{"data":{"ecosystem":"pypi","name":"text-generation","url":"https://aisecwatch.com/packages/pypi/text-generation","latestVersion":"0.7.0","firstReleaseAt":"2023-03-07T17:11:29.378Z","repository":"https://github.com/huggingface/text-generation-inference","llm":{"exposure":"direct","depth":0,"integratedAt":"2023-03-07T17:11:29.378Z","integratedVersion":"0.1.0","sdks":["huggingface"],"path":[]},"authority":{"profile":["http"],"fromDependencies":["pypi:aiohttp"]},"dependencies":[{"ecosystem":"pypi","name":"huggingface-hub","versionSpec":"<1.0,>=0.12","scope":"runtime"},{"ecosystem":"pypi","name":"aiohttp","versionSpec":"<4.0,>=3.8","scope":"runtime"},{"ecosystem":"pypi","name":"pydantic","versionSpec":"<3,>2","scope":"runtime"}],"advisories":[{"id":"8566a696-2386-40af-8fdd-22506d2679bf","url":"https://aisecwatch.com/issues/8566a696-2386-40af-8fdd-22506d2679bf","cveId":"CVE-2026-0599","title":"CVE-2026-0599: A vulnerability in huggingface/text-generation-inference version 3.3.6 allows unauthenticated remote attackers to…","headline":null,"severity":"high","publishedAt":"2026-02-02T16:16:17.773Z","affected":["text-generation@< 3.3.7 (fixed: 3.3.7)"],"epssScore":0.29877},{"id":"8273cc80-4edf-4472-a527-7b141b84e335","url":"https://aisecwatch.com/issues/8273cc80-4edf-4472-a527-7b141b84e335","cveId":"CVE-2024-3924","title":"CVE-2024-3924: A code injection vulnerability exists in the huggingface/text-generation-inference repository, specifically within the…","headline":null,"severity":"high","publishedAt":"2024-05-30T19:15:49.653Z","affected":["text-generation@< 2.0.0 (fixed: 2.0.0)"],"epssScore":0.00319}],"checkedAt":"2026-10-09T21:54:17.873Z"},"meta":{"advisoryMatching":"by package name; advisory records do not state an ecosystem"}}