streamlit
A faster way to build and share data apps
No LLM SDK, agent framework or MCP dependency in its latest release, and none among the tracked dependencies.
Advisories
Advisories that name streamlit as affected. Advisory records do not state an ecosystem, so packages with the same name in other ecosystems also match. For a version-exact check of your own dependencies, use Stack Check.
| Advisory | Severity | Affected | Fixed in | Published |
|---|---|---|---|---|
| CVE-2026-10804CVE-2026-10804: A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library… | Low | < 1.53.1 | 1.53.1 | 2026-06-04 |
| CVE-2024-42474CVE-2024-42474: Streamlit is a data oriented application development framework for python. Snowflake Streamlit open source addressed a… | Medium | < 1.37.0 | 1.37.0 | 2024-08-12 |
| CVE-2023-27494CVE-2023-27494: Streamlit, software for turning data scripts into web applications, had a cross-site scripting (XSS) vulnerability in… | Medium | >= 0.63.0, < 0.81.0 | 0.81.0 | 2023-03-17 |
| CVE-2022-35918CVE-2022-35918: Streamlit is a data oriented application development framework for python. Users hosting Streamlit app(s) that use… | Medium | >= 0.63.0, < 1.11.1 | 1.11.1 | 2022-08-02 |
Dependencies of the latest release
As declared in PyPI metadata for version 1.65.0. Optional extras are listed with their extra name.
- altair
- anyio
- authlib[auth]
- click
- graphviz[charts]
- httptools
- httpx[auth]
- itsdangerous
- matplotlib[charts]
- numpy
- orjson[charts]
- packaging
- pandas
- pillow
- plotly[charts]
- protobuf
- pyarrow
- pydeck
- python-multipart
- requests
- rich[all]
- snowflake-connector-python[snowflake]
- snowflake-snowpark-python[snowflake]
- sqlalchemy[sql]
- starlette
- streamlit-pdf[pdf]
- toml
- typing-extensions
- uvicorn
- uvloop[performance]
- watchdog
- websockets
Tracked packages that depend on it
Among the packages in the registry; not every dependent on PyPI.