← Scan another repo

github.com/zylon-ai/private-gpt

@ b94e70741be3

Submitted 8/4/2026, 10:27:37 AM · Status: ok

Risk grade
F
100 / 100
Findings
385
0 critical49 high312 medium22 low2 info0 on CISA KEV0ATT&CK
Showing 385 of 385 findings

Findings

  • Detected facebook-page-access-token: Discovered a Facebook Page Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposure
    Discovered a Facebook Page Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposure.
    gitleaks
  • Detected facebook-page-access-token: Discovered a Facebook Page Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposure
    Discovered a Facebook Page Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposure.
    gitleaks
  • Detected facebook-page-access-token: Discovered a Facebook Page Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposure
    Discovered a Facebook Page Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposure.
    gitleaks
  • Detected facebook-page-access-token: Discovered a Facebook Page Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposure
    Discovered a Facebook Page Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposure.
    gitleaks
  • Detected facebook-page-access-token: Discovered a Facebook Page Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposure
    Discovered a Facebook Page Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposure.
    gitleaks
  • Detected facebook-page-access-token: Discovered a Facebook Page Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposure
    Discovered a Facebook Page Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposure.
    gitleaks
  • Detected facebook-page-access-token: Discovered a Facebook Page Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposure
    Discovered a Facebook Page Access Token, posing a risk of unauthorized access to Facebook accounts and personal data exposure.
    gitleaks
  • `lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes
    grypeCVE-2026-49825
  • FITS GZIP decompression bomb in Pillow
    grypeCVE-2026-40192EPSS 0.7%
  • LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists
    grypeCVE-2026-44843EPSS 0.4%
  • LangSmith SDK TracingMiddleware: Arbitrary server-side file read
    grype
  • LangSmith SDK: Public prompt pull deserializes untrusted manifests without trust boundary warning
    grypeCVE-2026-45134EPSS 0.2%
  • lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files
    grypeCVE-2026-41066EPSS 0.3%
  • Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions
    grypeCVE-2026-59928EPSS 0.4%
  • Mistune inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
    grypeCVE-2026-59925EPSS 0.4%
  • Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)
    grypeCVE-2026-59922EPSS 0.4%
  • Mistune: Potential DoS via quadratic-time parsing in parse_link_text
    grypeCVE-2026-49851EPSS 0.4%
  • Natural Language Toolkit (NLTK): URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File Read
    grypeCVE-2026-54293EPSS 0.6%
  • Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
    grypeCVE-2026-55379EPSS 0.4%
  • Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`
    grypeCVE-2026-55380EPSS 0.4%
  • Pillow `PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading
    grypeCVE-2026-54059EPSS 0.4%
  • Pillow affected by out-of-bounds write when loading PSD images
    grypeCVE-2026-25990EPSS 0.4%
  • Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)
    grypeCVE-2026-42311EPSS 0.1%
  • Pillow JPEG2000 tiled decode retains a growing scratch buffer and can be used for denial of service
    grypeCVE-2026-59204EPSS 0.4%
  • Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`
    grypeCVE-2026-54060EPSS 0.4%
  • Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch
    grypeCVE-2026-59205EPSS 0.4%
  • Pillow: Decompression Bomb DoS via PdfParser.PdfStream.decode()
    grypeCVE-2026-59200EPSS 0.4%
  • Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow
    grypeCVE-2026-59199EPSS 0.4%
  • Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`
    grypeCVE-2026-59197EPSS 0.4%
  • Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
    grypeCVE-2026-54058EPSS 0.4%
  • PyJWT accepts unknown `crit` header extensions
    grypeCVE-2026-32597EPSS 0.3%
  • PyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowed
    grypeCVE-2026-48526EPSS 0.4%
  • pypdf: Possible infinite loop for not terminated inline images
    grypeCVE-2026-59936EPSS 0.3%
  • pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)
    grypeCVE-2026-59935EPSS 0.4%
  • python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service
    grypeCVE-2026-53539EPSS 0.4%
  • Soup Sieve has Memory Exhaustion via Large Comma-Separated Selector Lists
    grypeCVE-2026-49476EPSS 0.4%
  • Soup Sieve: Regular Expression Denial of Service (ReDoS) via Selector Parser
    grypeCVE-2026-49477EPSS 0.4%
  • Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS
    grypeCVE-2026-54283EPSS 0.4%
  • Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows
    grypeCVE-2026-48818EPSS 0.4%
  • tornado AsyncHTTPClient accumulates decompressed chunks without size limit (gzip bomb)
    grypeCVE-2026-49855EPSS 0.6%
  • Tornado has cookie attribute injection via .RequestHandler.set_cookie
    grypeCVE-2026-35536EPSS 0.2%
  • Tornado is vulnerable to DoS due to too many multipart parts
    grypeCVE-2026-31958EPSS 0.4%
  • Tornado: Authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient
    grypeCVE-2026-49853EPSS 0.4%
  • urllib3: Decompression-bomb safeguards bypassed in parts of the streaming API
    grypeCVE-2026-44432EPSS 0.7%
  • urllib3: Sensitive headers forwarded across origins in proxied low-level redirects
    grypeCVE-2026-44431EPSS 0.3%
  • Vulnerable OpenSSL included in cryptography wheels
    grype
  • pickle.load/loads on non-constant data executes arbitrary code on deserialize. Use JSON or a signed/whitelisted format for untrusted input. (Apache-2.0.)
    pickle.load/loads on non-constant data executes arbitrary code on deserialize. Use JSON or a signed/whitelisted format for untrusted input. (Apache-2.0.)
    semgrepprivate_gpt/components/cache/cache_service.py:102
  • pickle.load/loads on non-constant data executes arbitrary code on deserialize. Use JSON or a signed/whitelisted format for untrusted input. (Apache-2.0.)
    pickle.load/loads on non-constant data executes arbitrary code on deserialize. Use JSON or a signed/whitelisted format for untrusted input. (Apache-2.0.)
    semgrepprivate_gpt/components/readers/nodes/v2/document_node_v2.py:45
  • Image user should not be 'root'
    Running containers with 'root' user can lead to a container escape situation. It is a best practice to run containers as non-root users, which can be done by adding a 'USER' statement to the Dockerfile.
    trivyDockerfile:0

This report is public.