Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.Packages you depend on that have known security holes (CVEs).
CVE-2017-18342 PyYAML: yaml.load() API could execute arbitrary codeCVE-2020-14343 PyYAML: incomplete fix for CVE-2020-1747CVE-2021-42771 python-babel: Relative path traversal allows attacker to load arbitrary locale files and execute arbitrary codeCVE-2018-1000656 python-flask: Denial of Service via crafted JSON fileCVE-2019-1010083 python-flask: unexpected memory usage can lead to denial of service via crafted encoded JSON dataCVE-2023-30861 flask: Possible disclosure of permanent session cookie due to missing Vary: Cookie headerCVE-2014-1402 python-jinja2: FileSystemBytecodeCache insecure cache temporary file useCVE-2016-10745 python-jinja2: Sandbox escape due to information disclosure via str.formatCVE-2019-10906 python-jinja2: str.format_map allows sandbox escapeCVE-2014-0012 python-jinja2: FileSystemBytecodeCache insecure cache temporary file use, incorrect CVE-2014-1402 fixCVE-2020-28493 python-jinja2: ReDoS vulnerability in the urlize filterCVE-2024-22195 jinja2: HTML attribute injection when passing user input as keys to xmlattr filterCVE-2024-34064 jinja2: accepts keys containing non-attribute charactersCVE-2024-56326 jinja2: Jinja has a sandbox breakout through indirect reference to format methodCVE-2025-27516 jinja2: Jinja sandbox breakout through attr filter selecting format methodCVE-2019-14322 Pallets Werkzeug vulnerable to Path TraversalCVE-2019-14806 python-werkzeug: insufficient debugger PIN randomness vulnerabilityCVE-2023-25577 python-werkzeug: high resource usage when parsing multipart form data with many fieldsCVE-2024-34069 python-werkzeug: user may execute code on a developer's machineCVE-2016-10516 python-werkzeug: Cross-site scripting in render_full function in debug/tbtools.pyCVE-2020-28724 python-werkzeug: open redirect via double slash in the URLCVE-2024-49766 werkzeug: python-werkzeug: Werkzeug safe_join not safe on WindowsCVE-2025-66221 Werkzeug: Werkzeug: Denial of service via Windows device names in path segmentsCVE-2026-21860 Werkzeug safe_join() allows Windows special device names with compound extensionsCVE-2026-27199 Werkzeug safe_join() allows Windows special device namesYour dependencies cross-checked against the OSV vulnerability database.
PYSEC-2018-49 In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load() function has been deprecated in version 5.1 and the 'UnsafeLoader' has been introduced foPYSEC-2021-142 A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or PYSEC-2021-421 Babel.Locale in Babel before 2.9.1 allows attackers to load arbitrary locale .dat files (containing serialized Python objects) via directory traversal, leading to code execution.PYSEC-2018-66 The Pallets Project flask version Before 0.12.3 contains a CWE-20: Improper Input Validation vulnerability in flask that can result in Large amount of memory usage possibly leading to denial of servicPYSEC-2019-179 The Pallets Project Flask before 1.0 is affected by: unexpected memory usage. The impact is: denial of service. The attack vector is: crafted encoded JSON data. The fixed version is: 1. NOTE: this mayPYSEC-2023-62 Flask is a lightweight WSGI web application framework. When all of the following conditions are met, a response containing data intended for one client may be cached and subsequently sent by the proxyPYSEC-2026-2151 Flask is a web server gateway interface (WSGI) web application framework. In versions 3.1.2 and below, when the session object is accessed, Flask should set the Vary: Cookie header., resulting in a UsPYSEC-2014-8 The default configuration for bccache.FileSystemBytecodeCache in Jinja2 before 2.7.2 does not properly create temporary files, which allows local users to gain privileges via a crafted .cache file witPYSEC-2014-82 FileSystemBytecodeCache in Jinja2 2.7.2 does not properly create temporary directories, which allows local users to gain privileges by pre-creating a temporary directory with a user's uid. NOTE: thisPYSEC-2019-217 In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.PYSEC-2019-220 In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.PYSEC-2021-66 This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the PYSEC-2026-1471 Jinja2 vulnerable to sandbox breakout through attr filter selecting format methodPYSEC-2026-1473 Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filterPYSEC-2026-1474 Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filterPYSEC-2026-1475 Jinja has a sandbox breakout through indirect reference to format methodPYSEC-2017-43 Cross-site scripting (XSS) vulnerability in the render_full function in debug/tbtools.py in the debugger in Pallets Werkzeug before 0.11.11 (as used in Pallets Flask and other products) allows remote PYSEC-2019-140 Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same machine id.PYSEC-2020-157 Open redirect vulnerability in werkzeug before 0.11.6 via a double slash in the URL.PYSEC-2023-221 Werkzeug is a comprehensive WSGI web application library. If an upload of a file that starts with CR or LF and then is followed by megabytes of data without these characters: all of these bytes are apPYSEC-2023-58 Werkzeug is a comprehensive WSGI web application library. Prior to version 2.2.3, Werkzeug's multipart form data parser will parse an unlimited number of parts, including file parts. Parts can be a smPYSEC-2026-1065 Pallets Werkzeug vulnerable to Path TraversalPYSEC-2026-2043 Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domainPYSEC-2026-2044 Werkzeug safe_join() allows Windows special device names with compound extensionsPYSEC-2026-2045 Werkzeug safe_join not safe on WindowsCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.