gitsafehub
github.com/nvlabs/compass ↗

nvlabs/compass

scanned 2026-07-15 · git 8060f7c
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 5 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies13Known OSS vulnerabilities17Risky code patternsMalicious dependenciesProject health9

Security checks

Leaked secrets — Gitleaks none found ✓

API keys, passwords or tokens committed into the repo.

Nothing found by this check. ✓

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 13 found

Packages you depend on that have known security holes (CVEs).

  • Worth fixing CVE-2026-44513 Diffusers: Diffusers: Arbitrary remote code execution via `trust_remote_code` bypass
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-44513). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-45804 Diffusers: TOCTOU Trust Remote Code Bypass
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-45804). Fix: Update that package to its patched version.
  • Worth fixing GHSA-6v7p-g79w-8964 MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error
    requirements.txt
    A package you depend on has a known security hole (GHSA-6v7p-g79w-8964). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-27489 onnx: ONNX: Information Disclosure via Path Traversal Vulnerability
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-27489). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-28500 onnx: ONNX: Untrusted Model Repository Warnings Suppressed
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-28500). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-34445 ONNX: ONNX: Denial of Service and potential information disclosure via malicious model metadata
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-34445). Fix: Update that package to its patched version.
  • Worth fixing GHSA-q56x-g2fj-4rj6 ONNX: TOCTOU arbitrary file read/write in save_external_dat
    requirements.txt
    A package you depend on has a known security hole (GHSA-q56x-g2fj-4rj6). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-34446 onnx: ONNX: Information disclosure through hardlink path traversal
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-34446). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-34447 Open Neural Network Exchange (ONNX) is an open standard for machine le ...
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-34447). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-44512 onnx: ONNX: Denial of Service via crafted untrusted models
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-44512). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-4372 HuggingFace transformers vulnerable to remote code execution
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-4372). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-5241 python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code setting
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-5241). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-1839 transformers: HuggingFace Transformers: Arbitrary code execution via malicious checkpoint file
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-1839). Fix: Update that package to its patched version.

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 17 found · 3 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious PYSEC-2026-348 h11 accepts some malformed Chunked-Encoding bodies
    /workdirs/scan-b17a3fa2-94fc-47e2-9b19-91b91ad61cfc/docs/handbook/requirements.txt
    A package you depend on has a known security hole (CVE-2025-43859). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-103 Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and including 1.20.1, a security control bypass exists in onnx.hub.load() due to improp
    /workdirs/scan-b17a3fa2-94fc-47e2-9b19-91b91ad61cfc/requirements.txt
    A package you depend on has a known security hole (CVE-2026-28500). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-2290 A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The
    /workdirs/scan-b17a3fa2-94fc-47e2-9b19-91b91ad61cfc/requirements.txt
    A package you depend on has a known security hole (CVE-2026-5241). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-215 Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior
    /workdirs/scan-b17a3fa2-94fc-47e2-9b19-91b91ad61cfc/docs/handbook/requirements.txt
    A package you depend on has a known security hole (CVE-2026-45409). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2446 Diffusers: TOCTOU Trust Remote Code Bypass
    /workdirs/scan-b17a3fa2-94fc-47e2-9b19-91b91ad61cfc/requirements.txt
    A package you depend on has a known security hole (CVE-2026-45804). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-40 Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows arbitrary remote code execution despite the user pa
    /workdirs/scan-b17a3fa2-94fc-47e2-9b19-91b91ad61cfc/requirements.txt
    A package you depend on has a known security hole (CVE-2026-44513). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-41 Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, diffusers 0.37.0 allows remote code execution without the trust_remote_code=True safeguard when loading pipelines from Hug
    /workdirs/scan-b17a3fa2-94fc-47e2-9b19-91b91ad61cfc/requirements.txt
    A package you depend on has a known security hole (CVE-2026-44827). Fix: Update that package to its patched version.
  • Worth fixing GHSA-6v7p-g79w-8964 MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error
    /workdirs/scan-b17a3fa2-94fc-47e2-9b19-91b91ad61cfc/requirements.txt
    A package you depend on has a known security hole (CVE-2026-57585). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-104 Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is a symlink traversal vulnerability in external data loading allows readi
    /workdirs/scan-b17a3fa2-94fc-47e2-9b19-91b91ad61cfc/requirements.txt
    A package you depend on has a known security hole (CVE-2026-34447). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2239 Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, a path traversal vulnerability via symlink allows to read arbitrary files outsid
    /workdirs/scan-b17a3fa2-94fc-47e2-9b19-91b91ad61cfc/requirements.txt
    A package you depend on has a known security hole (CVE-2026-27489). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2240 Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was using Python’s setattr() function to load
    /workdirs/scan-b17a3fa2-94fc-47e2-9b19-91b91ad61cfc/requirements.txt
    A package you depend on has a known security hole (CVE-2026-34445). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2241 Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is an issue in onnx.load, the code checks for symlinks to prevent path tra
    /workdirs/scan-b17a3fa2-94fc-47e2-9b19-91b91ad61cfc/requirements.txt
    A package you depend on has a known security hole (CVE-2026-34446). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2689 ONNX has Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)
    /workdirs/scan-b17a3fa2-94fc-47e2-9b19-91b91ad61cfc/requirements.txt
    A package you depend on has a known security hole (CVE-2026-44512). Fix: Update that package to its patched version.
  • Worth fixing GHSA-q56x-g2fj-4rj6 ONNX: TOCTOU arbitrary file read/write in save_external_dat
    /workdirs/scan-b17a3fa2-94fc-47e2-9b19-91b91ad61cfc/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2025-217 Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on af
    /workdirs/scan-b17a3fa2-94fc-47e2-9b19-91b91ad61cfc/requirements.txt
    A package you depend on has a known security hole (CVE-2025-14929). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2288 A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_state()` method in `src/transformers/trainer.py` at li
    /workdirs/scan-b17a3fa2-94fc-47e2-9b19-91b91ad61cfc/requirements.txt
    A package you depend on has a known security hole (CVE-2026-1839). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2289 A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config.
    /workdirs/scan-b17a3fa2-94fc-47e2-9b19-91b91ad61cfc/requirements.txt
    A package you depend on has a known security hole (CVE-2026-4372). Fix: Update that package to its patched version.

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog timed out

Packages that look intentionally malicious: typosquats, sneaky install scripts.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Guarddog v2.10.0 · Apache-2.0

error: pypi:timeout

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard 9 notes

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

  • Worth fixing scorecard-overall OpenSSF Scorecard overall: 3.6/10
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-CII-Best-Practices CII-Best-Practices scored 0: no effort to earn an OpenSSF best practices badge detected
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Code-Review Code-Review scored 0: Found 0/12 approved changesets -- score normalized to 0
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Dependency-Update-Tool Dependency-Update-Tool scored 0: no update tool detected
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Fuzzing Fuzzing scored 0: project is not fuzzed
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Pinned-Dependencies Pinned-Dependencies scored 0: dependency not pinned by hash detected -- score normalized to 0
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-SAST SAST scored 0: SAST tool is not run on all commits -- score normalized to 0
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Security-Policy Security-Policy scored 0: security policy file not detected
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.
  • Minor scorecard-Token-Permissions Token-Permissions scored 0: detected GitHub workflow tokens with excessive permissions
    A project-health signal (maintenance / supply-chain hygiene), not a vulnerability in your code.

via OpenSSF Scorecard v5.5.0 · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.