cvss5.9
how bad it is if exploited, out of 10
epss1.1%
chance of exploitation in the next 30 days
xyz scorenot scored
CyberXYZ composite, out of 10
fig. 01 — GHSA-cr6p-23cf-w9g9, the advisory selected below
// advisories
GHSA-cr6p-23cf-w9g9
MODERATECVE-2022-31139Affected versions have no limit to using unsafe-accessor. Can be ignored if SecurityCheck.AccessLimiter not setup
- Affected
- >= 1.4.0, < 1.7.0
- Fixed in
- 1.7.0
- Weakness
- CWE-200
- Published
- 2022-07-12
- Source
- github
GHSANVDMITREreferencereferencereference
// ai model usageTracked for PyPI packages. HuggingFace models declare Python dependencies, so maven packages are not covered.
Checked 2026-09-22 at 01:50 UTC. The most recent advisory here was published 2022-07-12. Updated continuously from NVD, GHSA, OSV and CNA feeds.