pypi package report

Is tqdm safe?

2 known vulnerabilities, worst severity HIGH.

cvss
7.5

how bad it is if exploited, out of 10

epss
0.50%

chance of exploitation in the next 30 days

xyz score
5.1

CyberXYZ composite, out of 10

fig. 01 — GHSA-r7q7-xcjw-qx8q, the advisory selected below

// advisories

GHSA-r7q7-xcjw-qx8q

HIGHCVE-2016-10075

The tqdm.version module in tqdm versions 4.4.1 and 4.10 allows local users to execute arbitrary code via a crafted repo with a malicious git log in the current working directory.

Affected
= 4.10.0, = 4.4.1
Fixed in
4.11.2
Weakness
CWE-94
Published
2022-05-14
Source
github

GHSANVDMITREreferencereferencereferencereferencereferencereference


// dependencies

11 direct, 2 carrying known advisories, worst HIGH

Sign in for dependency paths and remediation

// ai model usage

64 published models

2 declared · 62 observed · 0 inferred

ModelEvidence
ZhengPeng7/BiRefNetdeclared
ZhengPeng7/BiRefNet_litedeclared

Sign in to see all 62 models and per-model risk

64 published AI models are associated with this package: 2 name it in a requirements or pyproject file, 62 load it or import it directly, and 0 are inferred from the runtime stack their declared library pulls in. Only 0 state a version requirement, so this is not a count of affected models.


Checked 2026-09-22 at 02:41 UTC. The most recent advisory here was published 2024-05-03. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is tqdm safe? pypi package security report | CyberXYZ