{"data":{"ecosystem":"pypi","name":"haystack-ai","url":"https://aisecwatch.com/packages/pypi/haystack-ai","latestVersion":"3.3.0","firstReleaseAt":"2023-11-24T16:43:38.441Z","repository":"https://github.com/deepset-ai/haystack/actions","llm":{"exposure":"direct","depth":0,"integratedAt":"2023-11-24T16:43:38.441Z","integratedVersion":"2.0.0a1","sdks":["haystack"],"path":[]},"authority":{"profile":["http"],"fromDependencies":["pypi:httpx"]},"dependencies":[{"ecosystem":"pypi","name":"openai","versionSpec":">=2.6.0","scope":"runtime"},{"ecosystem":"pypi","name":"posthog","versionSpec":"!=3.12.0","scope":"runtime"},{"ecosystem":"pypi","name":"anyio","versionSpec":">=4.14.2","scope":"runtime"},{"ecosystem":"pypi","name":"docstring-parser","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"filetype","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"httpx","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"jinja2","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"jsonschema","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"lazy-imports","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"markupsafe","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"more-itertools","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"networkx","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"numpy","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"pydantic","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"python-dateutil","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"pyyaml","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"tenacity","versionSpec":"!=8.4.0","scope":"runtime"},{"ecosystem":"pypi","name":"tqdm","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"typing-extensions","versionSpec":">=4.7","scope":"runtime"}],"advisories":[{"id":"58825d91-dce3-4aea-8897-c9c843305765","url":"https://aisecwatch.com/issues/58825d91-dce3-4aea-8897-c9c843305765","cveId":"CVE-2024-41950","title":"CVE-2024-41950: Haystack is an end-to-end LLM framework that allows you to build applications powered by LLMs, Transformer models…","headline":"Haystack remote code execution through user-created Jinja2 templates","severity":"high","publishedAt":"2024-07-31T20:15:04.797Z","affected":["haystack-ai@< 2.3.1 (fixed: 2.3.1)"],"epssScore":0.01171}],"checkedAt":"2026-10-09T21:48:35.187Z"},"meta":{"advisoryMatching":"by package name; advisory records do not state an ecosystem"}}