{
  "@context": "https://openvex.dev/ns/v0.2.0",
  "@id": "https://langgenius.ai/vex/dify-ee-pip-vendored",
  "author": "Dify Security <security@dify.ai>",
  "timestamp": "2026-08-27T00:00:00Z",
  "version": 1,
  "statements": [
    {
      "vulnerability": { "name": "CVE-2026-57585" },
      "products": [
        { "@id": "pkg:docker/langgenius/dify-ee-api", "subcomponents": [{ "@id": "pkg:pypi/msgpack@1.1.2" }] },
        { "@id": "pkg:docker/langgenius/dify-ee-api-insecure", "subcomponents": [{ "@id": "pkg:pypi/msgpack@1.1.2" }] },
        { "@id": "pkg:docker/langgenius/dify-ee-sandbox", "subcomponents": [{ "@id": "pkg:pypi/msgpack@1.1.2" }] },
        { "@id": "pkg:docker/langgenius/dify-ee-plugin-daemon-local", "subcomponents": [{ "@id": "pkg:pypi/msgpack@1.1.2" }] },
        { "@id": "pkg:docker/langgenius/dify-ee-plugin-build-base-python-3.12", "subcomponents": [{ "@id": "pkg:pypi/msgpack@1.1.2" }] },
        { "@id": "pkg:docker/langgenius/dify-ee-plugin-build-base-python-3.13", "subcomponents": [{ "@id": "pkg:pypi/msgpack@1.1.2" }] },
        { "@id": "pkg:docker/langgenius/dify-ee-plugin-build-base-python-3.14", "subcomponents": [{ "@id": "pkg:pypi/msgpack@1.1.2" }] }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_in_execute_path",
      "impact_statement": "msgpack 1.1.2 is only vendored inside the base-image system pip (pip/_vendor/msgpack). It is not installed in the application virtualenv nor imported by the runtime, which uses uv-managed venvs. Not exploitable."
    },
    {
      "vulnerability": { "name": "GHSA-6v7p-g79w-8964" },
      "products": [
        { "@id": "pkg:docker/langgenius/dify-ee-api", "subcomponents": [{ "@id": "pkg:pypi/msgpack@1.1.2" }] },
        { "@id": "pkg:docker/langgenius/dify-ee-api-insecure", "subcomponents": [{ "@id": "pkg:pypi/msgpack@1.1.2" }] },
        { "@id": "pkg:docker/langgenius/dify-ee-sandbox", "subcomponents": [{ "@id": "pkg:pypi/msgpack@1.1.2" }] },
        { "@id": "pkg:docker/langgenius/dify-ee-plugin-daemon-local", "subcomponents": [{ "@id": "pkg:pypi/msgpack@1.1.2" }] },
        { "@id": "pkg:docker/langgenius/dify-ee-plugin-build-base-python-3.12", "subcomponents": [{ "@id": "pkg:pypi/msgpack@1.1.2" }] },
        { "@id": "pkg:docker/langgenius/dify-ee-plugin-build-base-python-3.13", "subcomponents": [{ "@id": "pkg:pypi/msgpack@1.1.2" }] },
        { "@id": "pkg:docker/langgenius/dify-ee-plugin-build-base-python-3.14", "subcomponents": [{ "@id": "pkg:pypi/msgpack@1.1.2" }] }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_in_execute_path",
      "impact_statement": "msgpack 1.1.2 is only vendored inside the base-image system pip (pip/_vendor/msgpack). It is not installed in the application virtualenv nor imported by the runtime, which uses uv-managed venvs. Not exploitable."
    },
    {
      "vulnerability": { "name": "CVE-2025-47273" },
      "products": [
        { "@id": "pkg:docker/langgenius/dify-ee-api", "subcomponents": [{ "@id": "pkg:pypi/setuptools@70.3.0" }] },
        { "@id": "pkg:docker/langgenius/dify-ee-api-insecure", "subcomponents": [{ "@id": "pkg:pypi/setuptools@70.3.0" }] },
        { "@id": "pkg:docker/langgenius/dify-ee-sandbox", "subcomponents": [{ "@id": "pkg:pypi/setuptools@70.3.0" }] },
        { "@id": "pkg:docker/langgenius/dify-ee-plugin-daemon-local", "subcomponents": [{ "@id": "pkg:pypi/setuptools@70.3.0" }] },
        { "@id": "pkg:docker/langgenius/dify-ee-plugin-build-base-python-3.12", "subcomponents": [{ "@id": "pkg:pypi/setuptools@70.3.0" }] },
        { "@id": "pkg:docker/langgenius/dify-ee-plugin-build-base-python-3.13", "subcomponents": [{ "@id": "pkg:pypi/setuptools@70.3.0" }] },
        { "@id": "pkg:docker/langgenius/dify-ee-plugin-build-base-python-3.14", "subcomponents": [{ "@id": "pkg:pypi/setuptools@70.3.0" }] }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_in_execute_path",
      "impact_statement": "setuptools 70.3.0 is only vendored inside the base-image system pip (pip/_vendor/pkg_resources). Runtime setuptools is not this version; pip is not used to process untrusted input at runtime. Not exploitable."
    },
    {
      "vulnerability": { "name": "CVE-2026-59890" },
      "products": [
        { "@id": "pkg:docker/langgenius/dify-ee-api", "subcomponents": [{ "@id": "pkg:pypi/setuptools@70.3.0" }] },
        { "@id": "pkg:docker/langgenius/dify-ee-api-insecure", "subcomponents": [{ "@id": "pkg:pypi/setuptools@70.3.0" }] },
        { "@id": "pkg:docker/langgenius/dify-ee-sandbox", "subcomponents": [{ "@id": "pkg:pypi/setuptools@70.3.0" }] },
        { "@id": "pkg:docker/langgenius/dify-ee-plugin-daemon-local", "subcomponents": [{ "@id": "pkg:pypi/setuptools@70.3.0" }] },
        { "@id": "pkg:docker/langgenius/dify-ee-plugin-build-base-python-3.12", "subcomponents": [{ "@id": "pkg:pypi/setuptools@70.3.0" }] },
        { "@id": "pkg:docker/langgenius/dify-ee-plugin-build-base-python-3.13", "subcomponents": [{ "@id": "pkg:pypi/setuptools@70.3.0" }] },
        { "@id": "pkg:docker/langgenius/dify-ee-plugin-build-base-python-3.14", "subcomponents": [{ "@id": "pkg:pypi/setuptools@70.3.0" }] }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_in_execute_path",
      "impact_statement": "setuptools 70.3.0 is only vendored inside the base-image system pip (pip/_vendor/pkg_resources). Runtime setuptools is not this version; pip is not used to process untrusted input at runtime. Not exploitable."
    }
  ]
}
