streamlit
PyPI5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting streamlitpage 1 of 1
- CVE-2022-35918MEDIUMCVSS 6.5EG 6.5fixed in 1.11.12022-08-01
vulnerable: 0.63.0 ... 1.9.2rc1 (69 versions)
Streamlit is a data oriented application development framework for python. Users hosting Streamlit app(s) that use custom components are vulnerable to a directory traversal attack that could leak data from their web server file-system such…
- CVE-2023-27494MEDIUMCVSS 5.9EG 5.9fixed in 0.81.02023-03-16
vulnerable: 0.63.0 ... 0.80.0 (27 versions)
Streamlit, software for turning data scripts into web applications, had a cross-site scripting (XSS) vulnerability in versions 0.63.0 through 0.80.0. Users of hosted Streamlit app(s) were vulnerable to a reflected XSS vulnerability. An att…
- CVE-2024-42474MEDIUMCVSS 6.5EG 6.5fixed in 1.37.02024-08-12
vulnerable: 0.1 ... 1.9.2rc1 (224 versions)
Streamlit is a data oriented application development framework for python. Snowflake Streamlit open source addressed a security vulnerability via the static file sharing feature. Users of hosted Streamlit app(s) on Windows were vulnerable …
- CVE-2026-10804MEDIUMCVSS 4.7EG 4.7fixed in 1.53.12026-06-04
vulnerable: 0.1 ... 1.9.2rc1 (258 versions)
A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/runtime/caching/hashing.py of the component Palette Handler. Such manipulation leads to use of weak hash. Local access i…
- CVE-2026-33682MEDIUMCVSS 4.8EG 4.8fixed in 1.54.02026-03-26
vulnerable: 0.1 ... 1.9.2rc1 (259 versions)
Streamlit is a data oriented application development framework for python. Streamlit Open Source versions prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability …
Check whether streamlit is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for streamlit CVEs against the assets you own.
Book a Demo →