gitsafehub
github.com/lancelote/master_py_regex ↗

lancelote/master_py_regex

scanned 2026-08-12 · git 1d13891
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 5 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies60Known OSS vulnerabilities62Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks none found ✓

API keys, passwords or tokens committed into the repo.

Nothing found by this check. ✓

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 60 found · 1 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2015-8557 python-pygments: Shell injection in FontManager._get_nix_font_path
    requirements.txt
    A package you depend on has a known security hole (CVE-2015-8557). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-21699 IPython (Interactive Python) is a command shell for interactive comput ...
    requirements.txt
    A package you depend on has a known security hole (CVE-2022-21699). Fix: Update that package to its patched version.
  • Worth fixing CVE-2016-10745 python-jinja2: Sandbox escape due to information disclosure via str.format
    requirements.txt
    A package you depend on has a known security hole (CVE-2016-10745). Fix: Update that package to its patched version.
  • Worth fixing CVE-2019-10906 python-jinja2: str.format_map allows sandbox escape
    requirements.txt
    A package you depend on has a known security hole (CVE-2019-10906). Fix: Update that package to its patched version.
  • Worth fixing CVE-2020-28493 python-jinja2: ReDoS vulnerability in the urlize filter
    requirements.txt
    A package you depend on has a known security hole (CVE-2020-28493). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-22195 jinja2: HTML attribute injection when passing user input as keys to xmlattr filter
    requirements.txt
    A package you depend on has a known security hole (CVE-2024-22195). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-34064 jinja2: accepts keys containing non-attribute characters
    requirements.txt
    A package you depend on has a known security hole (CVE-2024-34064). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-56326 jinja2: Jinja has a sandbox breakout through indirect reference to format method
    requirements.txt
    A package you depend on has a known security hole (CVE-2024-56326). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-27516 jinja2: Jinja sandbox breakout through attr filter selecting format method
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-27516). Fix: Update that package to its patched version.
  • Worth fixing CVE-2022-39286 Jupyter Core is a package for the core common functionality of Jupyter ...
    requirements.txt
    A package you depend on has a known security hole (CVE-2022-39286). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-30167 Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-30167). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-49851 Mistune: Mistune: Denial of Service via crafted Markdown input
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-49851). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-59922 mistune: Mistune: Denial of Service via crafted input
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-59922). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-59925 mistune: Mistune: Denial of Service via crafted Markdown input
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-59925). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-59928 mistune: Mistune: Denial of Service via crafted Markdown document with reference-link definitions
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-59928). Fix: Update that package to its patched version.
  • Worth fixing CVE-2017-15612 mistune.py in Mistune 0.7.4 allows XSS via an unexpected newline (such ...
    requirements.txt
    A package you depend on has a known security hole (CVE-2017-15612). Fix: Update that package to its patched version.
  • Worth fixing CVE-2017-16876 Cross-site scripting (XSS) vulnerability in the _keyify function in mi ...
    requirements.txt
    A package you depend on has a known security hole (CVE-2017-16876). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-44896 mistune: Mistune: Cross-Site Scripting (XSS) via unescaped HTML attributes
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-44896). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-44897 mistune: Mistune: Cross-site scripting (XSS) via improper sanitization of HTML heading ID attribute
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-44897). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-59923 mistune: Mistune: Arbitrary code execution through crafted Markdown links
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-59923). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-59924 mistune: Mistune: Information disclosure via crafted include paths
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-59924). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-59926 mistune: Mistune: Cross-Site Scripting via unescaped HTML class attribute in Admonition directive
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-59926). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-59927 mistune: Mistune: Denial of Service via unbounded recursion in Markdown include directive
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-59927). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-59929 mistune: Mistune: Cross-site scripting via incomplete URL scheme filtering
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-59929). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-59930 mistune: Mistune: Same-page navigation redirection due to predictable heading IDs
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-59930). Fix: Update that package to its patched version.
… 35 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 62 found · 2 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious GHSA-hwvq-6gjx-j797 Special Element Injection in notebook
    /workdirs/scan-44960bee-6451-466b-affe-3c13504d2d6e/requirements.txt
    A package you depend on has a known security hole (CVE-2021-32798). Fix: Update that package to its patched version.
  • Serious PYSEC-2016-32 The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.
    /workdirs/scan-44960bee-6451-466b-affe-3c13504d2d6e/requirements.txt
    A package you depend on has a known security hole (CVE-2015-8557). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2022-12 IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to
    /workdirs/scan-44960bee-6451-466b-affe-3c13504d2d6e/requirements.txt
    A package you depend on has a known security hole (CVE-2022-21699). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2023-17 IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Versions prior to 8.1.0 are subje
    /workdirs/scan-44960bee-6451-466b-affe-3c13504d2d6e/requirements.txt
    A package you depend on has a known security hole (CVE-2023-24816). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2019-217 In Pallets Jinja before 2.10.1, str.format_map allows a sandbox escape.
    /workdirs/scan-44960bee-6451-466b-affe-3c13504d2d6e/requirements.txt
    A package you depend on has a known security hole (CVE-2019-10906). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2019-220 In Pallets Jinja before 2.8.1, str.format allows a sandbox escape.
    /workdirs/scan-44960bee-6451-466b-affe-3c13504d2d6e/requirements.txt
    A package you depend on has a known security hole (CVE-2016-10745). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2021-66 This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDoS vulnerability is mainly due to the `_punctuation_re regex` operator and its use of multiple wildcards. The last wildcard is the
    /workdirs/scan-44960bee-6451-466b-affe-3c13504d2d6e/requirements.txt
    A package you depend on has a known security hole (CVE-2020-28493). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1471 Jinja2 vulnerable to sandbox breakout through attr filter selecting format method
    /workdirs/scan-44960bee-6451-466b-affe-3c13504d2d6e/requirements.txt
    A package you depend on has a known security hole (CVE-2025-27516). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1473 Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
    /workdirs/scan-44960bee-6451-466b-affe-3c13504d2d6e/requirements.txt
    A package you depend on has a known security hole (CVE-2024-22195). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1474 Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
    /workdirs/scan-44960bee-6451-466b-affe-3c13504d2d6e/requirements.txt
    A package you depend on has a known security hole (CVE-2024-34064). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1475 Jinja has a sandbox breakout through indirect reference to format method
    /workdirs/scan-44960bee-6451-466b-affe-3c13504d2d6e/requirements.txt
    A package you depend on has a known security hole (CVE-2024-56326). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2022-42974 Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code execution vulnerability in `jupyter_core` that stems fr
    /workdirs/scan-44960bee-6451-466b-affe-3c13504d2d6e/requirements.txt
    A package you depend on has a known security hole (CVE-2022-39286). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1477 Jupyter Core on Windows Has Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
    /workdirs/scan-44960bee-6451-466b-affe-3c13504d2d6e/requirements.txt
    A package you depend on has a known security hole (CVE-2025-30167). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2017-18 Cross-site scripting (XSS) vulnerability in the _keyify function in mistune.py in Mistune before 0.8.1 allows remote attackers to inject arbitrary web script or HTML by leveraging failure to escape th
    /workdirs/scan-44960bee-6451-466b-affe-3c13504d2d6e/requirements.txt
    A package you depend on has a known security hole (CVE-2017-16876). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2017-80 mistune.py in Mistune 0.7.4 allows XSS via an unexpected newline (such as in java\nscript:) or a crafted email address, related to the escape and autolink functions.
    /workdirs/scan-44960bee-6451-466b-affe-3c13504d2d6e/requirements.txt
    A package you depend on has a known security hole (CVE-2017-15612). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-168 Mistune is a Python Markdown parser with renderers and plugins. In 3.2.0 and realier, in src/mistune/directives/image.py, the render_figure() function concatenates figclass and figwidth options direct
    /workdirs/scan-44960bee-6451-466b-affe-3c13504d2d6e/requirements.txt
    A package you depend on has a known security hole (CVE-2026-44896). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2206 Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the mistune math plugin renders inline math ($...$) and block math ($$...$$) by concatenating the raw user-supplied cont
    /workdirs/scan-44960bee-6451-466b-affe-3c13504d2d6e/requirements.txt
    A package you depend on has a known security hole (CVE-2026-44708). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2207 Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, HTMLRenderer.heading() builds the opening <hN> tag by string-concatenating the id attribute value directly into the HTML
    /workdirs/scan-44960bee-6451-466b-affe-3c13504d2d6e/requirements.txt
    A package you depend on has a known security hole (CVE-2026-44897). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2208 Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_toc_ul() builds a <ul> table-of-contents tree from a list of (level, id, text) tuples. Both the id value (used as
    /workdirs/scan-44960bee-6451-466b-affe-3c13504d2d6e/requirements.txt
    A package you depend on has a known security hole (CVE-2026-44898). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2209 Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the Image directive plugin validates the :width: and :height: options with a regex compiled as _num_re = re.compile(r"^\
    /workdirs/scan-44960bee-6451-466b-affe-3c13504d2d6e/requirements.txt
    A package you depend on has a known security hole (CVE-2026-44899). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2210 Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or caret marker pairs around a character causes quadratic work in src/mistune/plugin
    /workdirs/scan-44960bee-6451-466b-affe-3c13504d2d6e/requirements.txt
    A package you depend on has a known security hole (CVE-2026-59922). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2211 Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, HTMLRenderer.safe_url() does not block percent-encoded javascript URIs, allowing attacker-supplied Markdown links or ima
    /workdirs/scan-44960bee-6451-466b-affe-3c13504d2d6e/requirements.txt
    A package you depend on has a known security hole (CVE-2026-59923). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2212 Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Include.parse() joins and normalizes user-supplied include paths without verifying that the result remains within the in
    /workdirs/scan-44960bee-6451-466b-affe-3c13504d2d6e/requirements.txt
    A package you depend on has a known security hole (CVE-2026-59924). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2213 Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-asterisk or triple-asterisk emphasis pairs around a character cause quadratic work
    /workdirs/scan-44960bee-6451-466b-affe-3c13504d2d6e/requirements.txt
    A package you depend on has a known security hole (CVE-2026-59925). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2214 Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_admonition() in src/mistune/directives/admonition.py concatenates the Admonition directive :class: option into th
    /workdirs/scan-44960bee-6451-466b-affe-3c13504d2d6e/requirements.txt
    A package you depend on has a known security hole (CVE-2026-59926). Fix: Update that package to its patched version.
… 37 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.