Anthropic Python Vulnerabilities

pip LLM APIs

AI Threat Alert tracks 46 known vulnerabilities in Anthropic Python, 1 rated critical — an AI/ML llm apis in the pip ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
31
Risk Score
46
Total CVEs
1
Critical
pip
Ecosystem
Aug 17, 2026
Last CVE
90%
Patch Rate
12d
Avg Time to Patch
3,824 stars 812 forks 163 issues 6,417 dependents Last push Aug 15, 2026
View on GitHub

Known Vulnerabilities (46 total, page 1 of 2)

Severity CVE ID Summary CVSS Published
MEDIUM GHSA-mpwr-8vm7-h73f go-pkcs12: PBMAC1 flaw lets wrong-password files decode -- Aug 17, 2026 HIGH CVE-2026-54763 Traefik: underscore header bypass spoofs identity -- Aug 6, 2026 HIGH CVE-2026-67428 Flyto2 Core: SSRF via unvalidated URLs in agent tools 8.5 Jul 29, 2026 HIGH GHSA-xg4h-6gfc-h4m8 etcd: Watch API auth bypass leaks entire keyspace -- Jul 24, 2026 MEDIUM CVE-2026-58435 Gitea: LFS deploy-key flaw leaks private repo objects 5.4 Jul 21, 2026 HIGH CVE-2026-27775 Gitea: cached permission check allows repo takeover 8.8 Jul 21, 2026 MEDIUM CVE-2026-55407 Buffa: protobuf decoder DoS via 22x memory amplification -- Jul 16, 2026 MEDIUM CVE-2026-55406 buffa: use-after-free in Rust protobuf OwnedView type -- Jul 16, 2026 HIGH CVE-2026-54449 LangBot: RCE via arbitrary STDIO MCP command 8.8 Jul 15, 2026 HIGH CVE-2026-55076 Coder: OIDC type-confusion enables account takeover 7.4 Jul 6, 2026 HIGH CVE-2026-55075 Coder: OIDC auth bypass enables account takeover 7.4 Jul 6, 2026 HIGH CVE-2026-55077 Coder: user-admin can hijack owner accounts 7.2 Jul 6, 2026 HIGH CVE-2026-55427 Coder: SSH config injection via config-ssh enables RCE 8.3 Jul 6, 2026 MEDIUM CVE-2026-55079 Coder: unbounded FileSize crashes coderd via OOM 4.9 Jul 6, 2026 HIGH CVE-2026-55429 Coder: cross-workspace agent hijack via app ID reuse 8.7 Jul 6, 2026 HIGH CVE-2026-55428 Coder: agent IP spoofing hijacks workspace traffic 8.2 Jul 6, 2026 MEDIUM CVE-2026-55430 Coder: X-Forwarded-Host spoof leaks victim app data 5.8 Jul 6, 2026 MEDIUM CVE-2026-55078 Coder: zip decompression bomb crashes coderd (DoS) 6.5 Jul 6, 2026 HIGH CVE-2026-55431 Coder: session token leak via workspace app URL 7.7 Jul 6, 2026 MEDIUM CVE-2026-55432 Coder: sub-agent apps bypass org port-sharing policy 5.4 Jul 6, 2026 MEDIUM CVE-2026-55433 Coder: missing ActionUpdate check allows devcontainer wipe 5.4 Jul 6, 2026 MEDIUM CVE-2026-55434 Coder: AI Bridge unbounded read enables DoS 6.5 Jul 6, 2026 MEDIUM CVE-2026-55435 Coder AI Bridge: suspended user auth bypass 5.4 Jul 6, 2026 HIGH CVE-2026-55436 Coder AI Bridge Proxy: TLS bypass leaks BYOK keys 7.4 Jul 6, 2026 MEDIUM CVE-2026-55437 Coder: stored XSS in agent logs risks admin session 5.4 Jul 6, 2026

Showing 1–25 of 46

Frequently asked questions

What is Anthropic Python?

Anthropic Python is an AI/ML llm apis tracked by AI Threat Alert for security vulnerabilities in the pip ecosystem.

How many known vulnerabilities does Anthropic Python have?

Anthropic Python has 46 known CVEs, 1 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is Anthropic Python distributed in?

Anthropic Python is distributed via the pip ecosystem and categorized as llm apis.

Where does the Anthropic Python vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of Anthropic Python?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor Anthropic Python in your stack

Get instant alerts when new vulnerabilities affect Anthropic Python. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring