github.com/zylon-ai/private-gpt
Submitted 8/4/2026, 10:27:37 AM · Status: ok
Risk grade
F
100 / 100
Findings
385
0 critical49 high312 medium22 low2 info0 on CISA KEV0ATT&CK
Showing 385 of 385 findings
Findings
- Detected facebook-page-access-token: Discovered a Facebook Page Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposureDiscovered a Facebook Page Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposure.gitleaks
- Detected facebook-page-access-token: Discovered a Facebook Page Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposureDiscovered a Facebook Page Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposure.gitleaks
- Detected facebook-page-access-token: Discovered a Facebook Page Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposureDiscovered a Facebook Page Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposure.gitleaks
- Detected facebook-page-access-token: Discovered a Facebook Page Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposureDiscovered a Facebook Page Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposure.gitleaks
- Detected facebook-page-access-token: Discovered a Facebook Page Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposureDiscovered a Facebook Page Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposure.gitleaks
- Detected facebook-page-access-token: Discovered a Facebook Page Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposureDiscovered a Facebook Page Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposure.gitleaks
- Detected facebook-page-access-token: Discovered a Facebook Page Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposureDiscovered a Facebook Page Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposure.gitleaks
- `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributesgrypeCVE-2026-49825
- FITS GZIP decompression bomb in PillowgrypeCVE-2026-40192EPSS 0.7%
- LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlistsgrypeCVE-2026-44843EPSS 0.4%
- LangSmith SDK TracingMiddleware: Arbitrary server-side file readgrype
- LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warninggrypeCVE-2026-45134EPSS 0.2%
- lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local filesgrypeCVE-2026-41066EPSS 0.3%
- Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitionsgrypeCVE-2026-59928EPSS 0.4%
- Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairsgrypeCVE-2026-59925EPSS 0.4%
- Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)grypeCVE-2026-59922EPSS 0.4%
- Mistune: Potential DoS via quadratic-time parsing in parse_link_textgrypeCVE-2026-49851EPSS 0.4%
- Natural Language Toolkit (NLTK): URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File ReadgrypeCVE-2026-54293EPSS 0.6%
- Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loadinggrypeCVE-2026-55379EPSS 0.4%
- Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`grypeCVE-2026-55380EPSS 0.4%
- Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loadinggrypeCVE-2026-54059EPSS 0.4%
- Pillow affected by out-of-bounds write when loading PSD imagesgrypeCVE-2026-25990EPSS 0.4%
- Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)grypeCVE-2026-42311EPSS 0.1%
- Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of servicegrypeCVE-2026-59204EPSS 0.4%
- Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`grypeCVE-2026-54060EPSS 0.4%
- Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatchgrypeCVE-2026-59205EPSS 0.4%
- Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()grypeCVE-2026-59200EPSS 0.4%
- Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflowgrypeCVE-2026-59199EPSS 0.4%
- Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`grypeCVE-2026-59197EPSS 0.4%
- Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)grypeCVE-2026-54058EPSS 0.4%
- PyJWT accepts unknown `crit` header extensionsgrypeCVE-2026-32597EPSS 0.3%
- PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowedgrypeCVE-2026-48526EPSS 0.4%
- pypdf: Possible infinite loop for not terminated inline imagesgrypeCVE-2026-59936EPSS 0.3%
- pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)grypeCVE-2026-59935EPSS 0.4%
- python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of servicegrypeCVE-2026-53539EPSS 0.4%
- Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector ListsgrypeCVE-2026-49476EPSS 0.4%
- Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector ParsergrypeCVE-2026-49477EPSS 0.4%
- Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoSgrypeCVE-2026-54283EPSS 0.4%
- Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on WindowsgrypeCVE-2026-48818EPSS 0.4%
- tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)grypeCVE-2026-49855EPSS 0.6%
- Tornado has cookie attribute injection via .RequestHandler.set_cookiegrypeCVE-2026-35536EPSS 0.2%
- Tornado is vulnerable to DoS due to too many multipart partsgrypeCVE-2026-31958EPSS 0.4%
- Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClientgrypeCVE-2026-49853EPSS 0.4%
- urllib3: Decompression-bomb safeguards bypassed in parts of the streaming APIgrypeCVE-2026-44432EPSS 0.7%
- urllib3: Sensitive headers forwarded across origins in proxied low-level redirectsgrypeCVE-2026-44431EPSS 0.3%
- Vulnerable OpenSSL included in cryptography wheelsgrype
- pickle.load/loads on non-constant data executes arbitrary code on deserialize. Use JSON or a signed/whitelisted format for untrusted input. (Apache-2.0.)pickle.load/loads on non-constant data executes arbitrary code on deserialize. Use JSON or a signed/whitelisted format for untrusted input. (Apache-2.0.)semgrepprivate_gpt/components/cache/cache_service.py:102
- pickle.load/loads on non-constant data executes arbitrary code on deserialize. Use JSON or a signed/whitelisted format for untrusted input. (Apache-2.0.)pickle.load/loads on non-constant data executes arbitrary code on deserialize. Use JSON or a signed/whitelisted format for untrusted input. (Apache-2.0.)semgrepprivate_gpt/components/readers/nodes/v2/document_node_v2.py:45
- Image user should not be 'root'Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.trivyDockerfile:0
This report is public.