Skip to content

All advisories

2,669 advisories for 70 projects, newest first

60 of 2,669 advisories

DateAdvisory
Sep 23MemoryOS 2.0.34 was published with a credential-stealing binary
PYSEC-2026-3987Unratedno fix yet
Sep 23Malicious code in memoryos (PyPI)
MAL-2026-16475Unratedno fix yet
Sep 22lightrag-hku: Stored Cross-Site Scripting (XSS) in the LightRAG WebUI chat/answer renderer via ingested content
CVE-2026-86062Medium6.1fixed in 1.5.5
Sep 22lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard
CVE-2026-85740High7.1fixed in 1.5.5
Sep 22lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks
CVE-2026-85734Critical9.1fixed in 1.5.5
Sep 22lightrag-hku: Plaintext Passwords Compared Without Constant-Time Function
CVE-2026-85725Medium5.9fixed in 1.5.5
Sep 22lightrag-hku: Sensitive Information Exposure Through Raw Exception Messages in API Error Responses
CVE-2026-85709Medium5.3fixed in 1.5.5
Sep 22OpenBao Skips Stricter Deny Policy for LIST operations
CVE-2026-63131Mediumfixed in 0.0.0-20260713133043-f58d848c139e
Sep 22OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack
CVE-2026-63132Criticalfixed in 0.0.0-20260713141742-763625a20721
Sep 22OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters
CVE-2026-71543Highfixed in 0.0.0-20260710001938-2d4ebafec5c5
Sep 22OpenBao Agent Writes Secrets to Stdout
CVE-2026-77285Lowfixed in 0.0.0-20260714163218-90272575e5f5
Sep 22Graylog: Manager-to-Owner privilege escalation on saved searches and dashboards
CVE-2026-69190Medium6.3fixed in 6.3.14, 7.0.9, 7.1.4
Sep 18LMDeploy has an SSRF bypass
GHSA-39wr-7q6h-cf68LMDeployHigh7.5fixed in 0.15.0
Sep 18LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading
CVE-2026-33625LMDeployHigh8.8fixed in 0.12.3
Sep 18LMDeploy has Remote Code Execution by Pickle Deserialization via handle_zmq_recv in lmdeploy/lmdeploy/pytorch/disagg/conn/engine_conn.py
CVE-2025-66455LMDeployCritical9.8fixed in 0.16.0
Sep 17Jupyter Server: 5xx request logging leaks token-bearing Referer header values
CVE-2026-86049JupyterHigh7.1fixed in 2.21.0
Sep 17Kestra: Unauthenticated management/actuator endpoints exposed on port 8081 (/env, /loggers) bypass API basic-auth
CVE-2026-73245Medium6.5fixed in 2.0.0
Sep 17vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation
CVE-2026-69147vLLMMedium6.5fixed in 0.28.0
Sep 17LiteLLM Proxy has server-side request forgery via the `user_config` request parameter
CVE-2026-59823LiteLLMMediumfixed in 1.83.9
Sep 16vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions
CVE-2026-57173vLLMMedium6.5fixed in 0.24.0
Sep 16LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy
CVE-2025-59953LMDeployCritical9.8fixed in 0.10.2
Sep 12vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with
CVE-2026-90553vLLMHigh7.8fixed in 0.28.0
Sep 10Open WebUI: Users denied by the OAuth role policy can still sign in via token exchange
CVE-2026-88006Open WebUIMedium6.5fixed in 0.11.1
Sep 10Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout
CVE-2026-87011Open WebUIHigh7.5fixed in 0.11.1
Sep 10Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert value
CVE-2026-87012Open WebUIMedium4.3fixed in 0.11.1
Sep 10Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycle
CVE-2026-87013Open WebUIMedium4.3fixed in 0.11.1
Sep 10Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes
CVE-2026-87014Open WebUIMedium6.5fixed in 0.11.1
Sep 10Open WebUI: A user's session cookies are sent to tool servers configured for bearer authentication
CVE-2026-87015Open WebUIMedium6.8fixed in 0.11.1
Sep 10Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite
CVE-2026-87016Open WebUIHigh8.1fixed in 0.11.1
Sep 10n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution
CVE-2026-86073n8nMediumfixed in 2.37.7, 2.38.1
Sep 10n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content
CVE-2026-86074n8nMediumfixed in 2.37.7, 2.38.2
Sep 10n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
CVE-2026-86995n8nMediumfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints
CVE-2026-86085n8nMediumfixed in 2.37.7, 2.38.2
Sep 10n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
CVE-2026-86993n8nMediumfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions
CVE-2026-86084n8nMediumfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
CVE-2026-86080n8nMediumfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers
CVE-2026-86079n8nMediumfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service
CVE-2026-86078n8nMediumfixed in 2.37.7, 2.38.2
Sep 10n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter
CVE-2026-86994n8nMediumfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution
CVE-2026-86083n8nHighfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket
CVE-2026-86077n8nMediumfixed in 2.37.7, 2.38.2
Sep 10Remote code execution in pytorch lightning
CVE-2024-5452Critical9.8fixed in 2.3.3
Sep 10pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
CVE-2024-5980Critical9.1fixed in 2.3.3
Sep 10n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node
CVE-2026-86082n8nHighfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path
CVE-2026-86081n8nHighfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint
CVE-2026-86075n8nHighfixed in 2.37.7, 2.38.2
Sep 10n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution
CVE-2026-86076n8nHighfixed in 1.123.76, 2.37.7, 2.38.2
Sep 10Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backends
CVE-2026-87017Open WebUIMedium4.3fixed in 0.11.1
Sep 10Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint
CVE-2026-87994Open WebUIMedium4.3fixed in 0.11.1
Sep 10Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
CVE-2026-87995Open WebUIHigh8.7fixed in 0.11.1
Sep 10Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader
CVE-2026-87996Open WebUIHigh7.7fixed in 0.11.1
Sep 10Open WebUI: Any authenticated user can inject chats into another user's folder via chat completions
CVE-2026-87997Open WebUIMedium4.3fixed in 0.11.1
Sep 10Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion
CVE-2026-87998Open WebUIHigh7.1fixed in 0.11.1
Sep 10Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch
CVE-2026-87999Open WebUIHigh7.1fixed in 0.11.1
Sep 10Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange
CVE-2026-88005Open WebUIMedium6.5fixed in 0.9.0
Sep 9Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat tree
CVE-2026-88000Open WebUIMedium6.5fixed in 0.11.1
Sep 9Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targets
CVE-2026-88001Open WebUIMedium5.0fixed in 0.11.1
Sep 9Open WebUI: Any authenticated user can hang the server via a cyclic chat message history
CVE-2026-88002Open WebUIMedium6.5fixed in 0.11.1
Sep 8n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy
CVE-2026-86996n8nMediumfixed in 2.37.7, 2.38.2
Sep 8vLLM: SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections
CVE-2026-73560vLLMMedium6.5fixed in 0.26.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.