Skip to content

ai-scribe-0.1.0: 2 vulnerabilities (highest severity is: 6.8) [main] #1049

Description

@renovate
📂 Vulnerable Library - ai-scribe-0.1.0

Path to dependency file: /pyproject.toml

Path to vulnerable library: /.venv/lib/python3.12/site-packages/ai_scribe-0.1.0.dist-info

Findings

Finding Severity 🎯 CVSS Exploit Maturity EPSS Library Type Fixed in Remediation Available
CVE-2025-71176 🟠 Medium 6.8 Not Defined < 1% pytest-8.4.1-py3-none-any.whl Transitive N/A
CVE-2026-4539 🟡 Low 3.3 Proof of concept < 1% pygments-2.19.2-py3-none-any.whl Transitive N/A

Details

🟠CVE-2025-71176

Vulnerable Library - pytest-8.4.1-py3-none-any.whl

pytest: simple powerful testing with Python

Library home page: https://files.pythonhosted.org/packages/29/16/c8a903f4c4dffe7a12843191437d7cd8e32751d5de349d45d3fe69544e87/pytest-8.4.1-py3-none-any.whl

Path to dependency file: /pyproject.toml

Path to vulnerable library: /.venv/lib/python3.12/site-packages/pytest-8.4.1.dist-info

Dependency Hierarchy:

  • ai-scribe-0.1.0 (Root Library)
    • pytest-8.4.1-py3-none-any.whl (Vulnerable Library)

Vulnerability Details

pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.

Publish Date: Jan 22, 2026 04:59 AM

URL: CVE-2025-71176

Threat Assessment

Exploit Maturity:Not Defined

EPSS:< 1%

Score: 6.8


Suggested Fix

Type: Upgrade version

Origin:

Release Date:

Fix Resolution :

🟡CVE-2026-4539

Vulnerable Library - pygments-2.19.2-py3-none-any.whl

Pygments is a syntax highlighting package written in Python.

Library home page: https://files.pythonhosted.org/packages/c7/21/705964c7812476f378728bdf590ca4b771ec72385c533964653c68e86bdc/pygments-2.19.2-py3-none-any.whl

Path to dependency file: /pyproject.toml

Path to vulnerable library: /.venv/lib/python3.12/site-packages/pygments-2.19.2.dist-info

Dependency Hierarchy:

  • canvas-0.195.0-py3-none-any.whl (Root Library)

    • typer-0.16.0-py3-none-any.whl
      • rich-14.0.0-py3-none-any.whl
        • pygments-2.19.2-py3-none-any.whl (Vulnerable Library)
  • ai-scribe-0.1.0 (Root Library)

    • pytest-8.4.1-py3-none-any.whl
      • pygments-2.19.2-py3-none-any.whl (Vulnerable Library)

Vulnerability Details

A security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

Publish Date: Mar 22, 2026 05:35 AM

URL: CVE-2026-4539

Threat Assessment

Exploit Maturity:Proof of concept

EPSS:< 1%

Score: 3.3


Suggested Fix

Type: Upgrade version

Origin:

Release Date:

Fix Resolution :

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

dependenciesPull requests that update a dependency file

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions