gitsafehub
github.com/johnzja/neural_rx ↗

johnzja/neural_rx

scanned 2026-08-13 · git b22b9ce
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 3 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies9Known OSS vulnerabilities44Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks timed out

API keys, passwords or tokens committed into the repo.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Gitleaks v8.21.2 · MIT

error: timeout after 400s

Vulnerable dependencies — Trivy 9 found

Packages you depend on that have known security holes (CVEs).

  • Worth fixing CVE-2024-7776 A vulnerability in the `download_model` function of the onnx/onnx fram ...
    requirements.txt
    A package you depend on has a known security hole (CVE-2024-7776). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-27489 onnx: ONNX: Information Disclosure via Path Traversal Vulnerability
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-27489). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-28500 onnx: ONNX: Untrusted Model Repository Warnings Suppressed
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-28500). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-34445 ONNX: ONNX: Denial of Service and potential information disclosure via malicious model metadata
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-34445). Fix: Update that package to its patched version.
  • Worth fixing GHSA-q56x-g2fj-4rj6 ONNX: TOCTOU arbitrary file read/write in save_external_dat
    requirements.txt
    A package you depend on has a known security hole (GHSA-q56x-g2fj-4rj6). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-34446 onnx: ONNX: Information disclosure through hardlink path traversal
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-34446). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-34447 Open Neural Network Exchange (ONNX) is an open standard for machine le ...
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-34447). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-44512 onnx: ONNX: Denial of Service via crafted untrusted models
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-44512). Fix: Update that package to its patched version.
  • Minor CVE-2026-63632 ONNX: Heap-Buffer-Overflow READ in Gemm Version Converter Adapter via Undersized Input Shape
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-63632). Fix: Update that package to its patched version.

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 44 found · 3 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious PYSEC-2026-103 Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and including 1.20.1, a security control bypass exists in onnx.hub.load() due to improp
    /workdirs/scan-19dacede-0fc7-4fe6-bdc9-0ca0a371e6f8/requirements.txt
    A package you depend on has a known security hole (CVE-2026-28500). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-1486 Keras Directory Traversal Vulnerability
    /workdirs/scan-19dacede-0fc7-4fe6-bdc9-0ca0a371e6f8/requirements.txt
    A package you depend on has a known security hole (CVE-2025-12060). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-457 Arbitrary Code Execution in Pillow
    /workdirs/scan-19dacede-0fc7-4fe6-bdc9-0ca0a371e6f8/requirements.txt
    A package you depend on has a known security hole (CVE-2023-50447). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2025-148 Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted external_data.location paths containing t
    /workdirs/scan-19dacede-0fc7-4fe6-bdc9-0ca0a371e6f8/requirements.txt
    A package you depend on has a known security hole (CVE-2024-5187). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-104 Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is a symlink traversal vulnerability in external data loading allows readi
    /workdirs/scan-19dacede-0fc7-4fe6-bdc9-0ca0a371e6f8/requirements.txt
    A package you depend on has a known security hole (CVE-2026-34447). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2239 Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, a path traversal vulnerability via symlink allows to read arbitrary files outsid
    /workdirs/scan-19dacede-0fc7-4fe6-bdc9-0ca0a371e6f8/requirements.txt
    A package you depend on has a known security hole (CVE-2026-27489). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2240 Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was using Python’s setattr() function to load
    /workdirs/scan-19dacede-0fc7-4fe6-bdc9-0ca0a371e6f8/requirements.txt
    A package you depend on has a known security hole (CVE-2026-34445). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2241 Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is an issue in onnx.load, the code checks for symlinks to prevent path tra
    /workdirs/scan-19dacede-0fc7-4fe6-bdc9-0ca0a371e6f8/requirements.txt
    A package you depend on has a known security hole (CVE-2026-34446). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2689 ONNX has Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)
    /workdirs/scan-19dacede-0fc7-4fe6-bdc9-0ca0a371e6f8/requirements.txt
    A package you depend on has a known security hole (CVE-2026-44512). Fix: Update that package to its patched version.
  • Worth fixing GHSA-h36j-8vv3-cj52 Open Neural Network Exchange (ONNX) Path Traversal Vulnerability
    /workdirs/scan-19dacede-0fc7-4fe6-bdc9-0ca0a371e6f8/requirements.txt
    A package you depend on has a known security hole (CVE-2024-7776). Fix: Update that package to its patched version.
  • Worth fixing GHSA-q56x-g2fj-4rj6 ONNX: TOCTOU arbitrary file read/write in save_external_dat
    /workdirs/scan-19dacede-0fc7-4fe6-bdc9-0ca0a371e6f8/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-215 Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior
    /workdirs/scan-19dacede-0fc7-4fe6-bdc9-0ca0a371e6f8/requirements.txt
    A package you depend on has a known security hole (CVE-2026-45409). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2025-121 An issue in keras 3.7.0 allows attackers to write arbitrary files to the user's machine via downloading a crafted tar file through the get_file function.
    /workdirs/scan-19dacede-0fc7-4fe6-bdc9-0ca0a371e6f8/requirements.txt
    A package you depend on has a known security hole (CVE-2024-55459). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1487 Keras is vulnerable to arbitrary local file loading and Server-Side Request Forgery
    /workdirs/scan-19dacede-0fc7-4fe6-bdc9-0ca0a371e6f8/requirements.txt
    A package you depend on has a known security hole (CVE-2025-12058). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2324 Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/file_utils.py`. The functions `filter_safe_tarinfos()` and `filt
    /workdirs/scan-19dacede-0fc7-4fe6-bdc9-0ca0a371e6f8/requirements.txt
    A package you depend on has a known security hole (CVE-2026-11816). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2547 Keras has an untrusted deserialization vulnerability
    /workdirs/scan-19dacede-0fc7-4fe6-bdc9-0ca0a371e6f8/requirements.txt
    A package you depend on has a known security hole (CVE-2026-1462). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-3629 Keras: HDF5 virtual datasets can disclose local files
    /workdirs/scan-19dacede-0fc7-4fe6-bdc9-0ca0a371e6f8/requirements.txt
    A package you depend on has a known security hole (CVE-2026-12480). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-3631 Keras: Lambda deserialization can bypass safe mode and execute code
    /workdirs/scan-19dacede-0fc7-4fe6-bdc9-0ca0a371e6f8/requirements.txt
    A package you depend on has a known security hole (CVE-2026-12481). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-3632 Keras: DiskIOStore permits path traversal through crafted layer names
    /workdirs/scan-19dacede-0fc7-4fe6-bdc9-0ca0a371e6f8/requirements.txt
    A package you depend on has a known security hole (CVE-2026-12479). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-3633 Keras: HDF5 links can disclose local file contents
    /workdirs/scan-19dacede-0fc7-4fe6-bdc9-0ca0a371e6f8/requirements.txt
    A package you depend on has a known security hole (CVE-2026-9335). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-3634 Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data
    /workdirs/scan-19dacede-0fc7-4fe6-bdc9-0ca0a371e6f8/requirements.txt
    A package you depend on has a known security hole (CVE-2026-12484). Fix: Update that package to its patched version.
  • Worth fixing GHSA-36fq-jgmw-4r9c Keras is vulnerable to Deserialization of Untrusted Data
    /workdirs/scan-19dacede-0fc7-4fe6-bdc9-0ca0a371e6f8/requirements.txt
    A package you depend on has a known security hole (CVE-2025-9906). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2023-227 An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of
    /workdirs/scan-19dacede-0fc7-4fe6-bdc9-0ca0a371e6f8/requirements.txt
    A package you depend on has a known security hole (CVE-2023-44271). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-165 Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer
    /workdirs/scan-19dacede-0fc7-4fe6-bdc9-0ca0a371e6f8/requirements.txt
    A package you depend on has a known security hole (CVE-2026-42308). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1793 Pillow buffer overflow vulnerability
    /workdirs/scan-19dacede-0fc7-4fe6-bdc9-0ca0a371e6f8/requirements.txt
    A package you depend on has a known security hole (CVE-2024-28219). Fix: Update that package to its patched version.
… 19 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog timed out

Packages that look intentionally malicious: typosquats, sneaky install scripts.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Guarddog v2.10.0 · Apache-2.0

error: pypi:timeout

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.