{"data":{"ecosystem":"pypi","name":"banks","url":"https://aisecwatch.com/packages/pypi/banks","latestVersion":"2.5.1","firstReleaseAt":"2023-06-04T14:14:38.988Z","repository":"https://github.com/masci/banks","llm":{"exposure":"direct","depth":0,"integratedAt":"2023-06-04T14:25:09.323Z","integratedVersion":"0.0.3","sdks":["litellm"],"path":[]},"authority":{"profile":[],"fromDependencies":[]},"dependencies":[{"ecosystem":"pypi","name":"litellm","versionSpec":null,"scope":"extra:all"},{"ecosystem":"pypi","name":"deprecated","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"eval-type-backport","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"filetype","versionSpec":">=1.2.0","scope":"runtime"},{"ecosystem":"pypi","name":"griffe","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"jinja2","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"platformdirs","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"pydantic","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"redis","versionSpec":null,"scope":"extra:all"},{"ecosystem":"pypi","name":"typing-extensions","versionSpec":null,"scope":"runtime"}],"advisories":[{"id":"3d0c50f4-41f0-438e-b01b-c719387ce622","url":"https://aisecwatch.com/issues/3d0c50f4-41f0-438e-b01b-c719387ce622","cveId":"CVE-2026-107717","title":"GHSA-hmq2-7hp6-7crh: Banks: User-controlled prompt input can be parsed as privileged chat messages","headline":null,"severity":"medium","publishedAt":"2026-10-08T22:10:01.000Z","affected":["banks@<= 2.4.5 (fixed: 2.5.0)"],"epssScore":0.00279,"matchedBy":"ecosystem"},{"id":"fecc9365-42bf-48ff-958c-3284c8c3e535","url":"https://aisecwatch.com/issues/fecc9365-42bf-48ff-958c-3284c8c3e535","cveId":"CVE-2026-44209","title":"GHSA-gphh-9q3h-jgpp: banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI","headline":null,"severity":"high","publishedAt":"2026-05-08T20:36:22.000Z","affected":["banks@<= 2.4.1 (fixed: 2.4.2)"],"epssScore":0.00737,"matchedBy":"ecosystem"}],"checkedAt":"2026-10-09T22:04:57.177Z"},"meta":{"advisoryMatching":"by package name and ecosystem; an advisory with no ecosystem recorded for the package is matched by name alone"}}