📂 Vulnerable Library - ai-scribe-0.1.0
Path to dependency file: /pyproject.toml
Path to vulnerable library: /.venv/lib/python3.12/site-packages/ai_scribe-0.1.0.dist-info
Findings
| Finding |
Severity |
🎯 CVSS |
Exploit Maturity |
EPSS |
Library |
Type |
Fixed in |
Remediation Available |
| CVE-2025-71176 |
🟠 Medium |
6.8 |
Not Defined |
< 1% |
pytest-8.4.1-py3-none-any.whl |
Transitive |
N/A |
❌ |
| CVE-2026-4539 |
🟡 Low |
3.3 |
Proof of concept |
< 1% |
pygments-2.19.2-py3-none-any.whl |
Transitive |
N/A |
❌ |
Details
🟠CVE-2025-71176
Vulnerable Library - pytest-8.4.1-py3-none-any.whl
pytest: simple powerful testing with Python
Library home page: https://files.pythonhosted.org/packages/29/16/c8a903f4c4dffe7a12843191437d7cd8e32751d5de349d45d3fe69544e87/pytest-8.4.1-py3-none-any.whl
Path to dependency file: /pyproject.toml
Path to vulnerable library: /.venv/lib/python3.12/site-packages/pytest-8.4.1.dist-info
Dependency Hierarchy:
- ai-scribe-0.1.0 (Root Library)
- ❌ pytest-8.4.1-py3-none-any.whl (Vulnerable Library)
Vulnerability Details
pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.
Publish Date: Jan 22, 2026 04:59 AM
URL: CVE-2025-71176
Threat Assessment
Exploit Maturity:Not Defined
EPSS:< 1%
Score: 6.8
Suggested Fix
Type: Upgrade version
Origin:
Release Date:
Fix Resolution :
🟡CVE-2026-4539
Vulnerable Library - pygments-2.19.2-py3-none-any.whl
Pygments is a syntax highlighting package written in Python.
Library home page: https://files.pythonhosted.org/packages/c7/21/705964c7812476f378728bdf590ca4b771ec72385c533964653c68e86bdc/pygments-2.19.2-py3-none-any.whl
Path to dependency file: /pyproject.toml
Path to vulnerable library: /.venv/lib/python3.12/site-packages/pygments-2.19.2.dist-info
Dependency Hierarchy:
Vulnerability Details
A security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Publish Date: Mar 22, 2026 05:35 AM
URL: CVE-2026-4539
Threat Assessment
Exploit Maturity:Proof of concept
EPSS:< 1%
Score: 3.3
Suggested Fix
Type: Upgrade version
Origin:
Release Date:
Fix Resolution :
📂 Vulnerable Library - ai-scribe-0.1.0
Path to dependency file: /pyproject.toml
Path to vulnerable library: /.venv/lib/python3.12/site-packages/ai_scribe-0.1.0.dist-info
Findings
Details
🟠CVE-2025-71176
Vulnerable Library - pytest-8.4.1-py3-none-any.whl
pytest: simple powerful testing with Python
Library home page: https://files.pythonhosted.org/packages/29/16/c8a903f4c4dffe7a12843191437d7cd8e32751d5de349d45d3fe69544e87/pytest-8.4.1-py3-none-any.whl
Path to dependency file: /pyproject.toml
Path to vulnerable library: /.venv/lib/python3.12/site-packages/pytest-8.4.1.dist-info
Dependency Hierarchy:
Vulnerability Details
pytest through 9.0.2 on UNIX relies on directories with the /tmp/pytest-of-{user} name pattern, which allows local users to cause a denial of service or possibly gain privileges.
Publish Date: Jan 22, 2026 04:59 AM
URL: CVE-2025-71176
Threat Assessment
Exploit Maturity:Not Defined
EPSS:< 1%
Score: 6.8
Suggested Fix
Type: Upgrade version
Origin:
Release Date:
Fix Resolution :
🟡CVE-2026-4539
Vulnerable Library - pygments-2.19.2-py3-none-any.whl
Pygments is a syntax highlighting package written in Python.
Library home page: https://files.pythonhosted.org/packages/c7/21/705964c7812476f378728bdf590ca4b771ec72385c533964653c68e86bdc/pygments-2.19.2-py3-none-any.whl
Path to dependency file: /pyproject.toml
Path to vulnerable library: /.venv/lib/python3.12/site-packages/pygments-2.19.2.dist-info
Dependency Hierarchy:
canvas-0.195.0-py3-none-any.whl (Root Library)
ai-scribe-0.1.0 (Root Library)
Vulnerability Details
A security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity. The attack is only possible with local access. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
Publish Date: Mar 22, 2026 05:35 AM
URL: CVE-2026-4539
Threat Assessment
Exploit Maturity:Proof of concept
EPSS:< 1%
Score: 3.3
Suggested Fix
Type: Upgrade version
Origin:
Release Date:
Fix Resolution :