local-deep-research
PyPI3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting local-deep-researchpage 1 of 1
- CVE-2025-67743MEDIUMCVSS 6.3EG 6.3✓ Fixed in 1.3.92025-12-23
vulnerable: 1.3.0, 1.3.1, 1.3.6, 1.3.7, 1.3.8
Local Deep Research is an AI-powered research assistant for deep, iterative research. In versions from 1.3.0 to before 1.3.9, the download service (download_service.py) makes HTTP requests using raw requests.get() without utilizing the app…
- CVE-2026-43979MEDIUMCVSS 5.0EG 5.0✓ Fixed in 1.6.02026-05-28
vulnerable: 0.1.0 ... 1.5.6 (132 versions)
Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.0, PDFService._markdown_to_html() constructs an HTML document by interpolating user-controlled values — specifically title (sourced from r…
- CVE-2026-46526MEDIUMCVSS 5.0EG 5.0✓ Fixed in 1.6.102026-05-28
vulnerable: 0.1.0 ... 1.6.9 (142 versions)
Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.10, the URL checking logic in local-deep-research has a logical flaw that could be bypassed by attackers, leading to SSRF attacks. The curre…
Check whether local-deep-research is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for local-deep-research CVEs against the assets you own.
Start Free Scan →