gitsafehub
github.com/shaneutt/gorilla ↗

shaneutt/gorilla

scanned 2026-08-16 · git 45a56b2
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 3 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies50Known OSS vulnerabilities89Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks timed out

API keys, passwords or tokens committed into the repo.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Gitleaks v8.21.2 · MIT

error: timeout after 120s

Vulnerable dependencies — Trivy 50 found · 2 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2025-32434 PyTorch is a Python package that provides tensor computation with stro ...
    inference/requirements.txt
    A package you depend on has a known security hole (CVE-2025-32434). Fix: Update that package to its patched version.
  • Serious CVE-2023-6730 transformers has a Deserialization of Untrusted Data vulnerability
    inference/requirements.txt
    A package you depend on has a known security hole (CVE-2023-6730). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-1260 sentencepiece: Sentencepiece: Invalid memory access leading to potential arbitrary code execution via a crafted model file.
    inference/requirements.txt
    A package you depend on has a known security hole (CVE-2026-1260). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-31580 PyTorch before v2.2.0 was discovered to contain a heap buffer overflow ...
    inference/requirements.txt
    A package you depend on has a known security hole (CVE-2024-31580). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-31583 Pytorch before version v2.2.0 was discovered to contain a use-after-fr ...
    inference/requirements.txt
    A package you depend on has a known security hole (CVE-2024-31583). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-2999 A vulnerability was found in PyTorch 2.6.0. It has been rated as criti ...
    inference/requirements.txt
    A package you depend on has a known security hole (CVE-2025-2999). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-3730 A vulnerability, which was classified as problematic, was found in PyT ...
    inference/requirements.txt
    A package you depend on has a known security hole (CVE-2025-3730). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-7018 transformers has a Deserialization of Untrusted Data vulnerability
    inference/requirements.txt
    A package you depend on has a known security hole (CVE-2023-7018). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-11392 transformers: Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability
    inference/requirements.txt
    A package you depend on has a known security hole (CVE-2024-11392). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-11393 transformers: Hugging Face Transformers MaskFormer Model Deserialization of Untrusted Data Remote Code Execution Vulnerability
    inference/requirements.txt
    A package you depend on has a known security hole (CVE-2024-11393). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-11394 transformers: Hugging Face Transformers Trax Model Deserialization of Untrusted Data Remote Code Execution Vulnerability
    inference/requirements.txt
    A package you depend on has a known security hole (CVE-2024-11394). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-4372 HuggingFace transformers vulnerable to remote code execution
    inference/requirements.txt
    A package you depend on has a known security hole (CVE-2026-4372). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-5241 python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code setting
    inference/requirements.txt
    A package you depend on has a known security hole (CVE-2026-5241). Fix: Update that package to its patched version.
  • Worth fixing CVE-2023-2800 transformers has Insecure Temporary File
    inference/requirements.txt
    A package you depend on has a known security hole (CVE-2023-2800). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-12720 Transformers Regular Expression Denial of Service (ReDoS) vulnerability
    inference/requirements.txt
    A package you depend on has a known security hole (CVE-2024-12720). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-1194 Transformers Regular Expression Denial of Service (ReDoS) vulnerability
    inference/requirements.txt
    A package you depend on has a known security hole (CVE-2025-1194). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-2099 transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers
    inference/requirements.txt
    A package you depend on has a known security hole (CVE-2025-2099). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-3263 transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers
    inference/requirements.txt
    A package you depend on has a known security hole (CVE-2025-3263). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-3264 transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers
    inference/requirements.txt
    A package you depend on has a known security hole (CVE-2025-3264). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-3933 transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers
    inference/requirements.txt
    A package you depend on has a known security hole (CVE-2025-3933). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-5197 transformers: Transformers ReDoS Vulnerability
    inference/requirements.txt
    A package you depend on has a known security hole (CVE-2025-5197). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-6051 transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers
    inference/requirements.txt
    A package you depend on has a known security hole (CVE-2025-6051). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-6638 transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers
    inference/requirements.txt
    A package you depend on has a known security hole (CVE-2025-6638). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-6921 transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers
    inference/requirements.txt
    A package you depend on has a known security hole (CVE-2025-6921). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-1839 transformers: HuggingFace Transformers: Arbitrary code execution via malicious checkpoint file
    inference/requirements.txt
    A package you depend on has a known security hole (CVE-2026-1839). Fix: Update that package to its patched version.
… 25 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 89 found · 7 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious PYSEC-2026-517 Ray has arbitrary code execution via jobs submission API
    /workdirs/scan-b83a439a-ae60-4b45-8717-54ff7f34f01a/berkeley-function-call-leaderboard/requirements.txt
    A package you depend on has a known security hole (CVE-2023-48022). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-518 Ray's New Token Authentication is Disabled By Default
    /workdirs/scan-b83a439a-ae60-4b45-8717-54ff7f34f01a/berkeley-function-call-leaderboard/requirements.txt
    A package you depend on has a known security hole (CVE-2025-34351). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-520 Ray is vulnerable to Critical RCE via Safari & Firefox Browsers through DNS Rebinding Attack
    /workdirs/scan-b83a439a-ae60-4b45-8717-54ff7f34f01a/berkeley-function-call-leaderboard/requirements.txt
    A package you depend on has a known security hole (CVE-2025-62593). Fix: Update that package to its patched version.
  • Serious PYSEC-2024-259 In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing.
    /workdirs/scan-b83a439a-ae60-4b45-8717-54ff7f34f01a/inference/requirements.txt
    A package you depend on has a known security hole (CVE-2024-48063). Fix: Update that package to its patched version.
  • Serious PYSEC-2025-41 PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command E
    /workdirs/scan-b83a439a-ae60-4b45-8717-54ff7f34f01a/inference/requirements.txt
    A package you depend on has a known security hole (CVE-2025-32434). Fix: Update that package to its patched version.
  • Serious PYSEC-2023-300 Deserialization of Untrusted Data in GitHub repository huggingface/transformers prior to 4.36.
    /workdirs/scan-b83a439a-ae60-4b45-8717-54ff7f34f01a/inference/requirements.txt
    A package you depend on has a known security hole (CVE-2023-6730). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-2290 A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The
    /workdirs/scan-b83a439a-ae60-4b45-8717-54ff7f34f01a/inference/requirements.txt
    A package you depend on has a known security hole (CVE-2026-5241). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2025-23 Versions of the package ray before 2.43.0 are vulnerable to Insertion of Sensitive Information into Log File where the redis password is being logged in the standard logging. If the redis password is
    /workdirs/scan-b83a439a-ae60-4b45-8717-54ff7f34f01a/berkeley-function-call-leaderboard/requirements.txt
    A package you depend on has a known security hole (CVE-2025-1979). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2271 Ray is an AI compute engine. In versions 2.53.0 and below, thedashboard HTTP server blocks browser-origin POST/PUT but does not cover DELETE, and key DELETE endpoints are unauthenticated by default. I
    /workdirs/scan-b83a439a-ae60-4b45-8717-54ff7f34f01a/berkeley-function-call-leaderboard/requirements.txt
    A package you depend on has a known security hole (CVE-2026-27482). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2272 Ray is an AI compute engine. From version 2.54.0 to before version 2.55.0, Ray Data registers custom Arrow extension types (ray.data.arrow_tensor, ray.data.arrow_tensor_v2, ray.data.arrow_variable_sha
    /workdirs/scan-b83a439a-ae60-4b45-8717-54ff7f34f01a/berkeley-function-call-leaderboard/requirements.txt
    A package you depend on has a known security hole (CVE-2026-41486). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2273 Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to achieve remote code execution by supplying a malicious tar archive to the read_we
    /workdirs/scan-b83a439a-ae60-4b45-8717-54ff7f34f01a/berkeley-function-call-leaderboard/requirements.txt
    A package you depend on has a known security hole (CVE-2026-57516). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2018-28 The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to dis
    /workdirs/scan-b83a439a-ae60-4b45-8717-54ff7f34f01a/berkeley-function-call-leaderboard/requirements.txt
    A package you depend on has a known security hole (CVE-2018-18074). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2023-74 Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination servers when redirected to an HTTPS endpoint. This is a product of how we use `re
    /workdirs/scan-b83a439a-ae60-4b45-8717-54ff7f34f01a/berkeley-function-call-leaderboard/requirements.txt
    A package you depend on has a known security hole (CVE-2023-32681). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1872 Requests vulnerable to .netrc credentials leak via malicious URLs
    /workdirs/scan-b83a439a-ae60-4b45-8717-54ff7f34f01a/berkeley-function-call-leaderboard/requirements.txt
    A package you depend on has a known security hole (CVE-2024-47081). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1873 Requests `Session` object does not verify requests after making first request with verify=False
    /workdirs/scan-b83a439a-ae60-4b45-8717-54ff7f34f01a/berkeley-function-call-leaderboard/requirements.txt
    A package you depend on has a known security hole (CVE-2024-35195). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2275 Requests is a HTTP library. Prior to version 2.33.0, the `requests.utils.extract_zipped_paths()` utility function uses a predictable filename when extracting files from zip archives into the system te
    /workdirs/scan-b83a439a-ae60-4b45-8717-54ff7f34f01a/berkeley-function-call-leaderboard/requirements.txt
    A package you depend on has a known security hole (CVE-2026-25645). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-139 A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be pe
    /workdirs/scan-b83a439a-ae60-4b45-8717-54ff7f34f01a/berkeley-function-call-leaderboard/requirements.txt
    A package you depend on has a known security hole (CVE-2026-4538). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2286 PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker to craft a malicious checkpoint file (`.
    /workdirs/scan-b83a439a-ae60-4b45-8717-54ff7f34f01a/berkeley-function-call-leaderboard/requirements.txt
    A package you depend on has a known security hole (CVE-2026-24747). Fix: Update that package to its patched version.
  • Worth fixing GHSA-qfhq-4f3w-5fph PyTorch is vulnerable to memory corruption through its torch.lstm_cell function
    /workdirs/scan-b83a439a-ae60-4b45-8717-54ff7f34f01a/berkeley-function-call-leaderboard/requirements.txt
    A package you depend on has a known security hole (CVE-2025-3001). Fix: Update that package to its patched version.
  • Worth fixing GHSA-rrmf-rvhw-rf47 PyTorch is vulnerable to memory corruption through its torch.jit.script function
    /workdirs/scan-b83a439a-ae60-4b45-8717-54ff7f34f01a/berkeley-function-call-leaderboard/requirements.txt
    A package you depend on has a known security hole (CVE-2025-3000). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2017-74 The tqdm._version module in tqdm versions 4.4.1 and 4.10 allows local users to execute arbitrary code via a crafted repo with a malicious git log in the current working directory.
    /workdirs/scan-b83a439a-ae60-4b45-8717-54ff7f34f01a/berkeley-function-call-leaderboard/requirements.txt
    A package you depend on has a known security hole (CVE-2016-10075). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1374 filelock Time-of-Check-Time-of-Use (TOCTOU) Symlink Vulnerability in SoftFileLock
    /workdirs/scan-b83a439a-ae60-4b45-8717-54ff7f34f01a/berkeley-function-call-leaderboard/requirements.txt
    A package you depend on has a known security hole (CVE-2026-22701). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1375 filelock has a TOCTOU race condition which allows symlink attacks during lock file creation
    /workdirs/scan-b83a439a-ae60-4b45-8717-54ff7f34f01a/berkeley-function-call-leaderboard/requirements.txt
    A package you depend on has a known security hole (CVE-2025-68146). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1909 Sentencepiece has a a heap overflow issue
    /workdirs/scan-b83a439a-ae60-4b45-8717-54ff7f34f01a/inference/requirements.txt
    A package you depend on has a known security hole (CVE-2026-1260). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2024-251 Pytorch before version v2.2.0 was discovered to contain a use-after-free vulnerability in torch/csrc/jit/mobile/interpreter.cpp.
    /workdirs/scan-b83a439a-ae60-4b45-8717-54ff7f34f01a/inference/requirements.txt
    A package you depend on has a known security hole (CVE-2024-31583). Fix: Update that package to its patched version.
… 64 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog couldn’t run

Packages that look intentionally malicious: typosquats, sneaky install scripts.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Guarddog v2.10.0 · Apache-2.0

error: pypi:ERROR: Error while scanning. Received 'utf-8' codec can't decode byte 0xff in position 0: invalid start byte Traceback (

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.