gitsafehub
github.com/volksport/dots.ocr ↗

volksport/dots.ocr

scanned 2026-08-15 · git 2a5977c
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 4 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies9Known OSS vulnerabilities96Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks none found ✓

API keys, passwords or tokens committed into the repo.

Nothing found by this check. ✓

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 9 found

Packages you depend on that have known security holes (CVEs).

  • Worth fixing CVE-2026-4372 HuggingFace transformers vulnerable to remote code execution
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-4372). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-5241 python-transformers: python-transformers: Arbitrary code execution due to overridden trust_remote_code setting
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-5241). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-3933 transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-3933). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-5197 transformers: Transformers ReDoS Vulnerability
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-5197). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-6051 transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-6051). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-6638 transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-6638). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-6921 transformers: Regular Expression Denial of Service (ReDoS) in huggingface/transformers
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-6921). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-1839 transformers: HuggingFace Transformers: Arbitrary code execution via malicious checkpoint file
    requirements.txt
    A package you depend on has a known security hole (CVE-2026-1839). Fix: Update that package to its patched version.
  • Minor CVE-2025-3777 transformers: Improper Input Validation in huggingface/transformers
    requirements.txt
    A package you depend on has a known security hole (CVE-2025-3777). Fix: Update that package to its patched version.

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 96 found · 4 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious PYSEC-2026-2290 A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The
    /workdirs/scan-f602f402-505c-4b5f-85c5-e86ea3d128ed/requirements.txt
    A package you depend on has a known security hole (CVE-2026-5241). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-2102 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in resp
    /workdirs/scan-f602f402-505c-4b5f-85c5-e86ea3d128ed/requirements.txt
    A package you depend on has a known security hole (CVE-2026-34520). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-457 Arbitrary Code Execution in Pillow
    /workdirs/scan-f602f402-505c-4b5f-85c5-e86ea3d128ed/requirements.txt
    A package you depend on has a known security hole (CVE-2023-50447). Fix: Update that package to its patched version.
  • Serious PYSEC-2023-238 Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code execution. An application is vulnerable if it reads Arrow IPC, Feather or Parque
    /workdirs/scan-f602f402-505c-4b5f-85c5-e86ea3d128ed/requirements.txt
    A package you depend on has a known security hole (CVE-2023-47248). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2477 flash-attention contains an insecure deserialization vulnerability in its checkpoint loading mechanism
    /workdirs/scan-f602f402-505c-4b5f-85c5-e86ea3d128ed/requirements.txt
    A package you depend on has a known security hole (CVE-2026-31253). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2178 Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Space session fixation by exploiting a shared module-level HTTP client used across
    /workdirs/scan-f602f402-505c-4b5f-85c5-e86ea3d128ed/requirements.txt
    A package you depend on has a known security hole (CVE-2026-48545). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2179 Gradio before 6.16.0 contain a path traversal vulnerability in the FileExplorer component's preprocess() method that allows unauthenticated attackers to escape the configured root directory by supplyi
    /workdirs/scan-f602f402-505c-4b5f-85c5-e86ea3d128ed/requirements.txt
    A package you depend on has a known security hole (CVE-2026-49119). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2663 ModelScope is vulnerable to arbitrary code injection via a crafted module
    /workdirs/scan-f602f402-505c-4b5f-85c5-e86ea3d128ed/requirements.txt
    A package you depend on has a known security hole (CVE-2025-51427). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2025-211 Hugging Face Transformers Perceiver Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected instal
    /workdirs/scan-f602f402-505c-4b5f-85c5-e86ea3d128ed/requirements.txt
    A package you depend on has a known security hole (CVE-2025-14920). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2025-212 Hugging Face Transformers Transformer-XL Model Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected i
    /workdirs/scan-f602f402-505c-4b5f-85c5-e86ea3d128ed/requirements.txt
    A package you depend on has a known security hole (CVE-2025-14921). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2025-213 Hugging Face Transformers megatron_gpt2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installa
    /workdirs/scan-f602f402-505c-4b5f-85c5-e86ea3d128ed/requirements.txt
    A package you depend on has a known security hole (CVE-2025-14924). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2025-214 Hugging Face Transformers SEW convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Huggi
    /workdirs/scan-f602f402-505c-4b5f-85c5-e86ea3d128ed/requirements.txt
    A package you depend on has a known security hole (CVE-2025-14926). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2025-215 Hugging Face Transformers SEW-D convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hug
    /workdirs/scan-f602f402-505c-4b5f-85c5-e86ea3d128ed/requirements.txt
    A package you depend on has a known security hole (CVE-2025-14927). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2025-216 Hugging Face Transformers HuBERT convert_config Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hu
    /workdirs/scan-f602f402-505c-4b5f-85c5-e86ea3d128ed/requirements.txt
    A package you depend on has a known security hole (CVE-2025-14928). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2025-217 Hugging Face Transformers X-CLIP Checkpoint Conversion Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on af
    /workdirs/scan-f602f402-505c-4b5f-85c5-e86ea3d128ed/requirements.txt
    A package you depend on has a known security hole (CVE-2025-14929). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2025-218 Hugging Face Transformers GLM4 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of
    /workdirs/scan-f602f402-505c-4b5f-85c5-e86ea3d128ed/requirements.txt
    A package you depend on has a known security hole (CVE-2025-14930). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1977 Transformers is vulnerable to ReDoS attack through its DonutProcessor class
    /workdirs/scan-f602f402-505c-4b5f-85c5-e86ea3d128ed/requirements.txt
    A package you depend on has a known security hole (CVE-2025-3933). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1980 Hugging Face Transformers vulnerable to Regular Expression Denial of Service (ReDoS) in the AdamWeightDecay optimizer
    /workdirs/scan-f602f402-505c-4b5f-85c5-e86ea3d128ed/requirements.txt
    A package you depend on has a known security hole (CVE-2025-6921). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1981 Hugging Face Transformers is vulnerable to ReDoS through its MarianTokenizer
    /workdirs/scan-f602f402-505c-4b5f-85c5-e86ea3d128ed/requirements.txt
    A package you depend on has a known security hole (CVE-2025-6638). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1983 Hugging Face Transformers Regular Expression Denial of Service (ReDoS) vulnerability
    /workdirs/scan-f602f402-505c-4b5f-85c5-e86ea3d128ed/requirements.txt
    A package you depend on has a known security hole (CVE-2025-5197). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1988 Hugging Face Transformers library has Regular Expression Denial of Service
    /workdirs/scan-f602f402-505c-4b5f-85c5-e86ea3d128ed/requirements.txt
    A package you depend on has a known security hole (CVE-2025-6051). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2288 A vulnerability in the HuggingFace Transformers library, specifically in the `Trainer` class, allows for arbitrary code execution. The `_load_rng_state()` method in `src/transformers/trainer.py` at li
    /workdirs/scan-f602f402-505c-4b5f-85c5-e86ea3d128ed/requirements.txt
    A package you depend on has a known security hole (CVE-2026-1839). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-2289 A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config.
    /workdirs/scan-f602f402-505c-4b5f-85c5-e86ea3d128ed/requirements.txt
    A package you depend on has a known security hole (CVE-2026-4372). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1100 AIOHTTP vulnerable to denial of service through large payloads
    /workdirs/scan-f602f402-505c-4b5f-85c5-e86ea3d128ed/requirements.txt
    A package you depend on has a known security hole (CVE-2025-69228). Fix: Update that package to its patched version.
  • Worth fixing PYSEC-2026-1101 AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
    /workdirs/scan-f602f402-505c-4b5f-85c5-e86ea3d128ed/requirements.txt
    A package you depend on has a known security hole (CVE-2025-69223). Fix: Update that package to its patched version.
… 71 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog timed out

Packages that look intentionally malicious: typosquats, sneaky install scripts.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Guarddog v2.10.0 · Apache-2.0

error: pypi:timeout

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.