{"data":{"ecosystem":"pypi","name":"mesop","url":"https://aisecwatch.com/packages/pypi/mesop","latestVersion":"1.3.7","firstReleaseAt":"2023-12-13T06:18:35.839Z","repository":"https://github.com/mesop-dev/mesop","llm":{"exposure":"none","depth":null,"integratedAt":null,"integratedVersion":null,"sdks":[],"path":[]},"authority":{"profile":["filesystem"],"fromDependencies":["pypi:watchdog"]},"dependencies":[{"ecosystem":"pypi","name":"absl-py","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"deepdiff","versionSpec":"<9,>=8.6.1","scope":"runtime"},{"ecosystem":"pypi","name":"flask","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"msgpack","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"protobuf","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"pydantic","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"python-dotenv","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"watchdog","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"werkzeug","versionSpec":">=3.0.6","scope":"runtime"}],"advisories":[{"id":"d00fa48e-7f5e-474e-8e66-79dc4d59989b","url":"https://aisecwatch.com/issues/d00fa48e-7f5e-474e-8e66-79dc4d59989b","cveId":"CVE-2026-34824","title":"GHSA-3jr7-6hqp-x679: Mesop: Unbounded Thread Creation in WebSocket Handler Leads to Denial of Service","headline":null,"severity":"high","publishedAt":"2026-04-03T21:54:36.000Z","affected":["mesop@>= 1.2.3, < 1.2.5 (fixed: 1.2.5)"],"epssScore":0.00672},{"id":"fc152021-e34c-4e8c-9d8a-b9d3237e3b9d","url":"https://aisecwatch.com/issues/fc152021-e34c-4e8c-9d8a-b9d3237e3b9d","cveId":"CVE-2026-33057","title":"GHSA-gjgx-rvqr-6w6v: Mesop Affected by Unauthenticated Remote Code Execution via Test Suite Route /exec-py","headline":null,"severity":"critical","publishedAt":"2026-03-18T20:05:00.000Z","affected":["mesop@<= 1.2.2 (fixed: 1.2.3)"],"epssScore":0.04111},{"id":"0dea3171-59e5-45da-8bf4-ecbba609e248","url":"https://aisecwatch.com/issues/0dea3171-59e5-45da-8bf4-ecbba609e248","cveId":"CVE-2026-33054","title":"GHSA-8qvf-mr4w-9x2c: Mesop has a Path Traversal utilizing `FileStateSessionBackend` leads to Application Denial of Service and File Write/Deletion","headline":null,"severity":"critical","publishedAt":"2026-03-18T20:01:21.000Z","affected":["mesop@<= 1.2.2 (fixed: 1.2.3)"],"epssScore":0.00702},{"id":"d85fa0b7-c237-48ca-9e99-cf669996a0c5","url":"https://aisecwatch.com/issues/d85fa0b7-c237-48ca-9e99-cf669996a0c5","cveId":"CVE-2025-30358","title":"CVE-2025-30358: Mesop is a Python-based UI framework that allows users to build web applications. A class pollution vulnerability in…","headline":"Mesop class pollution allows overwriting global variables at runtime","severity":"high","publishedAt":"2025-03-27T15:16:02.297Z","affected":["mesop@< 0.14.1 (fixed: 0.14.1)"],"epssScore":0.00704}],"checkedAt":"2026-10-09T21:57:32.716Z"},"meta":{"advisoryMatching":"by package name; advisory records do not state an ecosystem"}}