Skip to main content
A package in the dependency tree has a known CVE in the OSV/NVD database

How to resolve

Upgrade the affected package to the fixed version. If no fix exists, evaluate alternatives or apply compensating controls.

Risk

Governance/Compliance This vulnerability falls under ASI04:2026 — Agentic Supply Chain Vulnerabilities in the OWASP Top 10 for Agentic Applications. Compromised runtime components — tools, plugins, MCP servers, deps — alter agent behavior. Security A package in the dependency tree has a known CVE in the OSV/NVD database. If exploited, this can compromise the agent’s integrity, confidentiality, or availability, potentially affecting downstream systems and data.

Explanation

A package in the dependency tree has a known CVE in the OSV/NVD database. This falls under ASI04 (Agentic Supply Chain Vulnerabilities): Compromised runtime components — tools, plugins, MCP servers, deps — alter agent behavior.

Specifications

Trigger
  • Agent scan detects a package in the dependency tree has a known CVE in the OSV/NVD database
The scanner looks for patterns such as:
  • pip-audit findings
  • OSV.dev advisory matches
Severity
  • CRITICAL
Applies to: Agent