gitsafehub
github.com/CollegesChat/university-information ↗

CollegesChat/university-information

scanned 2026-07-24 · git 0aa4c19
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 4 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies41Known OSS vulnerabilities70Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks timed out

API keys, passwords or tokens committed into the repo.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Gitleaks v8.21.2 · MIT

error: timeout after 120s

Vulnerable dependencies — Trivy 41 found · 3 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2020-14343 PyYAML: incomplete fix for CVE-2020-1747
    questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2020-14343). Fix: Update that package to its patched version.
  • Serious CVE-2022-21797 The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary ...
    questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2022-21797). Fix: Update that package to its patched version.
  • Serious CVE-2025-14009 nltk: Zip Slip Vulnerability in nltk Leading to Code Execution
    questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2025-14009). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-28493 python-jinja2: ReDoS vulnerability in the urlize filter
    questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2020-28493). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-22195 jinja2: HTML attribute injection when passing user input as keys to xmlattr filter
    questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2024-22195). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-34064 jinja2: accepts keys containing non-attribute characters
    questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2024-34064). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-56326 jinja2: Jinja has a sandbox breakout through indirect reference to format method
    questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2024-56326). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-27516 jinja2: Jinja sandbox breakout through attr filter selecting format method
    questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2025-27516). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-69534 python-markdown: denial of service via malformed HTML-like sequences
    questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2025-69534). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-20270 python-pygments: Infinite loop in SML lexer may lead to DoS
    questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2021-20270). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-27291 python-pygments: ReDoS in multiple lexers
    questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2021-27291). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-40896 pygments: ReDoS in pygments
    questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2022-40896). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-40899 python-future: remote attackers can cause denial of service via crafted Set-Cookie header from malicious web server
    questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2022-40899). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-3828 nltk is vulnerable to Inefficient Regular Expression Complexity
    questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2021-3828). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-3842 nltk is vulnerable to Inefficient Regular Expression Complexity
    questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2021-3842). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-43854 NLTK (Natural Language Toolkit) is a suite of open source Python modul ...
    questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2021-43854). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-39705 NLTK through 3.8.1 allows remote code execution if untrusted packages ...
    questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2024-39705). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-0846 nltk: NLTK: Arbitrary file read via improper path validation in `filestring()` function
    questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2026-0846). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-33231 nltk: NLTK: Denial of Service via unauthenticated remote shutdown
    questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2026-33231). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-54293 nltk: NLTK: Information Disclosure via Path Traversal in `nltk.data.load()`
    questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2026-54293). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-33230 nltk: NLTK: Script execution via reflected cross-site scripting in WordNet Browser
    questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2026-33230). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-32309 PyMdown Extensions is a set of extensions for the `Python-Markdown` ma ...
    questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2023-32309). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-52804 python-tornado: Tornado has HTTP cookie parsing DoS vulnerability
    questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2024-52804). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-47287 tornado: Tornado Multipart Form-Data Denial of Service
    questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2025-47287). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-67725 tornado: Tornado Quadratic DoS via Repeated Header Coalescing
    questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2025-67725). Fix: Update that package to its patched version.
… 16 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 70 found · 8 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious PYSEC-2021-142 A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or
    /workdirs/scan-38bd3047-c1c7-44d7-bb14-68471ddcbb79/questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2020-14343). Fix: Update that package to its patched version.
  • Serious PYSEC-2022-288 The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement.
    /workdirs/scan-38bd3047-c1c7-44d7-bb14-68471ddcbb79/questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2022-21797). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-96 A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter function in nltk/downloader.py uses zipfile.extractall() without performing path
    /workdirs/scan-38bd3047-c1c7-44d7-bb14-68471ddcbb79/questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2025-14009). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-99 NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamically loads external Java .jar files without verific
    /workdirs/scan-38bd3047-c1c7-44d7-bb14-68471ddcbb79/questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2026-0848). Fix: Update that package to its patched version.
  • Serious PYSEC-2022-42992 All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone
    /workdirs/scan-38bd3047-c1c7-44d7-bb14-68471ddcbb79/questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2022-24439). Fix: Update that package to its patched version.
  • Serious PYSEC-2023-137 GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.
    /workdirs/scan-38bd3047-c1c7-44d7-bb14-68471ddcbb79/questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2023-40267). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-2161 GitPython is a python library used to interact with Git repositories. Prior to version 3.1.47, _clone() validates multi_options as the original list, then executes shlex.split(" ".join(multi_options))
    /workdirs/scan-38bd3047-c1c7-44d7-bb14-68471ddcbb79/questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2026-42284). Fix: Update that package to its patched version.
  • Serious PYSEC-2021-142 A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or
    /workdirs/scan-38bd3047-c1c7-44d7-bb14-68471ddcbb79/questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2020-14343). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2021-66 This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the
    /workdirs/scan-38bd3047-c1c7-44d7-bb14-68471ddcbb79/questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2020-28493). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1471 Jinja2 vulnerable to sandbox breakout through attr filter selecting format method
    /workdirs/scan-38bd3047-c1c7-44d7-bb14-68471ddcbb79/questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2025-27516). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1473 Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
    /workdirs/scan-38bd3047-c1c7-44d7-bb14-68471ddcbb79/questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2024-22195). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1474 Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
    /workdirs/scan-38bd3047-c1c7-44d7-bb14-68471ddcbb79/questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2024-34064). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1475 Jinja has a sandbox breakout through indirect reference to format method
    /workdirs/scan-38bd3047-c1c7-44d7-bb14-68471ddcbb79/questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2024-56326). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-89 Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Ma
    /workdirs/scan-38bd3047-c1c7-44d7-bb14-68471ddcbb79/questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2025-69534). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2021-140 An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only
    /workdirs/scan-38bd3047-c1c7-44d7-bb14-68471ddcbb79/questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2021-20270). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2021-141 In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity an
    /workdirs/scan-38bd3047-c1c7-44d7-bb14-68471ddcbb79/questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2021-27291). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2023-117 A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.
    /workdirs/scan-38bd3047-c1c7-44d7-bb14-68471ddcbb79/questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2022-40896). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2132 Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.
    /workdirs/scan-38bd3047-c1c7-44d7-bb14-68471ddcbb79/questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2026-7246). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2022-42991 An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server.
    /workdirs/scan-38bd3047-c1c7-44d7-bb14-68471ddcbb79/questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2022-40899). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2021-356 nltk is vulnerable to Inefficient Regular Expression Complexity
    /workdirs/scan-38bd3047-c1c7-44d7-bb14-68471ddcbb79/questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2021-3828). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2021-859 NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Versions prior to 3.6.5 are vulne
    /workdirs/scan-38bd3047-c1c7-44d7-bb14-68471ddcbb79/questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2021-43854). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2022-5 nltk is vulnerable to Inefficient Regular Expression Complexity
    /workdirs/scan-38bd3047-c1c7-44d7-bb14-68471ddcbb79/questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2021-3842). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2024-167 NLTK through 3.8.1 allows remote code execution if untrusted packages have pickled Python code, and the integrated data package download functionality is used. This affects, for example, averaged_perc
    /workdirs/scan-38bd3047-c1c7-44d7-bb14-68471ddcbb79/questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2024-39705). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2078 NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Prior to 3.10.0-rc1, nltk.data.lo
    /workdirs/scan-38bd3047-c1c7-44d7-bb14-68471ddcbb79/questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2026-54293). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2085 In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, StanfordParser, StanfordDependencyParser, and StanfordNeuralDependencyParser) are vulner
    /workdirs/scan-38bd3047-c1c7-44d7-bb14-68471ddcbb79/questionnaires/site/requirements.txt
    A package you depend on has a known security hole (CVE-2026-12252). Fix: Update that package to its patched version.
… 45 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.