chore(deps): update dependency requests to v2.32.4 #10
Security Report
❗️Scan Incomplete: The scan completed with partial failure. The integration encountered issues with one or more projects in this repository, preventing their scan. The errors occurred in the following package managers: gradle,CocoaPods. Consequently, there may be gaps in the coverage of open-source dependencies used in the repository.
Scan Details Report
gradle
/tmp/ws-scm/AutoGPT/classic/frontend/android/build.gradle
| Step | Level | Description | Details |
|---|---|---|---|
| Preparing the project for scan | ⚠Warn | One or more of the installations failed | failed running mend init script (mendDeps): NOTE: Picked up JDK_JAVA_OPTIONS: --add-opens java.base/java.util=ALL-UNNAMED --add-opens java.base/sun.reflect.generics.reflectiveObjects=ALL-UNNAMED FAILURE: Build failed with an exception. * Where: Settings file '/tmp/ws-scm/AutoGPT/classic/frontend/android/settings.gradle' line: 6 * What went wrong: A problem occurred evaluating settings 'andro... |
pip
/tmp/ws-scm/AutoGPT/classic/benchmark/agbenchmark/challenges/verticals/code/6_battleship/artifacts_in/product_requirements.txt
| Step | Level | Description | Details |
|---|---|---|---|
| Resolving the project | ⚠Warn | Some problems occurred while performing the resolution operation |
|
/tmp/ws-scm/AutoGPT/classic/original_autogpt
| Step | Level | Description | Details |
|---|---|---|---|
| Resolving the project | ⚠Warn | Some problems occurred while performing the resolution operation |
|
/tmp/ws-scm/AutoGPT/classic/original_autogpt/autogpt/app
| Step | Level | Description | Details |
|---|---|---|---|
| Resolving the project | ⚠Warn | Some problems occurred while performing the resolution operation |
|
poetry
/tmp/ws-scm/AutoGPT/classic/forge/pyproject.toml
| Step | Level | Description | Details |
|---|---|---|---|
| Preparing the project for scan | ⚠Warn | One or more of the installations failed | poetry install --no-root failed with exit code 1 for manifest "/tmp/ws-scm/AutoGPT/classic/forge/pyproject.toml". output: The currently activated Python version 3.9.25 is not supported by the project (^3.10). Trying to find and use a compatible version. Using python3.13 (3.13.11) Creating virtualenv autogpt-forge-Eq_saOJk-py3.13 in /home/wss-scanner/.cache/pypoetry/virtualenvs Installing depen... |
| Resolving the project | ⚠Warn | Failed to build the dependency tree, fallback was used in the scan, results may be incomplete | Error occurred while parsing the poetry show --tree command on the /tmp/ws-scm/AutoGPT/classic/forge/pyproject.toml file |
/tmp/ws-scm/AutoGPT/classic/original_autogpt/pyproject.toml
| Step | Level | Description | Details |
|---|---|---|---|
| Preparing the project for scan | ⚠Warn | One or more of the installations failed | poetry install --no-root --without dev failed with exit code 1 for manifest "/tmp/ws-scm/AutoGPT/classic/original_autogpt/pyproject.toml". output: The currently activated Python version 3.9.25 is not supported by the project (^3.10). Trying to find and use a compatible version. Using python3.13 (3.13.11) Creating virtualenv agpt-cm9iHxbr-py3.13 in /home/wss-scanner/.cache/pypoetry/virtualenvs ... |
| Resolving the project | ⚠Warn | Failed to build the dependency tree, fallback was used in the scan, results may be incomplete | Error occurred while parsing the poetry show --tree command on the /tmp/ws-scm/AutoGPT/classic/original_autogpt/pyproject.toml file |
❌ New vulnerabilities:
| Vulnerability | Severity | Vulnerable Library | Direct Library | Suggested Fix | Issue | Reachability | |
|---|---|---|---|---|---|---|---|
CVE-2026-0994Dependency Hierarchy: -> autogpt-libs-0.2.0 (Root Library) -> google_cloud_logging-3.11.2-py2.py3-none-any.whl -> google_api_core-2.20.0-py3-none-any.whl -> googleapis_common_protos-1.65.0-py2.py3-none-any.whl -> ❌ protobuf-5.28.2-cp310-abi3-win32.whl (Vulnerable Library) |
8.6 | Transitive protobuf-5.28.2-cp310-abi3-win32.whl |
autogpt-libs-0.2.0 | None | |||
CVE-2026-0994Dependency Hierarchy: -> google_cloud_logging-3.11.2-py2.py3-none-any.whl (Root Library) -> google_api_core-2.19.2-py3-none-any.whl -> googleapis_common_protos-1.65.0-py2.py3-none-any.whl -> ❌ protobuf-5.28.0-cp310-abi3-win32.whl (Vulnerable Library) |
8.6 | Transitive protobuf-5.28.0-cp310-abi3-win32.whl |
google_cloud_logging-3.11.2-py2.py3-none-any.whl | None | |||
CVE-2025-69223Dependency Hierarchy: -> autogpt-libs-0.2.0 (Root Library) -> supabase-2.7.4-py3-none-any.whl -> realtime-2.0.5-py3-none-any.whl -> ❌ aiohttp-3.10.8-cp310-cp310-macosx_10_9_universal2.whl (Vulnerable Library) |
7.5 | Transitive aiohttp-3.10.8-cp310-cp310-macosx_10_9_universal2.whl |
autogpt-libs-0.2.0 | None | |||
CVE-2025-69223Dependency Hierarchy: -> ❌ aiohttp-3.9.3-cp310-cp310-macosx_10_9_universal2.whl (Vulnerable Library) |
7.5 | Direct aiohttp-3.9.3-cp310-cp310-macosx_10_9_universal2.whl |
aiohttp-3.9.3-cp310-cp310-macosx_10_9_universal2.whl | None | |||
CVE-2025-69223Dependency Hierarchy: -> supabase-2.7.4-py3-none-any.whl (Root Library) -> realtime-2.0.2-py3-none-any.whl -> ❌ aiohttp-3.10.5-cp310-cp310-macosx_10_9_universal2.whl (Vulnerable Library) |
7.5 | Transitive aiohttp-3.10.5-cp310-cp310-macosx_10_9_universal2.whl |
supabase-2.7.4-py3-none-any.whl | None | |||
| 7.5 | Direct orjson-3.10.5-cp38-none-win32.whl |
orjson-3.10.5-cp38-none-win32.whl | None | ||||
CVE-2025-4565Dependency Hierarchy: -> autogpt-libs-0.2.0 (Root Library) -> google_cloud_logging-3.11.2-py2.py3-none-any.whl -> google_api_core-2.20.0-py3-none-any.whl -> googleapis_common_protos-1.65.0-py2.py3-none-any.whl -> ❌ protobuf-5.28.2-cp310-abi3-win32.whl (Vulnerable Library) |
7.5 | Transitive protobuf-5.28.2-cp310-abi3-win32.whl |
autogpt-libs-0.2.0 | Transitive 5.29.5 |
None | ||
CVE-2025-4565Dependency Hierarchy: -> google_cloud_logging-3.11.2-py2.py3-none-any.whl (Root Library) -> google_api_core-2.19.2-py3-none-any.whl -> googleapis_common_protos-1.65.0-py2.py3-none-any.whl -> ❌ protobuf-5.28.0-cp310-abi3-win32.whl (Vulnerable Library) |
7.5 | Transitive protobuf-5.28.0-cp310-abi3-win32.whl |
google_cloud_logging-3.11.2-py2.py3-none-any.whl | Transitive 5.29.5 |
None | ||
| 7.5 | Direct python_multipart-0.0.7.tar.gz |
python_multipart-0.0.7.tar.gz | python-multipart - 0.0.18,python-multipart - 0.0.18 | None | |||
CVE-2024-52303Dependency Hierarchy: -> autogpt-libs-0.2.0 (Root Library) -> supabase-2.7.4-py3-none-any.whl -> realtime-2.0.5-py3-none-any.whl -> ❌ aiohttp-3.10.8-cp310-cp310-macosx_10_9_universal2.whl (Vulnerable Library) |
7.5 | Transitive aiohttp-3.10.8-cp310-cp310-macosx_10_9_universal2.whl |
autogpt-libs-0.2.0 | Transitive aiohttp - 3.10.11 |
None | ||
CVE-2025-69224Dependency Hierarchy: -> autogpt-libs-0.2.0 (Root Library) -> supabase-2.7.4-py3-none-any.whl -> realtime-2.0.5-py3-none-any.whl -> ❌ aiohttp-3.10.8-cp310-cp310-macosx_10_9_universal2.whl (Vulnerable Library) |
6.5 | Transitive aiohttp-3.10.8-cp310-cp310-macosx_10_9_universal2.whl |
autogpt-libs-0.2.0 | None | |||
CVE-2025-69224Dependency Hierarchy: -> ❌ aiohttp-3.9.3-cp310-cp310-macosx_10_9_universal2.whl (Vulnerable Library) |
6.5 | Direct aiohttp-3.9.3-cp310-cp310-macosx_10_9_universal2.whl |
aiohttp-3.9.3-cp310-cp310-macosx_10_9_universal2.whl | None | |||
CVE-2025-69224Dependency Hierarchy: -> supabase-2.7.4-py3-none-any.whl (Root Library) -> realtime-2.0.2-py3-none-any.whl -> ❌ aiohttp-3.10.5-cp310-cp310-macosx_10_9_universal2.whl (Vulnerable Library) |
6.5 | Transitive aiohttp-3.10.5-cp310-cp310-macosx_10_9_universal2.whl |
supabase-2.7.4-py3-none-any.whl | None | |||
CVE-2025-69226Dependency Hierarchy: -> autogpt-libs-0.2.0 (Root Library) -> supabase-2.7.4-py3-none-any.whl -> realtime-2.0.5-py3-none-any.whl -> ❌ aiohttp-3.10.8-cp310-cp310-macosx_10_9_universal2.whl (Vulnerable Library) |
5.3 | Transitive aiohttp-3.10.8-cp310-cp310-macosx_10_9_universal2.whl |
autogpt-libs-0.2.0 | None | |||
CVE-2025-69226Dependency Hierarchy: -> ❌ aiohttp-3.9.3-cp310-cp310-macosx_10_9_universal2.whl (Vulnerable Library) |
5.3 | Direct aiohttp-3.9.3-cp310-cp310-macosx_10_9_universal2.whl |
aiohttp-3.9.3-cp310-cp310-macosx_10_9_universal2.whl | None | |||
CVE-2025-69226Dependency Hierarchy: -> supabase-2.7.4-py3-none-any.whl (Root Library) -> realtime-2.0.2-py3-none-any.whl -> ❌ aiohttp-3.10.5-cp310-cp310-macosx_10_9_universal2.whl (Vulnerable Library) |
5.3 | Transitive aiohttp-3.10.5-cp310-cp310-macosx_10_9_universal2.whl |
supabase-2.7.4-py3-none-any.whl | None | |||
CVE-2025-53643Dependency Hierarchy: -> autogpt-libs-0.2.0 (Root Library) -> supabase-2.7.4-py3-none-any.whl -> realtime-2.0.5-py3-none-any.whl -> ❌ aiohttp-3.10.8-cp310-cp310-macosx_10_9_universal2.whl (Vulnerable Library) |
5.3 | Transitive aiohttp-3.10.8-cp310-cp310-macosx_10_9_universal2.whl |
autogpt-libs-0.2.0 | Transitive 3.12.14 |
None | ||
CVE-2025-53643Dependency Hierarchy: -> ❌ aiohttp-3.9.3-cp310-cp310-macosx_10_9_universal2.whl (Vulnerable Library) |
5.3 | Direct aiohttp-3.9.3-cp310-cp310-macosx_10_9_universal2.whl |
aiohttp-3.9.3-cp310-cp310-macosx_10_9_universal2.whl | 3.12.14 | None | ||
CVE-2025-53643Dependency Hierarchy: -> supabase-2.7.4-py3-none-any.whl (Root Library) -> realtime-2.0.2-py3-none-any.whl -> ❌ aiohttp-3.10.5-cp310-cp310-macosx_10_9_universal2.whl (Vulnerable Library) |
5.3 | Transitive aiohttp-3.10.5-cp310-cp310-macosx_10_9_universal2.whl |
supabase-2.7.4-py3-none-any.whl | Transitive 3.12.14 |
None | ||
CVE-2024-52304Dependency Hierarchy: -> autogpt-libs-0.2.0 (Root Library) -> supabase-2.7.4-py3-none-any.whl -> realtime-2.0.5-py3-none-any.whl -> ❌ aiohttp-3.10.8-cp310-cp310-macosx_10_9_universal2.whl (Vulnerable Library) |
5.3 | Transitive aiohttp-3.10.8-cp310-cp310-macosx_10_9_universal2.whl |
autogpt-libs-0.2.0 | Transitive aiohttp - 3.10.11 |
None | ||
CVE-2021-33430Path to dependency file: /classic/benchmark/.ws-temp-GZSUJL-requirements.txt Path to vulnerable library: /home/wss-scanner/.cache/pypoetry/virtualenvs/agbenchmark-gctv3_E3-py3.13/lib/python3.13/site-packages/numpy-1.26.3.dist-info Dependency Hierarchy: -> matplotlib-3.8.2.tar.gz (Root Library) -> contourpy-1.2.0-cp310-cp310-macosx_10_9_x86_64.whl -> ❌ numpy-1.26.3.tar.gz (Vulnerable Library) |
5.3 | Transitive numpy-1.26.3.tar.gz |
matplotlib-3.8.2.tar.gz | None | |||
CVE-2021-33430Dependency Hierarchy: -> ❌ numpy-1.26.3-cp310-cp310-macosx_10_9_x86_64.whl (Vulnerable Library) |
5.3 | Direct numpy-1.26.3-cp310-cp310-macosx_10_9_x86_64.whl |
numpy-1.26.3-cp310-cp310-macosx_10_9_x86_64.whl | None |
✔️ Remediated vulnerabilities:
| Vulnerability | Vulnerable Library |
|---|---|
| CVE-2025-69224 | aiohttp-3.10.8-cp312-cp312-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2025-53643 | aiohttp-3.10.5-cp312-cp312-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2025-69226 | aiohttp-3.10.5-cp312-cp312-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2025-4565 | protobuf-5.28.2-cp38-abi3-manylinux2014_x86_64.whl |
| CVE-2025-69223 | aiohttp-3.10.5-cp312-cp312-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2025-69226 | aiohttp-3.10.8-cp312-cp312-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2024-53981 | python_multipart-0.0.7-py3-none-any.whl |
| CVE-2025-69224 | aiohttp-3.10.5-cp312-cp312-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2026-0994 | protobuf-5.28.0-cp38-abi3-manylinux2014_x86_64.whl |
| CVE-2025-69223 | aiohttp-3.9.3-cp312-cp312-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2021-33430 | numpy-1.26.3-cp312-cp312-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2024-47081 | requests-2.31.0-py3-none-any.whl |
| CVE-2025-67221 | orjson-3.10.5-cp312-cp312-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2024-52304 | aiohttp-3.10.8-cp312-cp312-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2025-69226 | aiohttp-3.9.3-cp312-cp312-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2025-53643 | aiohttp-3.9.3-cp312-cp312-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2024-52303 | aiohttp-3.10.8-cp312-cp312-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2025-4565 | protobuf-5.28.0-cp38-abi3-manylinux2014_x86_64.whl |
| CVE-2025-69224 | aiohttp-3.9.3-cp312-cp312-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2026-0994 | protobuf-5.28.2-cp38-abi3-manylinux2014_x86_64.whl |
| CVE-2025-69223 | aiohttp-3.10.8-cp312-cp312-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
| CVE-2025-53643 | aiohttp-3.10.8-cp312-cp312-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
Base branch total remaining vulnerabilities: 91
Base branch commit: b74c8d4152d600b0a70b423a8ee2d3fcd7737272
Total libraries scanned: 948
Scan token: 7f2fa947a0544d8e8cad587bbb36ed71