Opengeos develops Streamlit-Geospatial, a geospatial data visualization and analysis framework that sits prominently in the spatial-data and mapping application layer despite a narrow product portfolio. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur through weakness classes including improper input validation and server-side request forgery, reflecting the data-processing and external-resource-fetching patterns inherent to geospatial web applications. Defenders should treat updates to this library as high-priority where it handles untrusted geographic data or connects to external mapping services; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Opengeos over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-41114CRITICAL streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `palette` variable on line 430 in `page | Jul 26, 2024 | 9.8 | 31 | NO | NO |
CVE-2024-41119CRITICAL streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 80 in `8_ | Jul 26, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-41116CRITICAL streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 1254 in ` | Jul 26, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-41120CRITICAL streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `url` variable on line 63 of `pages/9_🔲 | Jul 26, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-41118CRITICAL streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `url` variable on line 47 of `pages/7_📦 | Jul 26, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-41115CRITICAL streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `palette` variable on line 488 in `page | Jul 26, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-41113CRITICAL streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 383 or li | Jul 26, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-41112CRITICAL streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the palette variable in `pages/1_📷_Timelaps | Jul 26, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-41117CRITICAL streamlit-geospatial is a streamlit multipage app for geospatial applications. Prior to commit c4f81d9616d40c60584e36abb15300853a66e489, the `vis_params` variable on line 115 in `p | Jul 26, 2024 | 9.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Opengeos.
Media articles that mention a CVE ID that affects a product developed by Opengeos — matched by CVE ID, not by vendor name.