github Python not analyzable deep scan unknown

deepset-ai/haystack

github

not analyzable — repository too large to scan in full (large monorepo)

Open-source AI orchestration framework for building context-engineered, production-ready LLM applications. Design modular pipelines and agent workflows with explicit control over retrieval, routing, memory, and generation. Built for scalable agents, RAG, multimodal applications, semantic search, and conversational systems.

maintainer
deepset-ai
licence
Apache-2.0
first seen
2026-08-03
last seen
2026-09-16
releases · 30d
6
short id
risk insufficient evidence

Insufficient evidence to grade. This server's source has not been statically analyzed, so a low grade would only mean "nothing found", not "nothing there". We don't show a reassuring grade we can't stand behind. Attested signals (CVEs, provenance) below still apply.

Once the source is analyzed (see the analysis flag in the header), a graded score appears here. How analysis works: methodology.

vulnerabilities 1 CVEs · grade factor +2
LOW
Insecure Jinja2 templates rendered in Haystack Components can lead to RCE EPSS 1% CVE-2024-41950 affects ["<=2.3.0"]
tool safety all quiet

No tool-safety findings — heuristic detectors run on the compute-risk cadence; a finding appears when a tool trips a rule.

embed badge readme-ready
live risk-grade badge preview [![MCP Observatory risk grade](https://mcpobservatory.com/servers/github:deepset-ai/haystack/badge.svg)](https://mcpobservatory.com/servers/github:deepset-ai/haystack/security)

Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of deepset-ai.