Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
Packages you depend on that have known security holes (CVEs).
CVE-2023-30861 flask: Possible disclosure of permanent session cookie due to missing Vary: Cookie headerCVE-2020-28493 python-jinja2: ReDoS vulnerability in the urlize filterCVE-2024-22195 Jinja is an extensible templating engine. Special placeholders in the ...CVE-2024-34064 Jinja is an extensible templating engine. The `xmlattr` filter in affe ...CVE-2024-56326 Jinja is an extensible templating engine. Prior to 3.1.5, An oversight ...CVE-2025-27516 Jinja is an extensible templating engine. Prior to 3.1.6, an oversight ...CVE-2023-25577 python-werkzeug: high resource usage when parsing multipart form data with many fieldsCVE-2024-34069 Werkzeug is a comprehensive WSGI web application library. The debugger ...CVE-2024-49766 Werkzeug safe_join not safe on WindowsCVE-2025-66221 Werkzeug safe_join() allows Windows special device namesCVE-2026-21860 Werkzeug safe_join() allows Windows special device names with compound extensionsCVE-2026-27199 Werkzeug safe_join() allows Windows special device namesCVE-2026-27205 flask: Flask: Information disclosure via improper caching of session dataCVE-2023-23934 python-werkzeug: cookie prefixed with = can shadow unprefixed cookieYour dependencies cross-checked against the OSV vulnerability database.
GHSA-m2qf-hxjv-5gpq Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie headerGHSA-2g68-c3qc-8985 Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domainGHSA-xg9f-g7g7-2323 High resource usage when parsing multipart form data with many fieldsGHSA-m2qf-hxjv-5gpq Flask vulnerable to possible disclosure of permanent session cookie due to missing Vary: Cookie headerGHSA-2g68-c3qc-8985 Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domainGHSA-xg9f-g7g7-2323 High resource usage when parsing multipart form data with many fieldsGHSA-68rp-wp8r-4726 Flask session does not add `Vary: Cookie` header when accessed in some waysGHSA-px8h-6qxv-m22q Incorrect parsing of nameless cookies leads to __Host- cookies bypassGHSA-68rp-wp8r-4726 Flask session does not add `Vary: Cookie` header when accessed in some waysGHSA-px8h-6qxv-m22q Incorrect parsing of nameless cookies leads to __Host- cookies bypassPYSEC-2023-62 Flask is a lightweight WSGI web application framework. When all of the following conditions are met, a response containing data intended for one client may be cached and subsequently sent by the proxyPYSEC-2021-66 This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the GHSA-cpwx-vrp4-4pq7 Jinja2 vulnerable to sandbox breakout through attr filter selecting format methodGHSA-g3rq-g295-4j3m Regular Expression Denial of Service (ReDoS) in Jinja2GHSA-h5c8-rqwp-cp95 Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filterGHSA-h75v-3vvj-5mfj Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filterGHSA-q2x7-8rv6-6q7h Jinja has a sandbox breakout through indirect reference to format methodPYSEC-2022-203 ** DISPUTED ** Improper parsing of HTTP requests in Pallets Werkzeug v2.1.0 and below allows attackers to perform HTTP Request Smuggling using a crafted HTTP request with multiple requests included inPYSEC-2023-221 Werkzeug is a comprehensive WSGI web application library. If an upload of a file that starts with CR or LF and then is followed by megabytes of data without these characters: all of these bytes are apPYSEC-2023-57 Werkzeug is a comprehensive WSGI web application library. Browsers may allow "nameless" cookies that look like `=value` instead of `key=value`. A vulnerable browser may allow a compromised applicationPYSEC-2023-58 Werkzeug is a comprehensive WSGI web application library. Prior to version 2.2.3, Werkzeug's multipart form data parser will parse an unlimited number of parts, including file parts. Parts can be a smGHSA-29vq-49wr-vm6x Werkzeug safe_join() allows Windows special device namesGHSA-87hc-h4r5-73f7 Werkzeug safe_join() allows Windows special device names with compound extensionsGHSA-f9vj-2wh5-fj8j Werkzeug safe_join not safe on WindowsGHSA-hgf8-39gv-g3f2 Werkzeug safe_join() allows Windows special device namesCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.