How to resolve
Upgrade the affected package to the fixed version. If no fix exists, evaluate alternatives or apply compensating controls.Risk
Governance/Compliance This vulnerability falls under ASI04:2026 — Agentic Supply Chain Vulnerabilities in the OWASP Top 10 for Agentic Applications. Compromised runtime components — tools, plugins, MCP servers, deps — alter agent behavior. Security A package in the dependency tree has a known CVE in the OSV/NVD database. If exploited, this can compromise the agent’s integrity, confidentiality, or availability, potentially affecting downstream systems and data.Explanation
A package in the dependency tree has a known CVE in the OSV/NVD database. This falls under ASI04 (Agentic Supply Chain Vulnerabilities): Compromised runtime components — tools, plugins, MCP servers, deps — alter agent behavior.Specifications
Trigger- Agent scan detects a package in the dependency tree has a known CVE in the OSV/NVD database
- pip-audit findings
- OSV.dev advisory matches
- CRITICAL