Loading report…
← nittim
These are facts from deterministic scanners, not opinion — 1 committed production secret and 13 high/critical dependency vulnerabilities. The full picture — architecture, AI-generated-code risk, privacy, and 11 more dimensions — needs Audit.
These are facts found by automatic checks, not opinions — 1 password or key found in code that ships to production and 13 serious security bugs in the ready-made packages your project uses. The full picture — how your code is built, AI-generated-code risk, privacy, and 11 more areas — needs Audit.
1 committed secret and 13 critical dependency vulnerabilities found. 11 more dimensions need Audit for the full picture.
352 of 5031 files scanned (6%) — this snapshot was truncated: this audit's size limit was reached, so some source was left unread.
Two scanners read 352 of 5031 files, starting with the highest-priority ones: one for committed credentials, one for known vulnerabilities in your dependencies. They found 1 committed credential on production paths and 13 high or critical vulnerabilities in runtime dependencies. These two checks cover a narrow slice of what decides whether software is ready to ship. All 14 dimensions — architecture, privacy, reliability, AI-generated-code risk and the rest — are unexamined here. Deep Verification is the tier that issues a verdict. This scan does not.
48.0.0 — GHSA-537c-gmf6-5ccf, GHSA-g6cj-pr64-35w5, GHSA-jwv3-5hgf-82ww
Vulnerable OpenSSL included in cryptography wheels — HIGH
cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing — HIGH
python-cryptography: Duplicate self-signed intermediates can cause exponential path-building — HIGH
3.9.4 — GHSA-6hm5-jgcp-p838, GHSA-fg7f-2386-8897, GHSA-m42h-3232-vpv3
Natural Language Toolkit (NLTK): Path Traversal in NKJPCorpusReader leads to Arbitrary File Read and bypasses the nltk.pathsec sandbox (ENFORCE=True) — HIGH
Natural Language Toolkit (NLTK): ReDoS in NLTK ReviewsCorpusReader FEATURES regex — HIGH
nltk: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences — HIGH
12.2.0 — GHSA-45hq-cxwh-f6vc, GHSA-5x94-69rx-g8h2
Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading — HIGH
Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()` — HIGH
20.0.0 — GHSA-rgxp-2hwp-jwgg, PYSEC-2026-113
Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering — HIGH
Use After Free vulnerability in Apache Arrow C++. This issue affects Apache Arrow C++ from 15.0.0 through 23.0.0. It can be triggered when reading an Arrow IPC file (but not an IPC stream) with pre-b — CVSS CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
2.68.0 — GHSA-29g2-3rmr-qm68, GHSA-866w-xmhq-wj7x, GHSA-wqjv-9729-c5q2
SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header — MODERATE
SvelteKit: Prototype pollution in file input deletion path in remote-function forms — MODERATE
SvelteKit: Big remote form function payloads can cause Node process to crash — MODERATE
3.13.5 — GHSA-2fqr-mr3j-6wp8, GHSA-4fvr-rgm6-gqmc, GHSA-4m7w-qmgq-4wj5
aiohttp: Host-Only Cookies Become Domain Cookies After CookieJar Persistence — LOW
aiohttp: HTTP/1 Pipelined Requests Queue Without Limit — MODERATE
aiohttp: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections — LOW
0.86.0 — GHSA-q5f5-3gjm-7mfm, GHSA-w828-4qhx-vxx3, PYSEC-2026-2114
Claude SDK for Python has Insecure Default File Permissions in Local Filesystem Memory Tool — MODERATE
Claude SDK for Python: Memory Tool Path Validation Race Condition Allows Sandbox Escape — MODERATE
The Claude SDK for Python provides access to the Claude API from Python applications. From version 0.86.0 to before version 0.87.0, the local filesystem memory tool in the Anthropic Python SDK created — CVSS CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
5.0.6 — GHSA-3jxr-9vmj-r5cp, GHSA-mh99-v99m-4gvg, GHSA-rgw5-rvv9-x895
brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups — devDependency
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash — devDependency
brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation — devDependency
6.7.5 — GHSA-248m-82v9-q6g6, GHSA-3crg-w4f6-42mx, GHSA-4pxv-j86v-mhcw
pypdf: Possible long runtimes for zero-only width values in cross-reference streamsuntimes for zero-only width values in cross-reference streams — MODERATE
pypdf: Manipulated XMP metadata entity declarations can exhaust RAM — MODERATE
pypdf: Possible long runtimes for wrong size values in incremental mode — MODERATE
1.2.10 — GHSA-gr75-jv2w-4656, PYSEC-2026-2192
LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders — MODERATE
LangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that resolve filesystem paths or expand search patterns do not consistently conf — CVSS CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
10.21.3 — GHSA-9xwg-3r6f-jcx2, PYSEC-2026-3609
PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path — MODERATE
PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path — CVSS CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Security logic, privacy, reliability, AI-generated-code risk and 10 more — unaudited, not clean.Security logic, privacy, reliability, AI-generated-code risk and 10 more — not checked yet, which is different from safe.Security, privacy, reliability, AI-generated-code risk, 10 more: unaudited, not clean.
The free scan reasons across none of these. Absence of findings is reported as unaudited, not safe. Opus 4.8 reads the code semantically and scores every one — with evidence, business impact, and a fix per finding.
The free scan doesn't look at any of these. If nothing is flagged here, that means it wasn't checked — not that it's safe. Opus 4.8 (the AI model behind the audit) reads and understands your code and scores every one of these — with evidence, the real-world impact, and a fix for each finding.
The free scan doesn't reason across these — unaudited, not safe. Opus 4.8 scores each, with evidence, impact, and a fix.
Scanned 352 of 5031 files (highest-priority subset) · open-webui/open-webui
Dependency manifests: 1 package root found, 1 scanned; 2 Python manifests read — package list truncated at the vulnerability-lookup limit.
[](https://nittim.com)