gitsafehub
github.com/piesposito/tand ↗

piesposito/tand

scanned 2026-08-14 · git 3d46031
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 4 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies277Known OSS vulnerabilities556Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks none found ✓

API keys, passwords or tokens committed into the repo.

Nothing found by this check. ✓

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 277 found · 86 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2023-1177 mlflow is vulnerable to remote file access in `mlflow server` and `mlflow ui` CLIs
    requirements.txt
    A package you depend on has a known security hole (CVE-2023-1177). Fix: Update that package to its patched version.
  • Serious CVE-2023-2780 mlflow Path Traversal vulnerability
    requirements.txt
    A package you depend on has a known security hole (CVE-2023-2780). Fix: Update that package to its patched version.
  • Serious CVE-2023-3765 MLflow Path Traversal vulnerability
    requirements.txt
    A package you depend on has a known security hole (CVE-2023-3765). Fix: Update that package to its patched version.
  • Serious CVE-2023-6014 MLflow authentication requirement bypass can allow a user to arbitrarily create an account
    requirements.txt
    A package you depend on has a known security hole (CVE-2023-6014). Fix: Update that package to its patched version.
  • Serious CVE-2023-6015 MLflow allowed arbitrary files to be PUT onto the server
    requirements.txt
    A package you depend on has a known security hole (CVE-2023-6015). Fix: Update that package to its patched version.
  • Serious CVE-2023-6018 Remote Code Execution due to Full Controled File Write in mlflow
    requirements.txt
    A package you depend on has a known security hole (CVE-2023-6018). Fix: Update that package to its patched version.
  • Serious CVE-2023-6831 Path traversal in MLflow
    requirements.txt
    A package you depend on has a known security hole (CVE-2023-6831). Fix: Update that package to its patched version.
  • Serious CVE-2023-6974 MLflow Server-Side Request Forgery (SSRF)
    requirements.txt
    A package you depend on has a known security hole (CVE-2023-6974). Fix: Update that package to its patched version.
  • Serious CVE-2023-6975 MLFlow Path Traversal Vulnerability
    requirements.txt
    A package you depend on has a known security hole (CVE-2023-6975). Fix: Update that package to its patched version.
  • Serious CVE-2024-0520 Remote code execution in mlflow
    requirements.txt
    A package you depend on has a known security hole (CVE-2024-0520). Fix: Update that package to its patched version.
  • Serious CVE-2024-27132 Cross-site Scripting in MLFlow
    requirements.txt
    A package you depend on has a known security hole (CVE-2024-27132). Fix: Update that package to its patched version.
  • Serious CVE-2024-27133 MLFlow Cross-site Scripting vulnerability leads to client-side Remote Code Execution
    requirements.txt
    A package you depend on has a known security hole (CVE-2024-27133). Fix: Update that package to its patched version.
  • Serious CVE-2024-3573 mlflow vulnerable to Path Traversal
    requirements.txt
    A package you depend on has a known security hole (CVE-2024-3573). Fix: Update that package to its patched version.
  • Serious CVE-2025-15036 mlflow: mlflow: Path traversal vulnerability allows arbitrary file overwrite and privilege escalation
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-15036). Fix: Update that package to its patched version.
  • Serious CVE-2025-15379 mlflow: MLflow: Arbitrary command execution via command injection in model serving container initialization.
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-15379). Fix: Update that package to its patched version.
  • Serious CVE-2026-0596 Mlflow: Command Injection when serving models with enable_mlserver=True
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-0596). Fix: Update that package to its patched version.
  • Serious CVE-2026-2635 mlflow: MLflow Use of Default Password Authentication Bypass Vulnerability
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-2635). Fix: Update that package to its patched version.
  • Serious CVE-2026-2651 github.com/mlflow/mlflow: MLflow: Arbitrary code execution via unauthorized multipart upload access
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-2651). Fix: Update that package to its patched version.
  • Serious CVE-2026-4035 python-mlflow: MLflow: Sensitive credential exfiltration via environment variable resolution in AI Gateway secrets
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-4035). Fix: Update that package to its patched version.
  • Serious GHSA-83fm-w79m-64r5 Remote file access vulnerability in `mlflow server` and `mlflow ui` CLIs
    requirements.txt
    A package you depend on has a known security hole (GHSA-83fm-w79m-64r5). Fix: Update that package to its patched version.
  • Serious CVE-2022-45907 In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line c ...
    requirements.txt
    A package you depend on has a known security hole (CVE-2022-45907). Fix: Update that package to its patched version.
  • Serious CVE-2025-32434 PyTorch is a Python package that provides tensor computation with stro ...
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-32434). Fix: Update that package to its patched version.
  • Serious CVE-2023-1177 mlflow is vulnerable to remote file access in `mlflow server` and `mlflow ui` CLIs
    tand/structured_data/classification/pytorch/project_template/requirements.txt
    A package you depend on has a known security hole (CVE-2023-1177). Fix: Update that package to its patched version.
  • Serious CVE-2023-2780 mlflow Path Traversal vulnerability
    tand/structured_data/classification/pytorch/project_template/requirements.txt
    A package you depend on has a known security hole (CVE-2023-2780). Fix: Update that package to its patched version.
  • Serious CVE-2023-3765 MLflow Path Traversal vulnerability
    tand/structured_data/classification/pytorch/project_template/requirements.txt
    A package you depend on has a known security hole (CVE-2023-3765). Fix: Update that package to its patched version.
… 252 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 556 found · 116 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious PYSEC-2023-253 Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.9.2.
    /workdirs/scan-309c2336-0618-4342-8e51-3787e8a23458/requirements.txt
    A package you depend on has a known security hole (CVE-2023-6831). Fix: Update that package to its patched version.
  • Serious PYSEC-2023-29 Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.2.1.
    /workdirs/scan-309c2336-0618-4342-8e51-3787e8a23458/requirements.txt
    A package you depend on has a known security hole (CVE-2023-1177). Fix: Update that package to its patched version.
  • Serious PYSEC-2023-308 Absolute Path Traversal in GitHub repository mlflow/mlflow prior to 2.5.0.
    /workdirs/scan-309c2336-0618-4342-8e51-3787e8a23458/requirements.txt
    A package you depend on has a known security hole (CVE-2023-3765). Fix: Update that package to its patched version.
  • Serious PYSEC-2023-68 Relative Path Traversal in GitHub repository mlflow/mlflow prior to 2.3.1.
    /workdirs/scan-309c2336-0618-4342-8e51-3787e8a23458/requirements.txt
    A package you depend on has a known security hole (CVE-2023-2356). Fix: Update that package to its patched version.
  • Serious PYSEC-2023-69 Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.3.1.
    /workdirs/scan-309c2336-0618-4342-8e51-3787e8a23458/requirements.txt
    A package you depend on has a known security hole (CVE-2023-2780). Fix: Update that package to its patched version.
  • Serious PYSEC-2024-239 A vulnerability in mlflow/mlflow version 8.2.1 allows for remote code execution due to improper neutralization of special elements used in an OS command ('Command Injection') within the `mlflow.data.h
    /workdirs/scan-309c2336-0618-4342-8e51-3787e8a23458/requirements.txt
    A package you depend on has a known security hole (CVE-2024-0520). Fix: Update that package to its patched version.
  • Serious PYSEC-2024-240 Insufficient sanitization in MLflow leads to XSS when running an untrusted recipe. This issue leads to a client-side RCE when running an untrusted recipe in Jupyter Notebook. The vulnerability stems
    /workdirs/scan-309c2336-0618-4342-8e51-3787e8a23458/requirements.txt
    A package you depend on has a known security hole (CVE-2024-27132). Fix: Update that package to its patched version.
  • Serious PYSEC-2024-241 Insufficient sanitization in MLflow leads to XSS when running a recipe that uses an untrusted dataset. This issue leads to a client-side RCE when running the recipe in Jupyter Notebook. The vulnerabil
    /workdirs/scan-309c2336-0618-4342-8e51-3787e8a23458/requirements.txt
    A package you depend on has a known security hole (CVE-2024-27133). Fix: Update that package to its patched version.
  • Serious PYSEC-2024-243 mlflow/mlflow is vulnerable to Local File Inclusion (LFI) due to improper parsing of URIs, allowing attackers to bypass checks and read arbitrary files on the system. The issue arises from the 'is_loc
    /workdirs/scan-309c2336-0618-4342-8e51-3787e8a23458/requirements.txt
    A package you depend on has a known security hole (CVE-2024-3573). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-2220 A vulnerability in MLflow versions <=3.10.1.dev0 allows unauthorized access to multipart upload (MPU) endpoints when the `--serve-artifacts` mode is enabled. The authorization logic does not enforce r
    /workdirs/scan-309c2336-0618-4342-8e51-3787e8a23458/requirements.txt
    A package you depend on has a known security hole (CVE-2026-2651). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-2222 A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gateway secrets, which can be exploited to exfiltrate sensitive server-side environme
    /workdirs/scan-309c2336-0618-4342-8e51-3787e8a23458/requirements.txt
    A package you depend on has a known security hole (CVE-2026-4035). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-415 MLflow authentication requirement bypass can allow a user to arbitrarily create an account
    /workdirs/scan-309c2336-0618-4342-8e51-3787e8a23458/requirements.txt
    A package you depend on has a known security hole (CVE-2023-6014). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-416 MLflow Server-Side Request Forgery (SSRF)
    /workdirs/scan-309c2336-0618-4342-8e51-3787e8a23458/requirements.txt
    A package you depend on has a known security hole (CVE-2023-6974). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-417 Remote Code Execution due to Full Controled File Write in mlflow
    /workdirs/scan-309c2336-0618-4342-8e51-3787e8a23458/requirements.txt
    A package you depend on has a known security hole (CVE-2023-6018). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-419 mlflow: FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization
    /workdirs/scan-309c2336-0618-4342-8e51-3787e8a23458/requirements.txt
    A package you depend on has a known security hole (CVE-2026-0545). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-420 MLflow allowed arbitrary files to be PUT onto the server
    /workdirs/scan-309c2336-0618-4342-8e51-3787e8a23458/requirements.txt
    A package you depend on has a known security hole (CVE-2023-6015). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-421 MLflow Use of Default Password Authentication Bypass Vulnerability
    /workdirs/scan-309c2336-0618-4342-8e51-3787e8a23458/requirements.txt
    A package you depend on has a known security hole (CVE-2026-2635). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-422 MLFlow Path Traversal Vulnerability
    /workdirs/scan-309c2336-0618-4342-8e51-3787e8a23458/requirements.txt
    A package you depend on has a known security hole (CVE-2023-6975). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-423 MLflow Command Injection vulnerability
    /workdirs/scan-309c2336-0618-4342-8e51-3787e8a23458/requirements.txt
    A package you depend on has a known security hole (CVE-2025-15379). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-424 Mlflow: Command Injection when serving models with enable_mlserver=True
    /workdirs/scan-309c2336-0618-4342-8e51-3787e8a23458/requirements.txt
    A package you depend on has a known security hole (CVE-2026-0596). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-425 MLFlow path traversal vulnerability
    /workdirs/scan-309c2336-0618-4342-8e51-3787e8a23458/requirements.txt
    A package you depend on has a known security hole (CVE-2025-15036). Fix: Update that package to its patched version.
  • Serious GHSA-83fm-w79m-64r5 Remote file access vulnerability in `mlflow server` and `mlflow ui` CLIs
    /workdirs/scan-309c2336-0618-4342-8e51-3787e8a23458/requirements.txt
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Serious PYSEC-2020-107 ** DISPUTED ** scikit-learn (aka sklearn) through 0.23.0 can unserialize and execute commands from an untrusted file that is passed to the joblib.load() function, if __reduce__ makes an os.system call
    /workdirs/scan-309c2336-0618-4342-8e51-3787e8a23458/requirements.txt
    A package you depend on has a known security hole (CVE-2020-13092). Fix: Update that package to its patched version.
  • Serious PYSEC-2022-43015 In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.
    /workdirs/scan-309c2336-0618-4342-8e51-3787e8a23458/requirements.txt
    A package you depend on has a known security hole (CVE-2022-45907). Fix: Update that package to its patched version.
  • Serious PYSEC-2024-259 In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing.
    /workdirs/scan-309c2336-0618-4342-8e51-3787e8a23458/requirements.txt
    A package you depend on has a known security hole (CVE-2024-48063). Fix: Update that package to its patched version.
… 531 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog timed out

Packages that look intentionally malicious: typosquats, sneaky install scripts.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Guarddog v2.10.0 · Apache-2.0

error: pypi:timeout

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.