gitsafehub
github.com/zeyuchen/paddlenlp ↗

zeyuchen/paddlenlp

scanned 2026-08-13 · git bc6768f
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 3 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secrets2Vulnerable dependencies28Known OSS vulnerabilitiesRisky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks 2 found

API keys, passwords or tokens committed into the repo.

  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    community/Langboat/mengzi-t5-base/README.md:7
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.
  • Worth fixing generic-api-key Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    community/Langboat/mengzi-t5-base/README.md:7
    A credential (key, password or token) appears in your code. Fix: Remove it, rotate the key, and load it from an environment variable instead.

via Gitleaks v8.21.2 · MIT

Vulnerable dependencies — Trivy 28 found · 2 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2025-14009 nltk: Zip Slip Vulnerability in nltk Leading to Code Execution
    examples/text_summarization/bart/requirements.txt
    A package you depend on has a known security hole (CVE-2025-14009). Fix: Update that package to its patched version.
  • Serious CVE-2025-14009 nltk: Zip Slip Vulnerability in nltk Leading to Code Execution
    examples/text_summarization/prophetnet/requirements.txt
    A package you depend on has a known security hole (CVE-2025-14009). Fix: Update that package to its patched version.
  • Worth fixing GHSA-xgfm-fjx6-62mj readthedocs-sphinx-search vulnerable to cross-site scripting when including search results from malicious projects
    docs/requirements.txt
    A package you depend on has a known security hole (GHSA-xgfm-fjx6-62mj). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-3828 nltk is vulnerable to Inefficient Regular Expression Complexity
    examples/text_summarization/bart/requirements.txt
    A package you depend on has a known security hole (CVE-2021-3828). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-3842 nltk is vulnerable to Inefficient Regular Expression Complexity
    examples/text_summarization/bart/requirements.txt
    A package you depend on has a known security hole (CVE-2021-3842). Fix: Update that package to its patched version.
  • Worth fixing CVE-2021-43854 NLTK (Natural Language Toolkit) is a suite of open source Python modul ...
    examples/text_summarization/bart/requirements.txt
    A package you depend on has a known security hole (CVE-2021-43854). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-39705 NLTK through 3.8.1 allows remote code execution if untrusted packages ...
    examples/text_summarization/bart/requirements.txt
    A package you depend on has a known security hole (CVE-2024-39705). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-71408 NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval ...
    examples/text_summarization/bart/requirements.txt
    A package you depend on has a known security hole (CVE-2025-71408). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-0846 nltk: NLTK: Arbitrary file read via improper path validation in `filestring()` function
    examples/text_summarization/bart/requirements.txt
    A package you depend on has a known security hole (CVE-2026-0846). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-12061 Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
    examples/text_summarization/bart/requirements.txt
    A package you depend on has a known security hole (CVE-2026-12061). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-12072 Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)
    examples/text_summarization/bart/requirements.txt
    A package you depend on has a known security hole (CVE-2026-12072). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-12074 Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)
    examples/text_summarization/bart/requirements.txt
    A package you depend on has a known security hole (CVE-2026-12074). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-12075 Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode
    examples/text_summarization/bart/requirements.txt
    A package you depend on has a known security hole (CVE-2026-12075). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-33231 nltk: NLTK: Denial of Service via unauthenticated remote shutdown
    examples/text_summarization/bart/requirements.txt
    A package you depend on has a known security hole (CVE-2026-33231). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-54293 nltk: NLTK: Information Disclosure via Path Traversal in `nltk.data.load()`
    examples/text_summarization/bart/requirements.txt
    A package you depend on has a known security hole (CVE-2026-54293). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-33230 nltk: NLTK: Script execution via reflected cross-site scripting in WordNet Browser
    examples/text_summarization/bart/requirements.txt
    A package you depend on has a known security hole (CVE-2026-33230). Fix: Update that package to its patched version.
  • Worth fixing CVE-2024-39705 NLTK through 3.8.1 allows remote code execution if untrusted packages ...
    examples/text_summarization/prophetnet/requirements.txt
    A package you depend on has a known security hole (CVE-2024-39705). Fix: Update that package to its patched version.
  • Worth fixing CVE-2025-71408 NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval ...
    examples/text_summarization/prophetnet/requirements.txt
    A package you depend on has a known security hole (CVE-2025-71408). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-0846 nltk: NLTK: Arbitrary file read via improper path validation in `filestring()` function
    examples/text_summarization/prophetnet/requirements.txt
    A package you depend on has a known security hole (CVE-2026-0846). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-12061 Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex
    examples/text_summarization/prophetnet/requirements.txt
    A package you depend on has a known security hole (CVE-2026-12061). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-12072 Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True)
    examples/text_summarization/prophetnet/requirements.txt
    A package you depend on has a known security hole (CVE-2026-12072). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-12074 Natural Language Toolkit (NLTK) has path traversal in FramenetCorpusReader.frame() that allows arbitrary XML file read, bypassing the nltk.pathsec sandbox (ENFORCE=True)
    examples/text_summarization/prophetnet/requirements.txt
    A package you depend on has a known security hole (CVE-2026-12074). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-12075 Natural Language Toolkit (NLTK): DNS-rebinding SSRF filter bypass in nltk.pathsec.urlopen (nltk.download / nltk.data.load) defeats ENFORCE mode
    examples/text_summarization/prophetnet/requirements.txt
    A package you depend on has a known security hole (CVE-2026-12075). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-33231 nltk: NLTK: Denial of Service via unauthenticated remote shutdown
    examples/text_summarization/prophetnet/requirements.txt
    A package you depend on has a known security hole (CVE-2026-33231). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-54293 nltk: NLTK: Information Disclosure via Path Traversal in `nltk.data.load()`
    examples/text_summarization/prophetnet/requirements.txt
    A package you depend on has a known security hole (CVE-2026-54293). Fix: Update that package to its patched version.
… 3 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner timed out

Your dependencies cross-checked against the OSV vulnerability database.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OSV-Scanner v1.9.2 · Apache-2.0

error: timeout after 400s

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog timed out

Packages that look intentionally malicious: typosquats, sneaky install scripts.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Guarddog v2.10.0 · Apache-2.0

error: pypi:timeout

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.