VYPR

Streamlit

by Snowflake

pypi: streamlit

Source repositories

CVEs (5)

  • CVE-2024-42474MedAug 12, 2024
    risk 0.35cvss 6.5epss 0.01

    Streamlit is a data oriented application development framework for python. Snowflake Streamlit open source addressed a security vulnerability via the static file sharing feature. Users of hosted Streamlit app(s) on Windows were vulnerable to a path traversal vulnerability when…

  • CVE-2022-35918MedAug 1, 2022
    risk 0.35cvss 6.5epss 0.02

    Streamlit is a data oriented application development framework for python. Users hosting Streamlit app(s) that use custom components are vulnerable to a directory traversal attack that could leak data from their web server file-system such as: server logs, world readable files,…

  • CVE-2023-27494MedMar 16, 2023
    risk 0.31cvss 5.9epss 0.00

    Streamlit, software for turning data scripts into web applications, had a cross-site scripting (XSS) vulnerability in versions 0.63.0 through 0.80.0. Users of hosted Streamlit app(s) were vulnerable to a reflected XSS vulnerability. An attacker could craft a malicious URL with…

  • CVE-2026-33682MedMar 26, 2026
    risk 0.24cvss 4.7epss 0.00

    Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of…

  • CVE-2026-10804LowJun 4, 2026
    risk 0.16cvss 3.6epss 0.00

    A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access is required to approach this attack. The…