{
  "@context": "https://openvex.dev/ns/v0.2.0",
  "@id": "https://langgenius.ai/vex/dify-ee-pip-vendored",
  "author": "Dify Security <security@dify.ai>",
  "timestamp": "2026-10-09T00:00:00Z",
  "version": 3,
  "statements": [
    {
      "vulnerability": {
        "name": "CVE-2026-57585"
      },
      "products": [
        {
          "@id": "pkg:docker/langgenius/dify-ee-plugin-daemon-local",
          "subcomponents": [
            {
              "@id": "pkg:pypi/msgpack@1.1.2"
            }
          ]
        },
        {
          "@id": "pkg:docker/langgenius/dify-ee-plugin-build-base-python-3.12",
          "subcomponents": [
            {
              "@id": "pkg:pypi/msgpack@1.1.2"
            }
          ]
        },
        {
          "@id": "pkg:docker/langgenius/dify-ee-plugin-build-base-python-3.13",
          "subcomponents": [
            {
              "@id": "pkg:pypi/msgpack@1.1.2"
            }
          ]
        },
        {
          "@id": "pkg:docker/langgenius/dify-ee-plugin-build-base-python-3.14",
          "subcomponents": [
            {
              "@id": "pkg:pypi/msgpack@1.1.2"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "False positive from a stale SBOM. msgpack 1.1.2 is only reported by pip/_vendor/bom.cdx.json shipped in the Chainguard py3.x-pip-26.2.1-r2 apk used by the plugin images' -dev base. The vendored code actually shipped is msgpack 1.2.1 (pip/_vendor/vendor.txt and the package's own version metadata agree). Chainguard has published py3.x-pip-26.2.1-r3 with a corrected SBOM (already picked up by the sandbox image); remove this statement once the plugin images move to r3."
    },
    {
      "vulnerability": {
        "name": "GHSA-6v7p-g79w-8964"
      },
      "products": [
        {
          "@id": "pkg:docker/langgenius/dify-ee-plugin-daemon-local",
          "subcomponents": [
            {
              "@id": "pkg:pypi/msgpack@1.1.2"
            }
          ]
        },
        {
          "@id": "pkg:docker/langgenius/dify-ee-plugin-build-base-python-3.12",
          "subcomponents": [
            {
              "@id": "pkg:pypi/msgpack@1.1.2"
            }
          ]
        },
        {
          "@id": "pkg:docker/langgenius/dify-ee-plugin-build-base-python-3.13",
          "subcomponents": [
            {
              "@id": "pkg:pypi/msgpack@1.1.2"
            }
          ]
        },
        {
          "@id": "pkg:docker/langgenius/dify-ee-plugin-build-base-python-3.14",
          "subcomponents": [
            {
              "@id": "pkg:pypi/msgpack@1.1.2"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "False positive from a stale SBOM. msgpack 1.1.2 is only reported by pip/_vendor/bom.cdx.json shipped in the Chainguard py3.x-pip-26.2.1-r2 apk used by the plugin images' -dev base. The vendored code actually shipped is msgpack 1.2.1 (pip/_vendor/vendor.txt and the package's own version metadata agree). Chainguard has published py3.x-pip-26.2.1-r3 with a corrected SBOM (already picked up by the sandbox image); remove this statement once the plugin images move to r3."
    },
    {
      "vulnerability": {
        "name": "CVE-2025-47273"
      },
      "products": [
        {
          "@id": "pkg:docker/langgenius/dify-ee-sandbox",
          "subcomponents": [
            {
              "@id": "pkg:pypi/setuptools@70.3.0"
            }
          ]
        },
        {
          "@id": "pkg:docker/langgenius/dify-ee-plugin-daemon-local",
          "subcomponents": [
            {
              "@id": "pkg:pypi/setuptools@70.3.0"
            }
          ]
        },
        {
          "@id": "pkg:docker/langgenius/dify-ee-plugin-build-base-python-3.12",
          "subcomponents": [
            {
              "@id": "pkg:pypi/setuptools@70.3.0"
            }
          ]
        },
        {
          "@id": "pkg:docker/langgenius/dify-ee-plugin-build-base-python-3.13",
          "subcomponents": [
            {
              "@id": "pkg:pypi/setuptools@70.3.0"
            }
          ]
        },
        {
          "@id": "pkg:docker/langgenius/dify-ee-plugin-build-base-python-3.14",
          "subcomponents": [
            {
              "@id": "pkg:pypi/setuptools@70.3.0"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "setuptools 70.3.0 is only declared by pip/_vendor/bom.cdx.json for pip's vendored copy of pkg_resources. pip vendors pkg_resources alone; setuptools.package_index (where the path traversal lives) is not shipped in the image, so the vulnerable code is not present."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-97687"
      },
      "products": [
        {
          "@id": "pkg:docker/langgenius/dify-ee-plugin-daemon-local",
          "subcomponents": [
            {
              "@id": "pkg:pypi/urllib3@2.7.0"
            }
          ]
        },
        {
          "@id": "pkg:docker/langgenius/dify-ee-plugin-build-base-python-3.12",
          "subcomponents": [
            {
              "@id": "pkg:pypi/urllib3@2.7.0"
            }
          ]
        },
        {
          "@id": "pkg:docker/langgenius/dify-ee-plugin-build-base-python-3.13",
          "subcomponents": [
            {
              "@id": "pkg:pypi/urllib3@2.7.0"
            }
          ]
        },
        {
          "@id": "pkg:docker/langgenius/dify-ee-plugin-build-base-python-3.14",
          "subcomponents": [
            {
              "@id": "pkg:pypi/urllib3@2.7.0"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "False positive from a stale SBOM. urllib3 2.7.0 is only reported by pip/_vendor/bom.cdx.json shipped in the Chainguard py3.x-pip-26.2.1-r2 apk used by the plugin images' -dev base. The vendored code actually shipped is urllib3 2.8.0 (pip/_vendor/vendor.txt and the package's own version metadata agree). Chainguard has published py3.x-pip-26.2.1-r3 with a corrected SBOM (already picked up by the sandbox image); remove this statement once the plugin images move to r3."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-97689"
      },
      "products": [
        {
          "@id": "pkg:docker/langgenius/dify-ee-plugin-daemon-local",
          "subcomponents": [
            {
              "@id": "pkg:pypi/urllib3@2.7.0"
            }
          ]
        },
        {
          "@id": "pkg:docker/langgenius/dify-ee-plugin-build-base-python-3.12",
          "subcomponents": [
            {
              "@id": "pkg:pypi/urllib3@2.7.0"
            }
          ]
        },
        {
          "@id": "pkg:docker/langgenius/dify-ee-plugin-build-base-python-3.13",
          "subcomponents": [
            {
              "@id": "pkg:pypi/urllib3@2.7.0"
            }
          ]
        },
        {
          "@id": "pkg:docker/langgenius/dify-ee-plugin-build-base-python-3.14",
          "subcomponents": [
            {
              "@id": "pkg:pypi/urllib3@2.7.0"
            }
          ]
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_present",
      "impact_statement": "False positive from a stale SBOM. urllib3 2.7.0 is only reported by pip/_vendor/bom.cdx.json shipped in the Chainguard py3.x-pip-26.2.1-r2 apk used by the plugin images' -dev base. The vendored code actually shipped is urllib3 2.8.0 (pip/_vendor/vendor.txt and the package's own version metadata agree). Chainguard has published py3.x-pip-26.2.1-r3 with a corrected SBOM (already picked up by the sandbox image); remove this statement once the plugin images move to r3."
    }
  ]
}
