gitsafehub
github.com/sonlovinbot/awesome-llm-apps ↗

sonlovinbot/awesome-llm-apps

scanned 2026-08-06 · git 2463d17
1 of 6 checks flagged a security issue
🔴 Needs attention
Only 3 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies652Known OSS vulnerabilitiesRisky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks timed out

API keys, passwords or tokens committed into the repo.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Gitleaks v8.21.2 · MIT

error: timeout after 120s

Vulnerable dependencies — Trivy 652 found · 21 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2026-35002 Agno is vulnerable to Eval Injection
    advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
    A package you depend on has a known security hole (CVE-2026-35002). Fix: Update that package to its patched version.
  • Serious CVE-2025-43859 h11: h11 accepts some malformed Chunked-Encoding bodies
    advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
    A package you depend on has a known security hole (CVE-2025-43859). Fix: Update that package to its patched version.
  • Serious CVE-2026-35002 Agno is vulnerable to Eval Injection
    advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/backend/uv.lock
    A package you depend on has a known security hole (CVE-2026-35002). Fix: Update that package to its patched version.
  • Serious CVE-2026-53512 Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
    advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2026-53512). Fix: Update that package to its patched version.
  • Serious GHSA-xg6x-h9c9-2m83 Better Auth Has Two-Factor Authentication Bypass via Premature Session Caching (session.cookieCache)
    advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml
    A package you depend on has a known security hole (GHSA-xg6x-h9c9-2m83). Fix: Update that package to its patched version.
  • Serious CVE-2025-55182 next: React Server Components: Pre-authentication remote code execution via unsafe deserialization
    advanced_ai_agents/multi_agent_apps/agent_teams/ai_travel_planner_agent_team/client/pnpm-lock.yaml
    A package you depend on has a known security hole (CVE-2025-55182). Fix: Update that package to its patched version.
  • Serious CVE-2025-23042 Gradio Blocked Path ACL Bypass Vulnerability
    advanced_ai_agents/multi_agent_apps/ai_aqi_analysis_agent/requirements.txt
    A package you depend on has a known security hole (CVE-2025-23042). Fix: Update that package to its patched version.
  • Serious CVE-2026-35002 Agno is vulnerable to Eval Injection
    advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
    A package you depend on has a known security hole (CVE-2026-35002). Fix: Update that package to its patched version.
  • Serious CVE-2025-43859 h11: h11 accepts some malformed Chunked-Encoding bodies
    advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
    A package you depend on has a known security hole (CVE-2025-43859). Fix: Update that package to its patched version.
  • Serious CVE-2025-68664 langchain-core: LangChain: Arbitrary code execution via serialization injection
    advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
    A package you depend on has a known security hole (CVE-2025-68664). Fix: Update that package to its patched version.
  • Serious CVE-2025-14009 nltk: Zip Slip Vulnerability in nltk Leading to Code Execution
    advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
    A package you depend on has a known security hole (CVE-2025-14009). Fix: Update that package to its patched version.
  • Serious CVE-2025-32434 PyTorch is a Python package that provides tensor computation with stro ...
    advanced_ai_agents/multi_agent_apps/ai_news_and_podcast_agents/beifong/requirements.txt
    A package you depend on has a known security hole (CVE-2025-32434). Fix: Update that package to its patched version.
  • Serious CVE-2025-68664 langchain-core: LangChain: Arbitrary code execution via serialization injection
    advanced_ai_agents/single_agent_apps/windows_use_autonomous_agent/uv.lock
    A package you depend on has a known security hole (CVE-2025-68664). Fix: Update that package to its patched version.
  • Serious CVE-2025-68664 langchain-core: LangChain: Arbitrary code execution via serialization injection
    rag_tutorials/corrective_rag/requirements.txt
    A package you depend on has a known security hole (CVE-2025-68664). Fix: Update that package to its patched version.
  • Serious CVE-2025-68664 langchain-core: LangChain: Arbitrary code execution via serialization injection
    rag_tutorials/rag_agent_cohere/requirements.txt
    A package you depend on has a known security hole (CVE-2025-68664). Fix: Update that package to its patched version.
  • Serious CVE-2025-68664 langchain-core: LangChain: Arbitrary code execution via serialization injection
    rag_tutorials/rag_database_routing/requirements.txt
    A package you depend on has a known security hole (CVE-2025-68664). Fix: Update that package to its patched version.
  • Serious CVE-2026-35002 Agno is vulnerable to Eval Injection
    starter_ai_agents/ai_blog_to_podcast_agent/requirements.txt
    A package you depend on has a known security hole (CVE-2026-35002). Fix: Update that package to its patched version.
  • Serious CVE-2026-35002 Agno is vulnerable to Eval Injection
    starter_ai_agents/ai_breakup_recovery_agent/requirements.txt
    A package you depend on has a known security hole (CVE-2026-35002). Fix: Update that package to its patched version.
  • Serious CVE-2023-50447 pillow: Arbitrary Code Execution via the environment parameter
    starter_ai_agents/ai_medical_imaging_agent/requirements.txt
    A package you depend on has a known security hole (CVE-2023-50447). Fix: Update that package to its patched version.
  • Serious CVE-2025-47241 Browser Use allows bypassing `allowed_domains` by putting a decoy domain in http auth username portion of a URL
    starter_ai_agents/ai_meme_generator_agent_browseruse/requirements.txt
    A package you depend on has a known security hole (CVE-2025-47241). Fix: Update that package to its patched version.
  • Serious CVE-2026-35002 Agno is vulnerable to Eval Injection
    starter_ai_agents/ai_music_generator_agent/requirements.txt
    A package you depend on has a known security hole (CVE-2026-35002). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-42215 GitPython is a python library used to interact with Git repositories. ...
    advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
    A package you depend on has a known security hole (CVE-2026-42215). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-42284 GitPython is a python library used to interact with Git repositories. ...
    advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
    A package you depend on has a known security hole (CVE-2026-42284). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-44243 GitPython: GitPython: Arbitrary file write via crafted reference paths
    advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
    A package you depend on has a known security hole (CVE-2026-44243). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-44244 GitPython is a python library used to interact with Git repositories. ...
    advanced_ai_agents/autonomous_game_playing_agent_apps/ai_tic_tac_toe_agent/requirements.txt
    A package you depend on has a known security hole (CVE-2026-44244). Fix: Update that package to its patched version.
… 627 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner timed out

Your dependencies cross-checked against the OSV vulnerability database.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OSV-Scanner v1.9.2 · Apache-2.0

error: timeout after 120s

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog none found ✓

Packages that look intentionally malicious: typosquats, sneaky install scripts.

Nothing found by this check. ✓

via Guarddog v2.10.0 · Apache-2.0

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.