Cheetah 0.9.15 and 0.9.16 searches the /tmp directory for modules before using the paths in the PYTHONPATH variable, which allows local users to execute arbitrary code via a malicious module in /tmp/.
pypi package report
Is cheetah safe?
1 known vulnerability, worst severity HIGH.
// reach
0 direct dependencies
none carry a known advisory
Create a free accountfor every dependency path, dependent and what to upgrade
// ai model usage
No published models are known to use this package.
cvss
0.0
high
severity band, no base score published
epss
0.00%
medium
chance of exploitation in 30 days, 36th percentile of all CVEs
xyz score
0.0
low
CyberXYZ composite out of 10
fig. 01 — GHSA-vxf2-7rc3-pxmx, the advisory selected below
// 1 advisories
Checked 2026-10-04 at 01:14 UTC. The most recent advisory here was published 2022-05-01. Updated continuously from NVD, GHSA, OSV and CNA feeds.