| Sep 23 | MemoryOS 2.0.34 was published with a credential-stealing binary PYSEC-2026-3987Unratedno fix yet | | Unrated | No fix yet |
| Sep 23 | Malicious code in memoryos (PyPI) MAL-2026-16475Unratedno fix yet | | Unrated | No fix yet |
| Sep 22 | lightrag-hku: Stored Cross-Site Scripting (XSS) in the LightRAG WebUI chat/answer renderer via ingested content CVE-2026-86062Medium6.1fixed in 1.5.5 | | Medium6.1 | 1.5.5 |
| Sep 22 | lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard CVE-2026-85740High7.1fixed in 1.5.5 | | High7.1 | 1.5.5 |
| Sep 22 | lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks CVE-2026-85734Critical9.1fixed in 1.5.5 | | Critical9.1 | 1.5.5 |
| Sep 22 | lightrag-hku: Plaintext Passwords Compared Without Constant-Time Function CVE-2026-85725Medium5.9fixed in 1.5.5 | | Medium5.9 | 1.5.5 |
| Sep 22 | lightrag-hku: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses CVE-2026-85709Medium5.3fixed in 1.5.5 | | Medium5.3 | 1.5.5 |
| Sep 22 | OpenBao Skips Stricter Deny Policy for LIST operations CVE-2026-63131Mediumfixed in 0.0.0-20260713133043-f58d848c139e | | Medium | 0.0.0-20260713133043-f58d848c139e |
| Sep 22 | OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack CVE-2026-63132Criticalfixed in 0.0.0-20260713141742-763625a20721 | | Critical | 0.0.0-20260713141742-763625a20721 |
| Sep 22 | OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters CVE-2026-71543Highfixed in 0.0.0-20260710001938-2d4ebafec5c5 | | High | 0.0.0-20260710001938-2d4ebafec5c5 |
| Sep 22 | OpenBao Agent Writes Secrets to Stdout CVE-2026-77285Lowfixed in 0.0.0-20260714163218-90272575e5f5 | | Low | 0.0.0-20260714163218-90272575e5f5 |
| Sep 22 | Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards CVE-2026-69190Medium6.3fixed in 6.3.14, 7.0.9, 7.1.4 | | Medium6.3 | 6.3.14, 7.0.9, 7.1.4 |
| Sep 18 | LMDeploy has an SSRF bypassGHSA-39wr-7q6h-cf68 LMDeployHigh7.5fixed in 0.15.0 | LMDeploy | High7.5 | 0.15.0 |
| Sep 18 | LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loadingCVE-2026-33625 LMDeployHigh8.8fixed in 0.12.3 | LMDeploy | High8.8 | 0.12.3 |
| Sep 18 | LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.pyCVE-2025-66455 LMDeployCritical9.8fixed in 0.16.0 | LMDeploy | Critical9.8 | 0.16.0 |
| Sep 17 | Jupyter Server: 5xx request logging leaks token-bearing Referer header valuesCVE-2026-86049 JupyterHigh7.1fixed in 2.21.0 | Jupyter | High7.1 | 2.21.0 |
| Sep 17 | Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-auth CVE-2026-73245Medium6.5fixed in 2.0.0 | | Medium6.5 | 2.0.0 |
| Sep 17 | vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservationCVE-2026-69147 vLLMMedium6.5fixed in 0.28.0 | vLLM | Medium6.5 | 0.28.0 |
| Sep 17 | LiteLLM Proxy has server-side request forgery via the `user_config` request parameterCVE-2026-59823 LiteLLMMediumfixed in 1.83.9 | LiteLLM | Medium | 1.83.9 |
| Sep 16 | vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completionsCVE-2026-57173 vLLMMedium6.5fixed in 0.24.0 | vLLM | Medium6.5 | 0.24.0 |
| Sep 16 | LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeployCVE-2025-59953 LMDeployCritical9.8fixed in 0.10.2 | LMDeploy | Critical9.8 | 0.10.2 |
| Sep 12 | vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes withCVE-2026-90553 vLLMHigh7.8fixed in 0.28.0 | vLLM | High7.8 | 0.28.0 |
| Sep 10 | Open WebUI: Users denied by the OAuth role policy can still sign in via token exchangeCVE-2026-88006 Open WebUIMedium6.5fixed in 0.11.1 | Open WebUI | Medium6.5 | 0.11.1 |
| Sep 10 | Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logoutCVE-2026-87011 Open WebUIHigh7.5fixed in 0.11.1 | Open WebUI | High7.5 | 0.11.1 |
| Sep 10 | Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert valueCVE-2026-87012 Open WebUIMedium4.3fixed in 0.11.1 | Open WebUI | Medium4.3 | 0.11.1 |
| Sep 10 | Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycleCVE-2026-87013 Open WebUIMedium4.3fixed in 0.11.1 | Open WebUI | Medium4.3 | 0.11.1 |
| Sep 10 | Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notesCVE-2026-87014 Open WebUIMedium6.5fixed in 0.11.1 | Open WebUI | Medium6.5 | 0.11.1 |
| Sep 10 | Open WebUI: A user's session cookies are sent to tool servers configured for bearer authenticationCVE-2026-87015 Open WebUIMedium6.8fixed in 0.11.1 | Open WebUI | Medium6.8 | 0.11.1 |
| Sep 10 | Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLiteCVE-2026-87016 Open WebUIHigh8.1fixed in 0.11.1 | Open WebUI | High8.1 | 0.11.1 |
| Sep 10 | n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource SubstitutionCVE-2026-86073 n8nMediumfixed in 2.37.7, 2.38.1 | n8n | Medium | 2.37.7, 2.38.1 |
| Sep 10 | n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched ContentCVE-2026-86074 n8nMediumfixed in 2.37.7, 2.38.2 | n8n | Medium | 2.37.7, 2.38.2 |
| Sep 10 | n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository ReadCVE-2026-86995 n8nMediumfixed in 1.123.76, 2.37.7, 2.38.2 | n8n | Medium | 1.123.76, 2.37.7, 2.38.2 |
| Sep 10 | n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment EndpointsCVE-2026-86085 n8nMediumfixed in 2.37.7, 2.38.2 | n8n | Medium | 2.37.7, 2.38.2 |
| Sep 10 | n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership CheckCVE-2026-86993 n8nMediumfixed in 1.123.76, 2.37.7, 2.38.2 | n8n | Medium | 1.123.76, 2.37.7, 2.38.2 |
| Sep 10 | n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid SessionsCVE-2026-86084 n8nMediumfixed in 1.123.76, 2.37.7, 2.38.2 | n8n | Medium | 1.123.76, 2.37.7, 2.38.2 |
| Sep 10 | n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-OpenCVE-2026-86080 n8nMediumfixed in 1.123.76, 2.37.7, 2.38.2 | n8n | Medium | 1.123.76, 2.37.7, 2.38.2 |
| Sep 10 | n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded IdentifiersCVE-2026-86079 n8nMediumfixed in 1.123.76, 2.37.7, 2.38.2 | n8n | Medium | 1.123.76, 2.37.7, 2.38.2 |
| Sep 10 | n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of ServiceCVE-2026-86078 n8nMediumfixed in 2.37.7, 2.38.2 | n8n | Medium | 2.37.7, 2.38.2 |
| Sep 10 | n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId FilterCVE-2026-86994 n8nMediumfixed in 1.123.76, 2.37.7, 2.38.2 | n8n | Medium | 1.123.76, 2.37.7, 2.38.2 |
| Sep 10 | n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code ExecutionCVE-2026-86083 n8nHighfixed in 1.123.76, 2.37.7, 2.38.2 | n8n | High | 1.123.76, 2.37.7, 2.38.2 |
| Sep 10 | n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocketCVE-2026-86077 n8nMediumfixed in 2.37.7, 2.38.2 | n8n | Medium | 2.37.7, 2.38.2 |
| Sep 10 | Remote code execution in pytorch lightning CVE-2024-5452Critical9.8fixed in 2.3.3 | | Critical9.8 | 2.3.3 |
| Sep 10 | pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint CVE-2024-5980Critical9.1fixed in 2.3.3 | | Critical9.1 | 2.3.3 |
| Sep 10 | n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model NodeCVE-2026-86082 n8nHighfixed in 1.123.76, 2.37.7, 2.38.2 | n8n | High | 1.123.76, 2.37.7, 2.38.2 |
| Sep 10 | n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone PathCVE-2026-86081 n8nHighfixed in 1.123.76, 2.37.7, 2.38.2 | n8n | High | 1.123.76, 2.37.7, 2.38.2 |
| Sep 10 | n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration EndpointCVE-2026-86075 n8nHighfixed in 2.37.7, 2.38.2 | n8n | High | 2.37.7, 2.38.2 |
| Sep 10 | n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code ExecutionCVE-2026-86076 n8nHighfixed in 1.123.76, 2.37.7, 2.38.2 | n8n | High | 1.123.76, 2.37.7, 2.38.2 |
| Sep 10 | Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backendsCVE-2026-87017 Open WebUIMedium4.3fixed in 0.11.1 | Open WebUI | Medium4.3 | 0.11.1 |
| Sep 10 | Open WebUI: Channel members can overwrite another member's message via the chat completions endpointCVE-2026-87994 Open WebUIMedium4.3fixed in 0.11.1 | Open WebUI | Medium4.3 | 0.11.1 |
| Sep 10 | Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-originCVE-2026-87995 Open WebUIHigh8.7fixed in 0.11.1 | Open WebUI | High8.7 | 0.11.1 |
| Sep 10 | Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loaderCVE-2026-87996 Open WebUIHigh7.7fixed in 0.11.1 | Open WebUI | High7.7 | 0.11.1 |
| Sep 10 | Open WebUI: Any authenticated user can inject chats into another user's folder via chat completionsCVE-2026-87997 Open WebUIMedium4.3fixed in 0.11.1 | Open WebUI | Medium4.3 | 0.11.1 |
| Sep 10 | Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletionCVE-2026-87998 Open WebUIHigh7.1fixed in 0.11.1 | Open WebUI | High7.1 | 0.11.1 |
| Sep 10 | Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetchCVE-2026-87999 Open WebUIHigh7.1fixed in 0.11.1 | Open WebUI | High7.1 | 0.11.1 |
| Sep 10 | Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchangeCVE-2026-88005 Open WebUIMedium6.5fixed in 0.9.0 | Open WebUI | Medium6.5 | 0.9.0 |
| Sep 9 | Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat treeCVE-2026-88000 Open WebUIMedium6.5fixed in 0.11.1 | Open WebUI | Medium6.5 | 0.11.1 |
| Sep 9 | Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targetsCVE-2026-88001 Open WebUIMedium5.0fixed in 0.11.1 | Open WebUI | Medium5.0 | 0.11.1 |
| Sep 9 | Open WebUI: Any authenticated user can hang the server via a cyclic chat message historyCVE-2026-88002 Open WebUIMedium6.5fixed in 0.11.1 | Open WebUI | Medium6.5 | 0.11.1 |
| Sep 8 | n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller PolicyCVE-2026-86996 n8nMediumfixed in 2.37.7, 2.38.2 | n8n | Medium | 2.37.7, 2.38.2 |
| Sep 8 | vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protectionsCVE-2026-73560 vLLMMedium6.5fixed in 0.26.0 | vLLM | Medium6.5 | 0.26.0 |