Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

33 advisories

Loading
senaite.core Vulnerable to Eval Injection and Missing Authorization Critical
CVE-2026-54569 was published for senaite.core (pip) Aug 26, 2026
snomi Credited to snomi and Volcore Volcore Volcore
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing Critical
CVE-2026-61539 was published for xinference (pip) Aug 21, 2026
XlabAITeam Credited to XlabAITeam, keenanwgn, and A7um keenanwgn keenanwgn
A7um A7um
thegr1ffyn Credited to thegr1ffyn, mhamzakhattak, and Muzammilxi mhamzakhattak mhamzakhattak
Muzammilxi Muzammilxi
NLTK vulnerable to Eval Injection via collocations CLI arguments High
CVE-2025-71408 was published for nltk (pip) Jul 25, 2026
PercevalFox Credited to PercevalFox
django-haystack: Remote Code Execution via `eval()` in Elasticsearch Result Deserialization High
GHSA-r3hx-x5rh-p9vv was published for django-haystack (pip) Jul 15, 2026
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval Critical
CVE-2026-61667 was published for DIRAC (pip) Jul 13, 2026
sfayer Credited to sfayer
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input Critical
CVE-2026-45579 was published for DIRAC (pip) Jul 13, 2026
sfayer Credited to sfayer
python-statemachine SCXML <data expr> Eval Injection Critical
CVE-2026-47103 was published for python-statemachine (pip) Jun 18, 2026
wsparks-vc Credited to wsparks-vc and SaiTeja-Erukude SaiTeja-Erukude SaiTeja-Erukude
Duplicate Advisory: Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER High
GHSA-cc5p-54x3-hcf8 was published for picklescan (pip) Jun 17, 2026 withdrawn
PraisonAI's unauthenticated A2A official example can reach real LLM-driven `eval()` tool execution Critical
CVE-2026-47391 was published for PraisonAI (pip) May 29, 2026
foxirain Credited to foxirain
Koukyosyumei Credited to Koukyosyumei
verl's math_equal() Vulnerable to Arbitrary Code Execution via Unsafe eval() Low
CVE-2026-6878 was published for verl (pip) Apr 23, 2026
Agno is vulnerable to Eval Injection Critical
CVE-2026-35002 was published for agno (pip) Apr 2, 2026
TorchGeo Remote Code Execution Vulnerability High
CVE-2024-49048 was published for torchgeo (pip) Apr 1, 2026
zpbrent Credited to zpbrent, calebrob6, and adamjstewart calebrob6 calebrob6
adamjstewart adamjstewart
Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint Critical
CVE-2026-33017 was published for langflow (pip) Mar 17, 2026
Aviral2642 Credited to Aviral2642, andifilhohub, Jkavia, and srmish-jfrog andifilhohub andifilhohub
Jkavia Jkavia srmish-jfrog srmish-jfrog
OpenStack Vitrage: Unauthorized Access to the Host can Lead to Eval Injection Critical
CVE-2026-28370 was published for vitrage (pip) Feb 27, 2026
Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events High
CVE-2025-64496 was published for open-webui (npm) Nov 7, 2025
vitalysim Credited to vitalysim
Picklescan has a missing detection when calling built-in python idlelib.calltip.Calltip High
CVE-2025-71361 was published for picklescan (pip) Aug 26, 2025
FredericDT Credited to FredericDT
AgentScope uses `eval` High
CVE-2024-48050 was published for agentscope (pip) Nov 5, 2024
LangChain Experimental Eval Injection vulnerability Critical
CVE-2024-46946 was published for langchain-experimental (pip) Sep 19, 2024
Guardrails has an arbitrary code execution vulnerability High
CVE-2024-45858 was published for guardrails-ai (pip) Sep 18, 2024
MindsDB Eval Injection vulnerability High
CVE-2024-45851 was published for mindsdb (pip) Sep 12, 2024
Refuel Autolab Eval Injection vulnerability High
CVE-2024-27321 was published for refuel-autolabel (pip) Sep 12, 2024
Refuel Autolab Eval Injection vulnerability High
CVE-2024-27320 was published for refuel-autolabel (pip) Sep 12, 2024
MindsDB Eval Injection vulnerability High
CVE-2024-45849 was published for mindsdb (pip) Sep 12, 2024
ProTip! Advisories are also available from the GraphQL API