{"data":{"ecosystem":"pypi","name":"streamlit","url":"https://aisecwatch.com/packages/pypi/streamlit","latestVersion":"1.65.0","firstReleaseAt":"2018-03-20T18:00:56.464Z","repository":"https://github.com/streamlit/streamlit","llm":{"exposure":"none","depth":null,"integratedAt":null,"integratedVersion":null,"sdks":[],"path":[]},"authority":{"profile":["filesystem","http"],"fromDependencies":["pypi:httpx","pypi:requests","pypi:watchdog"]},"dependencies":[{"ecosystem":"pypi","name":"altair","versionSpec":"!=5.4.0,!=5.4.1,<7,>=5.0.0","scope":"runtime"},{"ecosystem":"pypi","name":"anyio","versionSpec":"<5,>=4.0.0","scope":"runtime"},{"ecosystem":"pypi","name":"authlib","versionSpec":">=1.3.2","scope":"extra:auth"},{"ecosystem":"pypi","name":"click","versionSpec":"<9,>=7.0","scope":"runtime"},{"ecosystem":"pypi","name":"graphviz","versionSpec":">=0.19.0","scope":"extra:charts"},{"ecosystem":"pypi","name":"httptools","versionSpec":"<1,>=0.6.3","scope":"runtime"},{"ecosystem":"pypi","name":"httpx","versionSpec":">=0.24.1","scope":"extra:auth"},{"ecosystem":"pypi","name":"itsdangerous","versionSpec":"<3,>=2.1.2","scope":"runtime"},{"ecosystem":"pypi","name":"matplotlib","versionSpec":">=3.0.0","scope":"extra:charts"},{"ecosystem":"pypi","name":"numpy","versionSpec":"<3,>=1.23","scope":"runtime"},{"ecosystem":"pypi","name":"orjson","versionSpec":">=3.5.0","scope":"extra:charts"},{"ecosystem":"pypi","name":"packaging","versionSpec":">=20","scope":"runtime"},{"ecosystem":"pypi","name":"pandas","versionSpec":"<4,>=1.4.0","scope":"runtime"},{"ecosystem":"pypi","name":"pillow","versionSpec":"<13,>=7.1.0","scope":"runtime"},{"ecosystem":"pypi","name":"plotly","versionSpec":">=4.0.0","scope":"extra:charts"},{"ecosystem":"pypi","name":"protobuf","versionSpec":"<8,>=5.26.1","scope":"runtime"},{"ecosystem":"pypi","name":"pyarrow","versionSpec":"!=25.0.0,<26,>=7.0","scope":"runtime"},{"ecosystem":"pypi","name":"pydeck","versionSpec":"<1,>=0.8.0b4","scope":"runtime"},{"ecosystem":"pypi","name":"python-multipart","versionSpec":"<1,>=0.0.10","scope":"runtime"},{"ecosystem":"pypi","name":"requests","versionSpec":"<3,>=2.27","scope":"runtime"},{"ecosystem":"pypi","name":"rich","versionSpec":">=11.0.0","scope":"extra:all"},{"ecosystem":"pypi","name":"snowflake-connector-python","versionSpec":">=3.3.0","scope":"extra:snowflake"},{"ecosystem":"pypi","name":"snowflake-snowpark-python","versionSpec":">=1.17.0","scope":"extra:snowflake"},{"ecosystem":"pypi","name":"sqlalchemy","versionSpec":">=2.0.0","scope":"extra:sql"},{"ecosystem":"pypi","name":"starlette","versionSpec":"<2,>=0.46.0","scope":"runtime"},{"ecosystem":"pypi","name":"streamlit-pdf","versionSpec":">=2.1.0","scope":"extra:pdf"},{"ecosystem":"pypi","name":"toml","versionSpec":"<2,>=0.10.1","scope":"runtime"},{"ecosystem":"pypi","name":"typing-extensions","versionSpec":"<5,>=4.10.0","scope":"runtime"},{"ecosystem":"pypi","name":"uvicorn","versionSpec":"<1,>=0.30.0","scope":"runtime"},{"ecosystem":"pypi","name":"uvloop","versionSpec":">=0.15.2","scope":"extra:performance"},{"ecosystem":"pypi","name":"watchdog","versionSpec":"<7,>=2.1.5","scope":"runtime"},{"ecosystem":"pypi","name":"websockets","versionSpec":"<18,>=12.0.0","scope":"runtime"}],"advisories":[{"id":"11efa100-3065-4f4b-a1ed-836ba11fb36b","url":"https://aisecwatch.com/issues/11efa100-3065-4f4b-a1ed-836ba11fb36b","cveId":"CVE-2026-10804","title":"CVE-2026-10804: A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library…","headline":"Streamlit weak hash in palette handler caching","severity":"low","publishedAt":"2026-06-04T12:16:24.620Z","affected":["streamlit@< 1.53.1 (fixed: 1.53.1)"],"epssScore":0.00083},{"id":"e49ac6a3-cf6d-4afc-b0f2-926e29fb291e","url":"https://aisecwatch.com/issues/e49ac6a3-cf6d-4afc-b0f2-926e29fb291e","cveId":"CVE-2024-42474","title":"CVE-2024-42474: Streamlit is a data oriented application development framework for python. Snowflake Streamlit open source addressed a…","headline":"Streamlit path traversal through static file sharing on Windows","severity":"medium","publishedAt":"2024-08-12T21:15:17.513Z","affected":["streamlit@< 1.37.0 (fixed: 1.37.0)"],"epssScore":0.00568},{"id":"41eaa91c-f59f-46b7-b23a-03c8d55c2be9","url":"https://aisecwatch.com/issues/41eaa91c-f59f-46b7-b23a-03c8d55c2be9","cveId":"CVE-2023-27494","title":"CVE-2023-27494: Streamlit, software for turning data scripts into web applications, had a cross-site scripting (XSS) vulnerability in…","headline":null,"severity":"medium","publishedAt":"2023-03-17T01:15:13.270Z","affected":["streamlit@>= 0.63.0, < 0.81.0 (fixed: 0.81.0)"],"epssScore":0.0041},{"id":"bda515e4-35db-4d85-9c28-91370e017213","url":"https://aisecwatch.com/issues/bda515e4-35db-4d85-9c28-91370e017213","cveId":"CVE-2022-35918","title":"CVE-2022-35918: Streamlit is a data oriented application development framework for python. Users hosting Streamlit app(s) that use…","headline":"Streamlit directory traversal in custom components leaks server files","severity":"medium","publishedAt":"2022-08-02T02:15:10.223Z","affected":["streamlit@>= 0.63.0, < 1.11.1 (fixed: 1.11.1)"],"epssScore":0.01716}],"checkedAt":"2026-10-09T21:57:19.975Z"},"meta":{"advisoryMatching":"by package name; advisory records do not state an ecosystem"}}