Skip to content

Security advisories for the AI and data stack

2,669 advisories for 70 projects · 46 critical or high in the last 30 days · checked daily

CriticalHighMediumLow

Patch now

All critical

Critical and high advisories published in the last six weeks, worst first, with the version that fixes each.

PublishedAdvisory
Sep 22lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks
CVE-2026-85734Critical9.1fixed in 1.5.5
Sep 22OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack
CVE-2026-63132Criticalfixed in 0.0.0-20260713141742-763625a20721
Sep 18LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py
CVE-2025-66455LMDeployCritical9.8fixed in 0.16.0
Sep 16LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy
CVE-2025-59953LMDeployCritical9.8fixed in 0.10.2
Sep 10Remote code execution in pytorch lightning
CVE-2024-5452Critical9.8fixed in 2.3.3
Sep 10pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
CVE-2024-5980Critical9.1fixed in 2.3.3
Sep 8NLTK: Allowlisted pickle loaders still permit code execution in current source
CVE-2026-79657NLTKCriticalfixed in 3.10.3
Sep 8NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution
CVE-2026-78683NLTKCriticalfixed in 3.10.0
Sep 2SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control
CVE-2026-72920Critical9.8fixed in 0.0.0-20260512171108-5e8f99f40a8a
Sep 1NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)
CVE-2026-79675NLTKCritical9.8fixed in 3.10.3
Aug 27LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
CVE-2026-37004LiteLLMCritical9.8fixed in 1.83.7
Aug 25Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import in github.com/dgraph-io/dgraph
CVE-2026-54061Critical9.1no fix yet
Aug 25Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution
CVE-2026-45018Critical9.8fixed in 2.12.0
Aug 21Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing
CVE-2026-61539XinferenceCritical10.0fixed in 2.7.0
Aug 17MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
CVE-2026-64849MLflowCritical9.3fixed in 3.15.0

Latest advisories

60 of 2,669 advisories

DateAdvisory
Sep 23MemoryOS 2.0.34 was published with a credential-stealing binary
PYSEC-2026-3987Unratedno fix yet
Sep 23Malicious code in memoryos (PyPI)
MAL-2026-16475Unratedno fix yet
Sep 22lightrag-hku: Stored Cross-Site Scripting (XSS) in the LightRAG WebUI chat/answer renderer via ingested content
CVE-2026-86062Medium6.1fixed in 1.5.5
Sep 22lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard
CVE-2026-85740High7.1fixed in 1.5.5
Sep 22lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks
CVE-2026-85734Critical9.1fixed in 1.5.5
Sep 22lightrag-hku: Plaintext Passwords Compared Without Constant-Time Function
CVE-2026-85725Medium5.9fixed in 1.5.5
Sep 22lightrag-hku: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses
CVE-2026-85709Medium5.3fixed in 1.5.5
Sep 22OpenBao Skips Stricter Deny Policy for LIST operations
CVE-2026-63131Mediumfixed in 0.0.0-20260713133043-f58d848c139e
Sep 22OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack
CVE-2026-63132Criticalfixed in 0.0.0-20260713141742-763625a20721
Sep 22OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters
CVE-2026-71543Highfixed in 0.0.0-20260710001938-2d4ebafec5c5
Sep 22OpenBao Agent Writes Secrets to Stdout
CVE-2026-77285Lowfixed in 0.0.0-20260714163218-90272575e5f5
Sep 22Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards
CVE-2026-69190Medium6.3fixed in 6.3.14, 7.0.9, 7.1.4
Sep 18LMDeploy has an SSRF bypass
GHSA-39wr-7q6h-cf68LMDeployHigh7.5fixed in 0.15.0
Sep 18LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading
CVE-2026-33625LMDeployHigh8.8fixed in 0.12.3
Sep 18LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py
CVE-2025-66455LMDeployCritical9.8fixed in 0.16.0
Sep 17Jupyter Server: 5xx request logging leaks token-bearing Referer header values
CVE-2026-86049JupyterHigh7.1fixed in 2.21.0
Sep 17Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-auth
CVE-2026-73245Medium6.5fixed in 2.0.0
Sep 17vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation
CVE-2026-69147vLLMMedium6.5fixed in 0.28.0
Sep 17LiteLLM Proxy has server-side request forgery via the `user_config` request parameter
CVE-2026-59823LiteLLMMediumfixed in 1.83.9
Sep 16vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions
CVE-2026-57173vLLMMedium6.5fixed in 0.24.0
Sep 16LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy
CVE-2025-59953LMDeployCritical9.8fixed in 0.10.2
Sep 12vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with
CVE-2026-90553vLLMHigh7.8fixed in 0.28.0
Sep 10Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange
CVE-2026-88006Open WebUIMedium6.5fixed in 0.11.1
Sep 10Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout
CVE-2026-87011Open WebUIHigh7.5fixed in 0.11.1
Sep 10Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value
CVE-2026-87012Open WebUIMedium4.3fixed in 0.11.1
Sep 10Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle
CVE-2026-87013Open WebUIMedium4.3fixed in 0.11.1
Sep 10Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes
CVE-2026-87014Open WebUIMedium6.5fixed in 0.11.1
Sep 10Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication
CVE-2026-87015Open WebUIMedium6.8fixed in 0.11.1
Sep 10Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite
CVE-2026-87016Open WebUIHigh8.1fixed in 0.11.1
Sep 10n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution
CVE-2026-86073n8nMediumfixed in 2.37.7, 2.38.1
Sep 10n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content
CVE-2026-86074n8nMediumfixed in 2.37.7, 2.38.2
Sep 10n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
CVE-2026-86995n8nMediumfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints
CVE-2026-86085n8nMediumfixed in 2.37.7, 2.38.2
Sep 10n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
CVE-2026-86993n8nMediumfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions
CVE-2026-86084n8nMediumfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
CVE-2026-86080n8nMediumfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers
CVE-2026-86079n8nMediumfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service
CVE-2026-86078n8nMediumfixed in 2.37.7, 2.38.2
Sep 10n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter
CVE-2026-86994n8nMediumfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution
CVE-2026-86083n8nHighfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket
CVE-2026-86077n8nMediumfixed in 2.37.7, 2.38.2
Sep 10Remote code execution in pytorch lightning
CVE-2024-5452Critical9.8fixed in 2.3.3
Sep 10pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
CVE-2024-5980Critical9.1fixed in 2.3.3
Sep 10n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node
CVE-2026-86082n8nHighfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path
CVE-2026-86081n8nHighfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint
CVE-2026-86075n8nHighfixed in 2.37.7, 2.38.2
Sep 10n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution
CVE-2026-86076n8nHighfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends
CVE-2026-87017Open WebUIMedium4.3fixed in 0.11.1
Sep 10Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint
CVE-2026-87994Open WebUIMedium4.3fixed in 0.11.1
Sep 10Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
CVE-2026-87995Open WebUIHigh8.7fixed in 0.11.1
Sep 10Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader
CVE-2026-87996Open WebUIHigh7.7fixed in 0.11.1
Sep 10Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions
CVE-2026-87997Open WebUIMedium4.3fixed in 0.11.1
Sep 10Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
CVE-2026-87998Open WebUIHigh7.1fixed in 0.11.1
Sep 10Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch
CVE-2026-87999Open WebUIHigh7.1fixed in 0.11.1
Sep 10Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange
CVE-2026-88005Open WebUIMedium6.5fixed in 0.9.0
Sep 9Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree
CVE-2026-88000Open WebUIMedium6.5fixed in 0.11.1
Sep 9Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
CVE-2026-88001Open WebUIMedium5.0fixed in 0.11.1
Sep 9Open WebUI: Any authenticated user can hang the server via a cyclic chat message history
CVE-2026-88002Open WebUIMedium6.5fixed in 0.11.1
Sep 8n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy
CVE-2026-86996n8nMediumfixed in 2.37.7, 2.38.2
Sep 8vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections
CVE-2026-73560vLLMMedium6.5fixed in 0.26.0

Questions

What is fru.dev Advisories?

A daily list of security advisories and CVEs for the AI and data stack: inference servers (vLLM, Ollama, SGLang, LiteLLM), agent frameworks (LangChain, LlamaIndex, Langflow, n8n), ML frameworks (PyTorch, TensorFlow, Transformers), MLOps (MLflow, Ray) and the data platform (Airflow, Spark, Kafka, dbt, DuckDB). Each advisory shows its severity, CVSS score, the affected versions and the version that fixes it.

Where does the data come from?

From the OSV database (osv.dev), which carries the GitHub Advisory Database and the PyPA, Go and other ecosystem databases, read every day. Duplicate records of the same issue (GHSA, PYSEC, GO ids) are folded into one, under the GitHub id. NVD fills in a score for the few records that have none.

How is severity decided?

Where GitHub reviewed an advisory, its severity label (critical, high, moderate, low) is used. The CVSS 3.x base score is computed from the advisory's vector with the FIRST formula. An advisory with only a CVSS 4.0 vector keeps GitHub's label. "Unrated" means no source has scored it yet.

What should I patch first?

The Patch now table on the home page lists critical and high advisories published in the last six weeks, worst first, with the fixed version. Upgrade the package to at least that version. An advisory with no fixed version has no patch yet: check the source advisory for a workaround.

Does an advisory mean my deployment is vulnerable?

Not necessarily. It means the listed versions of the package contain the issue. Whether you are exposed depends on the version you run and whether you use the affected feature. Check your installed version against the affected ranges on the advisory page.

Is there an RSS feed?

Yes. /rss.xml carries every new advisory, /severe.xml only critical and high ones, and each package has its own feed, for example /packages/vllm/rss.xml. A weekly email on Wednesdays lists the critical and high advisories, only in weeks that have some.

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.