ahmetoner / whisper-asr-webservice

OpenAI Whisper ASR Webservice API
https://ahmetoner.github.io/whisper-asr-webservice
MIT License
2.11k stars 379 forks source link

[Security-Critical] Vulnerabilities introduced via third party libs #206

Closed steph19952 closed 7 months ago

steph19952 commented 7 months ago

Hello Team, 👋

First of all, I want to begin with the fact that you have a great project going on here 😄

I am writing this issue hoping that you might be able to address the following vulnerabilities introduced by some of the packages that the project uses.

Those are:

The following ones are not directly linked to the project, but might be fixable by upgrading to a higher version of faster-whisper. They both seem to come from faster-whisper.

Thank you! Stefan

ostpachukAndrii commented 7 months ago

@ahmetoner, @ayancey Hi guys, it looks like serious security concern. Suggest to fix ASAP. Especially fastapi. It looks like only update of packages needed.