
hashi-vault-js: Vault token and secret values exposed in thrown errors 36 minutes ago
  • Fix available
GHSA-vqfp-p66c-xrp9
  • npm/ep_etherpad-lite
ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token 38 minutes ago
  • Fix available
  • Severity - 6.8 (Medium)
GHSA-2jwf-f4xq-f24h
  • npm/ep_etherpad-lite
ep_etherpad-lite: Import/export uses Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwrite 39 minutes ago
  • Fix available
  • Severity - 4.2 (Medium)
ROOT-APP-NPM-CVE-2026-13149
  • Root:npm/@rootio/brace-expansion
  • Root:npm/brace-expansion
CVE-2026-13149 in brace-expansion - Patched by Root 59 minutes ago
  • Fix available
ROOT-APP-NPM-CVE-2026-14257
  • Root:npm/@rootio/brace-expansion
  • Root:npm/brace-expansion
CVE-2026-14257 in brace-expansion - Patched by Root 59 minutes ago
  • Fix available
ROOT-APP-NPM-CVE-2026-69152
  • Root:npm/@rootio/brace-expansion
  • Root:npm/brace-expansion
CVE-2026-69152 in brace-expansion - Patched by Root 59 minutes ago
  • Fix available
ROOT-APP-NPM-GHSA-gcfj-64vw-6mp9
  • Root:npm/@rootio/axios
  • Root:npm/axios
GHSA-gcfj-64vw-6mp9 in axios - Patched by Root 59 minutes ago
  • Fix available
ROOT-APP-NPM-CVE-2026-45149
  • Root:npm/@rootio/brace-expansion
  • Root:npm/brace-expansion
CVE-2026-45149 in brace-expansion - Patched by Root 1 hour ago
  • Fix available
  • Severity - 6.5 (Medium)
ROOT-APP-NPM-CVE-2026-53655
  • Root:npm/@rootio/tar
  • Root:npm/tar
CVE-2026-53655 in tar - Patched by Root 1 hour ago
  • Fix available
ROOT-APP-NPM-CVE-2026-59871
  • Root:npm/@rootio/tar
  • Root:npm/tar
CVE-2026-59871 in tar - Patched by Root 1 hour ago
  • Fix available
ROOT-APP-NPM-CVE-2026-59873
  • Root:npm/@rootio/tar
  • Root:npm/tar
CVE-2026-59873 in tar - Patched by Root 1 hour ago
  • Fix available
ROOT-APP-NPM-CVE-2026-59874
  • Root:npm/@rootio/tar
  • Root:npm/tar
CVE-2026-59874 in tar - Patched by Root 1 hour ago
  • Fix available
ROOT-APP-NPM-CVE-2026-69192
  • Root:npm/@rootio/ip-address
  • Root:npm/ip-address
CVE-2026-69192 in ip-address - Patched by Root 1 hour ago
  • Fix available