gitsafehub
github.com/dennybritz/nn-theano ↗

dennybritz/nn-theano

scanned 2026-08-05 · git c34675f
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 4 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies71Known OSS vulnerabilities90Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks none found ✓

API keys, passwords or tokens committed into the repo.

Nothing found by this check. ✓

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 71 found · 3 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2015-8557 python-pygments: Shell injection in FontManager._get_nix_font_path
    requirements.txt
    A package you depend on has a known security hole (CVE-2015-8557). Fix: Update that package to its patched version.
  • Serious CVE-2015-7337 Improper Input Validation in Jupyter Notebook
    requirements.txt
    A package you depend on has a known security hole (CVE-2015-7337). Fix: Update that package to its patched version.
  • Serious CVE-2019-6446 numpy: crafted serialized object passed in numpy.load() in pickle python module allows arbitrary code execution
    requirements.txt
    A package you depend on has a known security hole (CVE-2019-6446). Fix: Update that package to its patched version.
  • Worth fixing CVE-2016-10745 python-jinja2: Sandbox escape due to information disclosure via str.format
    requirements.txt
    A package you depend on has a known security hole (CVE-2016-10745). Fix: Update that package to its patched version.
  • Worth fixing CVE-2019-10906 python-jinja2: str.format_map allows sandbox escape
    requirements.txt
    A package you depend on has a known security hole (CVE-2019-10906). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-28493 python-jinja2: ReDoS vulnerability in the urlize filter
    requirements.txt
    A package you depend on has a known security hole (CVE-2020-28493). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-22195 jinja2: HTML attribute injection when passing user input as keys to xmlattr filter
    requirements.txt
    A package you depend on has a known security hole (CVE-2024-22195). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-34064 jinja2: accepts keys containing non-attribute characters
    requirements.txt
    A package you depend on has a known security hole (CVE-2024-34064). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-56326 jinja2: Jinja has a sandbox breakout through indirect reference to format method
    requirements.txt
    A package you depend on has a known security hole (CVE-2024-56326). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-27516 jinja2: Jinja sandbox breakout through attr filter selecting format method
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-27516). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-20270 python-pygments: Infinite loop in SML lexer may lead to DoS
    requirements.txt
    A package you depend on has a known security hole (CVE-2021-20270). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-27291 python-pygments: ReDoS in multiple lexers
    requirements.txt
    A package you depend on has a known security hole (CVE-2021-27291). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-40896 pygments: ReDoS in pygments
    requirements.txt
    A package you depend on has a known security hole (CVE-2022-40896). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-37920 python-certifi: Removal of e-Tugra root certificate
    requirements.txt
    A package you depend on has a known security hole (CVE-2023-37920). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-21699 IPython (Interactive Python) is a command shell for interactive comput ...
    requirements.txt
    A package you depend on has a known security hole (CVE-2022-21699). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-39286 Jupyter Core is a package for the core common functionality of Jupyter ...
    requirements.txt
    A package you depend on has a known security hole (CVE-2022-39286). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-30167 Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-30167). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-49851 Mistune: Mistune: Denial of Service via crafted Markdown input
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-49851). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-59922 mistune: Mistune: Denial of Service via crafted input
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-59922). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-59925 mistune: Mistune: Denial of Service via crafted Markdown input
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-59925). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-59928 mistune: Mistune: Denial of Service via crafted Markdown document with reference-link definitions
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-59928). Fix: Update that package to its patched version.
  • Worth fixing CVE-2017-15612 mistune.py in Mistune 0.7.4 allows XSS via an unexpected newline (such ...
    requirements.txt
    A package you depend on has a known security hole (CVE-2017-15612). Fix: Update that package to its patched version.
  • Worth fixing CVE-2017-16876 Cross-site scripting (XSS) vulnerability in the _keyify function in mi ...
    requirements.txt
    A package you depend on has a known security hole (CVE-2017-16876). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-44896 mistune: Mistune: Cross-Site Scripting (XSS) via unescaped HTML attributes
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-44896). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-44897 mistune: Mistune: Cross-site scripting (XSS) via improper sanitization of HTML heading ID attribute
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-44897). Fix: Update that package to its patched version.
… 46 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 90 found · 6 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious PYSEC-2016-32 The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.
    /workdirs/scan-4ea278b2-4718-4de8-84ad-c9c675f18685/requirements.txt
    A package you depend on has a known security hole (CVE-2015-8557). Fix: Update that package to its patched version.
  • Serious PYSEC-2015-27 The editor in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to execute arbitrary JavaScript code via a crafted file, which triggers a redirect to files/
    /workdirs/scan-4ea278b2-4718-4de8-84ad-c9c675f18685/requirements.txt
    A package you depend on has a known security hole (CVE-2015-7337). Fix: Update that package to its patched version.
  • Serious GHSA-hwvq-6gjx-j797 Special Element Injection in notebook
    /workdirs/scan-4ea278b2-4718-4de8-84ad-c9c675f18685/requirements.txt
    A package you depend on has a known security hole (CVE-2021-32798). Fix: Update that package to its patched version.
  • Serious PYSEC-2019-108 ** DISPUTED ** An issue was discovered in NumPy 1.16.0 and earlier. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object
    /workdirs/scan-4ea278b2-4718-4de8-84ad-c9c675f18685/requirements.txt
    A package you depend on has a known security hole (CVE-2019-6446). Fix: Update that package to its patched version.
  • Serious PYSEC-2020-107 ** DISPUTED ** scikit-learn (aka sklearn) through 0.23.0 can unserialize and execute commands from an untrusted file that is passed to the joblib.load() function, if __reduce__ makes an os.system call
    /workdirs/scan-4ea278b2-4718-4de8-84ad-c9c675f18685/requirements.txt
    A package you depend on has a known security hole (CVE-2020-13092). Fix: Update that package to its patched version.
  • Serious PYSEC-2016-32 The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.
    /workdirs/scan-4ea278b2-4718-4de8-84ad-c9c675f18685/requirements.txt
    A package you depend on has a known security hole (CVE-2015-8557). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2019-217 In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.
    /workdirs/scan-4ea278b2-4718-4de8-84ad-c9c675f18685/requirements.txt
    A package you depend on has a known security hole (CVE-2019-10906). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2019-220 In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.
    /workdirs/scan-4ea278b2-4718-4de8-84ad-c9c675f18685/requirements.txt
    A package you depend on has a known security hole (CVE-2016-10745). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2021-66 This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the
    /workdirs/scan-4ea278b2-4718-4de8-84ad-c9c675f18685/requirements.txt
    A package you depend on has a known security hole (CVE-2020-28493). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1471 Jinja2 vulnerable to sandbox breakout through attr filter selecting format method
    /workdirs/scan-4ea278b2-4718-4de8-84ad-c9c675f18685/requirements.txt
    A package you depend on has a known security hole (CVE-2025-27516). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1473 Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
    /workdirs/scan-4ea278b2-4718-4de8-84ad-c9c675f18685/requirements.txt
    A package you depend on has a known security hole (CVE-2024-22195). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1474 Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
    /workdirs/scan-4ea278b2-4718-4de8-84ad-c9c675f18685/requirements.txt
    A package you depend on has a known security hole (CVE-2024-34064). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1475 Jinja has a sandbox breakout through indirect reference to format method
    /workdirs/scan-4ea278b2-4718-4de8-84ad-c9c675f18685/requirements.txt
    A package you depend on has a known security hole (CVE-2024-56326). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2021-140 An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only
    /workdirs/scan-4ea278b2-4718-4de8-84ad-c9c675f18685/requirements.txt
    A package you depend on has a known security hole (CVE-2021-20270). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2021-141 In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity an
    /workdirs/scan-4ea278b2-4718-4de8-84ad-c9c675f18685/requirements.txt
    A package you depend on has a known security hole (CVE-2021-27291). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2023-117 A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer.
    /workdirs/scan-4ea278b2-4718-4de8-84ad-c9c675f18685/requirements.txt
    A package you depend on has a known security hole (CVE-2022-40896). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2023-135 Certifi 2023.07.22 removes root certificates from "e-Tugra" from the root store. These are in the process of being removed from Mozilla's trust store. e-Tugra's root certificates are being removed pur
    /workdirs/scan-4ea278b2-4718-4de8-84ad-c9c675f18685/requirements.txt
    A package you depend on has a known security hole (CVE-2023-37920). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2024-230 Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.05.30 and prior to 2024.
    /workdirs/scan-4ea278b2-4718-4de8-84ad-c9c675f18685/requirements.txt
    A package you depend on has a known security hole (CVE-2024-39689). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2022-12 IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to
    /workdirs/scan-4ea278b2-4718-4de8-84ad-c9c675f18685/requirements.txt
    A package you depend on has a known security hole (CVE-2022-21699). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2023-17 IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Versions prior to 8.1.0 are subje
    /workdirs/scan-4ea278b2-4718-4de8-84ad-c9c675f18685/requirements.txt
    A package you depend on has a known security hole (CVE-2023-24816). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2022-42974 Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code execution vulnerability in `jupyter_core` that stems fr
    /workdirs/scan-4ea278b2-4718-4de8-84ad-c9c675f18685/requirements.txt
    A package you depend on has a known security hole (CVE-2022-39286). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1477 Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
    /workdirs/scan-4ea278b2-4718-4de8-84ad-c9c675f18685/requirements.txt
    A package you depend on has a known security hole (CVE-2025-30167). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2017-18 Cross-site scripting (XSS) vulnerability in the _keyify function in mistune.py in Mistune before 0.8.1 allows remote attackers to inject arbitrary web script or HTML by leveraging failure to escape th
    /workdirs/scan-4ea278b2-4718-4de8-84ad-c9c675f18685/requirements.txt
    A package you depend on has a known security hole (CVE-2017-16876). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2017-80 mistune.py in Mistune 0.7.4 allows XSS via an unexpected newline (such as in java\nscript:) or a crafted email address, related to the escape and autolink functions.
    /workdirs/scan-4ea278b2-4718-4de8-84ad-c9c675f18685/requirements.txt
    A package you depend on has a known security hole (CVE-2017-15612). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-168 Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and realier, in src/mistune/directives/image.py, the render_figure() function concatenates figclass and figwidth options direct
    /workdirs/scan-4ea278b2-4718-4de8-84ad-c9c675f18685/requirements.txt
    A package you depend on has a known security hole (CVE-2026-44896). Fix: Update that package to its patched version.
… 65 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog timed out

Packages that look intentionally malicious: typosquats, sneaky install scripts.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Guarddog v2.10.0 · Apache-2.0

error: pypi:timeout

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.