Informational scan, not a security audit. How this is computed.
API keys, passwords or tokens committed into the repo.
Nothing found by this check. ✓
Packages you depend on that have known security holes (CVEs).
CVE-2023-47248 PyArrow: Arbitrary code execution when loading a malicious data fileCVE-2025-32434 PyTorch is a Python package that provides tensor computation with stro ...CVE-2023-6730 transformers has a Deserialization of Untrusted Data vulnerabilityCVE-2024-22195 jinja2: HTML attribute injection when passing user input as keys to xmlattr filterCVE-2024-34064 jinja2: accepts keys containing non-attribute charactersCVE-2024-56201 jinja2: Jinja has a sandbox breakout through malicious filenamesCVE-2024-56326 jinja2: Jinja has a sandbox breakout through indirect reference to format methodCVE-2025-27516 jinja2: Jinja sandbox breakout through attr filter selecting format methodCVE-2024-23334 aiohttp: follow_symlinks directory traversal vulnerabilityCVE-2024-30251 aiohttp: DoS when trying to parse malformed POST requestsCVE-2025-69223 aiohttp: AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bombCVE-2026-69244 aiohttp: AIOHTTP: Denial of Service via malformed HTTP responsesCVE-2023-37276 python-aiohttp: HTTP request smuggling via llhttp HTTP request parserCVE-2023-47627 python-aiohttp: numerous issues in HTTP parser with header parsingCVE-2023-49081 aiohttp: HTTP request modificationCVE-2023-49082 aiohttp: CRLF injection if user controls the HTTP method using aiohttp clientCVE-2024-23829 python-aiohttp: http request smugglingCVE-2024-27306 aiohttp: XSS on index pages for static file handlingCVE-2024-52304 aiohttp: aiohttp vulnerable to request smuggling due to incorrect parsing of chunk extensionsCVE-2025-69227 aiohttp: aiohttp: Denial of Service via specially crafted POST requestCVE-2025-69228 aiohttp: aiohttp: Denial of Service via memory exhaustion from crafted POST requestCVE-2025-69229 aiohttp: AIOHTTP: Denial of Service via excessive CPU usage in chunked message handlingCVE-2026-22815 aiohttp: AIOHTTP: Denial of Service via insufficient header/trailer handlingCVE-2026-34515 aiohttp: AIOHTTP: Information disclosure via static resource handler on WindowsCVE-2026-34516 aiohttp: AIOHTTP: Denial of Service via excessive multipart headersYour dependencies cross-checked against the OSV vulnerability database.
PYSEC-2026-2102 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in respPYSEC-2024-223 Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy.
PYSEC-2025-10 A vulnerability in the `download_model` function of the onnx/onnx framework, before and including version 1.16.1, allows for arbitrary file overwrite due to inadequate prevention of path traversal attPYSEC-2026-103 Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and including 1.20.1, a security control bypass exists in onnx.hub.load() due to impropPYSEC-2023-238 Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code execution. An application is vulnerable if it reads Arrow IPC, Feather or ParquePYSEC-2024-259 In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing.PYSEC-2025-41 PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command EPYSEC-2023-300 Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.PYSEC-2026-2290 A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The GHSA-vvj3-c3rp-c85p PHPUnit Vulnerable to Unsafe Deserialization in PHPT Code Coverage HandlingPYSEC-2026-1471 Jinja2 vulnerable to sandbox breakout through attr filter selecting format methodPYSEC-2026-1472 Jinja has a sandbox breakout through malicious filenamesPYSEC-2026-1473 Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filterPYSEC-2026-1474 Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filterPYSEC-2026-1475 Jinja has a sandbox breakout through indirect reference to format methodPYSEC-2023-120 aiohttp.web.Application vulnerable to HTTP request smuggling via llhttp HTTP request parserPYSEC-2023-246 aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. The HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling. This parserPYSEC-2023-250 aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation made it possible for an attacker to modify the HTTP request (e.g. to insert a new header) or create PYSEC-2023-251 aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Improper validation makes it possible for an attacker to modify the HTTP request (e.g. insert a new header) or even creaPYSEC-2024-24 aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static fiPYSEC-2024-26 aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, that must triPYSEC-2026-1098 aiohttp vulnerable to Denial of Service when trying to parse malformed POST requestsPYSEC-2026-1100 AIOHTTP vulnerable to denial of service through large payloadsPYSEC-2026-1101 AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bombPYSEC-2026-1102 aiohttp Cross-site Scripting vulnerability on index pages for static file handlingCode that can be exploited: injection, hardcoded credentials and similar.
Nothing found by this check. ✓
Packages that look intentionally malicious: typosquats, sneaky install scripts.
Nothing found by this check. ✓
A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.
Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.
This check didn’t finish — that’s not the same as “clean.” Try Check again above.