VYPR

Taipy

by Avaiga

pypi: taipy

Source repositories

CVEs (3)

  • CVE-2026-85183CriSep 3, 2026
    risk 0.53cvss 9.3epss 0.00

    Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page to establish credentialed WebSocket connections to victim applications. Attackers can open socket.io sessions from arbitrary domains and invoke state variable…

  • CVE-2026-48544HigMay 27, 2026
    risk 0.42cvss 7.5epss 0.01

    Taipy 4.1.1, fixed in commit 129fd40, contains a path traversal vulnerability in the ElementLibrary.get_resource() method in taipy/gui/extension/library.py that allows unauthenticated attackers to escape the intended module directory by exploiting an incomplete path containment…

  • CVE-2024-47833MedOct 9, 2024
    risk 0.42cvss 6.5epss 0.00

    Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine learning engineers. In affected versions session cookies are served without Secure and HTTPOnly flags. This issue has been addressed in release version 4.0.0 and…