Your dependencies cross-checked against the OSV vulnerability database.
-
Serious PYSEC-2026-457 Arbitrary Code Execution in Pillow
/workdirs/scan-be427df3-3bea-41c2-a4e0-fcf7dd64eefe/MtaDesignedAgents/PictureBookMaker/src/requirements.txt
A package you depend on has a known security hole (CVE-2023-50447). Fix: Update that package to its patched version.
-
Serious PYSEC-2026-2102 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.13.4, the C parser (the default for most installs) accepted null bytes and control characters in resp
/workdirs/scan-be427df3-3bea-41c2-a4e0-fcf7dd64eefe/src/client/requirements.txt
A package you depend on has a known security hole (CVE-2026-34520). Fix: Update that package to its patched version.
-
Serious PYSEC-2023-238 Deserialization of untrusted data in IPC and Parquet readers in PyArrow versions 0.14.0 to 14.0.0 allows arbitrary code execution. An application is vulnerable if it reads Arrow IPC, Feather or Parque
/workdirs/scan-be427df3-3bea-41c2-a4e0-fcf7dd64eefe/src/generated_agents/badchatbot/requirements.txt
A package you depend on has a known security hole (CVE-2023-47248). Fix: Update that package to its patched version.
-
Serious PYSEC-2026-457 Arbitrary Code Execution in Pillow
/workdirs/scan-be427df3-3bea-41c2-a4e0-fcf7dd64eefe/src/generated_agents/badchatbot/requirements.txt
A package you depend on has a known security hole (CVE-2023-50447). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-215 Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior
/workdirs/scan-be427df3-3bea-41c2-a4e0-fcf7dd64eefe/MtaDesignedAgents/PictureBookMaker/src/requirements.txt
A package you depend on has a known security hole (CVE-2026-45409). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2023-227 An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of
/workdirs/scan-be427df3-3bea-41c2-a4e0-fcf7dd64eefe/MtaDesignedAgents/PictureBookMaker/src/requirements.txt
A package you depend on has a known security hole (CVE-2023-44271). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-165 Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer
/workdirs/scan-be427df3-3bea-41c2-a4e0-fcf7dd64eefe/MtaDesignedAgents/PictureBookMaker/src/requirements.txt
A package you depend on has a known security hole (CVE-2026-42308). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-1793 Pillow buffer overflow vulnerability
/workdirs/scan-be427df3-3bea-41c2-a4e0-fcf7dd64eefe/MtaDesignedAgents/PictureBookMaker/src/requirements.txt
A package you depend on has a known security hole (CVE-2024-28219). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-1794 libwebp: OOB write in BuildHuffmanTable
/workdirs/scan-be427df3-3bea-41c2-a4e0-fcf7dd64eefe/MtaDesignedAgents/PictureBookMaker/src/requirements.txt
A package you depend on has a known security hole (CVE-2023-4863). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-2253 Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling
/workdirs/scan-be427df3-3bea-41c2-a4e0-fcf7dd64eefe/MtaDesignedAgents/PictureBookMaker/src/requirements.txt
A package you depend on has a known security hole (CVE-2026-54059). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-2254 Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new("1", (xsize, ysize)) without calling Image._dec
/workdirs/scan-be427df3-3bea-41c2-a4e0-fcf7dd64eefe/MtaDesignedAgents/PictureBookMaker/src/requirements.txt
A package you depend on has a known security hole (CVE-2026-54060). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-2255 Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() wit
/workdirs/scan-be427df3-3bea-41c2-a4e0-fcf7dd64eefe/MtaDesignedAgents/PictureBookMaker/src/requirements.txt
A package you depend on has a known security hole (CVE-2026-55379). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-2256 Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompress
/workdirs/scan-be427df3-3bea-41c2-a4e0-fcf7dd64eefe/MtaDesignedAgents/PictureBookMaker/src/requirements.txt
A package you depend on has a known security hole (CVE-2026-55380). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-2257 Pillow is a Python imaging library. Prior to 12.3.0, WindowsViewer.get_command() constructed a cmd.exe shell command by directly embedding a file path into an f-string without escaping and passed the
/workdirs/scan-be427df3-3bea-41c2-a4e0-fcf7dd64eefe/MtaDesignedAgents/PictureBookMaker/src/requirements.txt
A package you depend on has a known security hole (CVE-2026-55798). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-2874 Pillow has a PDF Parsing Trailer Infinite Loop (DoS)
/workdirs/scan-be427df3-3bea-41c2-a4e0-fcf7dd64eefe/MtaDesignedAgents/PictureBookMaker/src/requirements.txt
A package you depend on has a known security hole (CVE-2026-42310). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-3451 Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in I
/workdirs/scan-be427df3-3bea-41c2-a4e0-fcf7dd64eefe/MtaDesignedAgents/PictureBookMaker/src/requirements.txt
A package you depend on has a known security hole (CVE-2026-59199). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-3453 Pillow is a Python imaging library. Prior to 12.3.0, Pillow's ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image who
/workdirs/scan-be427df3-3bea-41c2-a4e0-fcf7dd64eefe/MtaDesignedAgents/PictureBookMaker/src/requirements.txt
A package you depend on has a known security hole (CVE-2026-59205). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-3454 Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilte
/workdirs/scan-be427df3-3bea-41c2-a4e0-fcf7dd64eefe/MtaDesignedAgents/PictureBookMaker/src/requirements.txt
A package you depend on has a known security hole (CVE-2026-59197). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-3493 Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
/workdirs/scan-be427df3-3bea-41c2-a4e0-fcf7dd64eefe/MtaDesignedAgents/PictureBookMaker/src/requirements.txt
A package you depend on has a known security hole (CVE-2026-54058). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-3494 Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images
/workdirs/scan-be427df3-3bea-41c2-a4e0-fcf7dd64eefe/MtaDesignedAgents/PictureBookMaker/src/requirements.txt
A package you depend on has a known security hole (CVE-2026-59198). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-3495 Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
/workdirs/scan-be427df3-3bea-41c2-a4e0-fcf7dd64eefe/MtaDesignedAgents/PictureBookMaker/src/requirements.txt
A package you depend on has a known security hole (CVE-2026-59200). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-3496 Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
/workdirs/scan-be427df3-3bea-41c2-a4e0-fcf7dd64eefe/MtaDesignedAgents/PictureBookMaker/src/requirements.txt
A package you depend on has a known security hole (CVE-2026-59204). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2017-74 The tqdm._version module in tqdm versions 4.4.1 and 4.10 allows local users to execute arbitrary code via a crafted repo with a malicious git log in the current working directory.
/workdirs/scan-be427df3-3bea-41c2-a4e0-fcf7dd64eefe/MtaDesignedAgents/PictureBookMaker/src/requirements.txt
A package you depend on has a known security hole (CVE-2016-10075). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-1100 AIOHTTP vulnerable to denial of service through large payloads
/workdirs/scan-be427df3-3bea-41c2-a4e0-fcf7dd64eefe/src/client/requirements.txt
A package you depend on has a known security hole (CVE-2025-69228). Fix: Update that package to its patched version.
-
Worth fixing PYSEC-2026-1101 AIOHTTP's HTTP Parser auto_decompress feature is vulnerable to zip bomb
/workdirs/scan-be427df3-3bea-41c2-a4e0-fcf7dd64eefe/src/client/requirements.txt
A package you depend on has a known security hole (CVE-2025-69223). Fix: Update that package to its patched version.