pypi package report

Is deepdiff safe?

2 known vulnerabilities, worst severity CRITICAL.

cvss
10.0

how bad it is if exploited, out of 10

epss
1.1%

chance of exploitation in the next 30 days

xyz score
5.2

CyberXYZ composite, out of 10

fig. 01 — GHSA-mw26-5g2v-hqw3, the advisory selected below

// advisories

GHSA-mw26-5g2v-hqw3

CRITICALCVE-2025-58367

[Python class pollution](https://blog.abdulrah33m.com/prototype-pollution-in-python/) is a novel vulnerability categorized under [CWE-915](https://cwe.mitre.org/data/definitions/915.html). The Delta class is vulnerable to class pollution via its constructor, and when combined with a gadget available in DeltaDiff itself, it can lead to Denial of Service and Remote Code Execution (via insecure [Pick

Affected
>= 5.0.0, <= 8.6.0
Fixed in
8.6.1
Weakness
CWE-915
Published
2025-09-03
Source
github

GHSANVDMITREreferencereferencereferencereferencereference


// dependencies

10 direct, 3 carrying known advisories, worst CRITICAL

Sign in for dependency paths and remediation

// ai model usage

No published models are known to use this package.


Checked 2026-09-22 at 01:34 UTC. The most recent advisory here was published 2026-03-18. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is deepdiff safe? pypi package security report | CyberXYZ