Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2019-6446 numpy: crafted serialized object passed in numpy.load() in pickle python module allows arbitrary code executionCVE-2018-7575 Integer Overflow or Wraparound in Google TensorFlowCVE-2021-41208 Incomplete validation in boosted trees codeCVE-2023-25668 CVE-2023-25668 affecting package tensorflow for versions less than 2.11.1-1GHSA-h6gw-r52c-724r NULL Pointer Dereference and Access of Uninitialized Pointer in TensorFlowCVE-2025-69534 python-markdown: denial of service via malformed HTML-like sequencesCVE-2019-14322 Pallets Werkzeug vulnerable to Path TraversalCVE-2019-14806 python-werkzeug: insufficient debugger PIN randomness vulnerabilityCVE-2023-25577 python-werkzeug: high resource usage when parsing multipart form data with many fieldsCVE-2024-34069 python-werkzeug: user may execute code on a developer's machineCVE-2024-49766 werkzeug: python-werkzeug: Werkzeug safe_join not safe on WindowsCVE-2025-66221 Werkzeug: Werkzeug: Denial of service via Windows device names in path segmentsCVE-2026-21860 Werkzeug safe_join() allows Windows special device names with compound extensionsCVE-2026-27199 Werkzeug safe_join() allows Windows special device namesCVE-2020-6817 bleach.clean behavior parsing style attributes could result in a regul ...CVE-2020-6802 In Mozilla Bleach before 3.11, a mutation XSS affects users calling bl ...CVE-2020-6816 In Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCD ...CVE-2021-23980 python-bleach: Mutation cross-site scripting in bleach.cleanGHSA-gj48-438w-jh9v Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributesCVE-2023-33953 gRPC: hpack table accounting errors can lead to denial of serviceCVE-2016-9909 The serializer in html5lib before 0.99999999 might allow remote attack ...CVE-2016-9910 The serializer in html5lib before 0.99999999 might allow remote attack ...CVE-2021-41495 numpy: NULL pointer dereference in numpy.sort in in the PyArray_DescrNew() due to missing return-value validationCVE-2021-33430 numpy: buffer overflow in the PyArray_NewFromDescr_int() in ctors.cCVE-2021-34141 numpy: incomplete string comparison in the numpy.core componentYour dependencies cross-checked against the OSV vulnerability database.
PYSEC-2019-108 ** DISPUTED ** An issue was discovered in NumPy 1.16.0 and earlier. It uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized objectPYSEC-2019-205 Google TensorFlow 1.7.x and earlier is affected by a Buffer Overflow vulnerability. The type of exploitation is context-dependent.PYSEC-2020-125 In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `Shard` API in TensorFlow expects the last argument to be a function taking two `int64` (i.e., `long long`) arguments. However,PYSEC-2020-128 In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `data_splits` argument of `tf.raw_ops.StringNGrams` lacks validation. This allows a user to pass values that can cause heap ovePYSEC-2020-129 In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, changing the TensorFlow's `SavedModel` protocol buffer and altering the name of required keys results in segfaults and data corruptPYSEC-2021-400 TensorFlow is an open source platform for machine learning. In affected versions the code for boosted trees in TensorFlow is still missing validation. As a result, attackers can trigger denial of servPYSEC-2026-548 TensorFlow has a heap out-of-buffer read vulnerability in the QuantizeAndDequantize operationGHSA-h6gw-r52c-724r NULL Pointer Dereference and Access of Uninitialized Pointer in TensorFlowGHSA-r6jx-9g48-2r5r Arbitrary code execution due to YAML deserializationPYSEC-2026-89 Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-MaPYSEC-2019-140 Pallets Werkzeug before 0.15.3, when used with Docker, has insufficient debugger PIN randomness because Docker containers share the same machine id.PYSEC-2023-221 Werkzeug is a comprehensive WSGI web application library. If an upload of a file that starts with CR or LF and then is followed by megabytes of data without these characters: all of these bytes are apPYSEC-2023-58 Werkzeug is a comprehensive WSGI web application library. Prior to version 2.2.3, Werkzeug's multipart form data parser will parse an unlimited number of parts, including file parts. Parts can be a smPYSEC-2026-1065 Pallets Werkzeug vulnerable to Path TraversalPYSEC-2026-2043 Werkzeug debugger vulnerable to remote execution when interacting with attacker controlled domainPYSEC-2026-2044 Werkzeug safe_join() allows Windows special device names with compound extensionsPYSEC-2026-2045 Werkzeug safe_join not safe on WindowsPYSEC-2026-2046 Werkzeug safe_join() allows Windows special device namesPYSEC-2026-2320 Werkzeug is a comprehensive WSGI web application library. Versions 3.1.5 and below, the safe_join function allows Windows device names as filenames if preceded by other path segments. This was previouPYSEC-2020-27 In Mozilla Bleach before 3.11, a mutation XSS affects users calling bleach.clean with noscript and a raw tag in the allowed/whitelisted tags option.PYSEC-2020-28 In Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCDATA and either svg or math tags are whitelisted and the keyword argument strip=False.PYSEC-2020-340 In Mozilla Bleach before 3.1.4, `bleach.clean` behavior parsing style attributes could result in a regular expression denial of service (ReDoS).PYSEC-2021-865 In Mozilla Bleach before 3.3.0, a mutation XSS affects users calling bleach.clean with math or svg; p or br; and style, title, noscript, script, textarea, noframes, iframe, or xmp tags with strip_commGHSA-gj48-438w-jh9v Bleach clean() / Cleaner() fails to sanitize dangerous URI schemes in allowed formaction attributesPYSEC-2026-1424 Excessive Iteration in gRPCCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.