pypi package report

Is text-generation safe?

2 known vulnerabilities, worst severity HIGH.

cvss
7.5

how bad it is if exploited, out of 10

epss
27.6%

chance of exploitation in the next 30 days

xyz score
4.3

CyberXYZ composite, out of 10

fig. 01 — GHSA-j7x9-7j54-2v3h, the advisory selected below

// advisories

GHSA-j7x9-7j54-2v3h

HIGHCVE-2026-0599

A vulnerability in huggingface/text-generation-inference version 3.3.6 allows unauthenticated remote attackers to exploit unbounded external image fetching during input validation in VLM mode. The issue arises when the router scans inputs for Markdown image links and performs a blocking HTTP GET request, reading the entire response body into memory and cloning it before decoding. This behavior can

Affected
< 3.3.7
Fixed in
3.3.7
Weakness
CWE-400
Published
2026-02-02
Source
github

GHSANVDMITREreferencereference


// ai model usage

No published models are known to use this package.


Checked 2026-09-22 at 00:44 UTC. The most recent advisory here was published 2026-02-02. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is text-generation safe? pypi package security report | CyberXYZ