🧬 Known OSS vulnerabilities — OSV-Scannerⓘ4 found · 4 serious
Your dependencies cross-checked against the OSV vulnerability database.
SeriousPYSEC-2020-96 A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method o
A package you depend on has a known security hole (CVE-2020-1747). Fix: Update that package to its patched version.
SeriousPYSEC-2021-142 A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or
A package you depend on has a known security hole (CVE-2020-14343). Fix: Update that package to its patched version.
SeriousPYSEC-2020-96 A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method o
A package you depend on has a known security hole (CVE-2020-1747). Fix: Update that package to its patched version.
SeriousPYSEC-2021-142 A vulnerability was discovered in the PyYAML library in versions before 5.4, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or
About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.