Skip to content

All advisories

14,478 advisories for 277 projects, newest first

52 advisories

Advisory
Agno session state overwrites between different sessions/users
agnoHigh7.1Oct 31, 2025
n8n Vulnerable to Remote Code Execution via Git Node Pre-Commit Hook
n8nHigh8.8Oct 30, 2025
Apache Airflow `/api/v2/dagReports` executes DAG Python in API
Apache AirflowMedium5.4Oct 30, 2025
Apache Airflow's create action can upsert existing Pools/Connections/Variables
Apache AirflowMedium4.6Oct 30, 2025
Apache Airflow has a command injection vulnerability in "example_dag_decorator"
Apache AirflowMediumOct 30, 2025
MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability
MLflowHigh8.1Oct 29, 2025
MLflow Weak Password Requirements Authentication Bypass Vulnerability
MLflowHigh8.1Oct 29, 2025
FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name
fastmcpMediumOct 29, 2025
FastMCP vulnerable to reflected XSS in client's callback page
fastmcpMediumOct 29, 2025
FastMCP Auth Integration Allows for Confused Deputy Account Takeover
fastmcpHighOct 29, 2025
Keras is vulnerable to arbitrary local file loading and Server-Side Request Forgery
KerasMediumOct 29, 2025
Consul key/value endpoint is vulnerable to denial of service
ConsulMedium6.5Oct 28, 2025
Consul event endpoint is vulnerable to denial of service
ConsulMedium6.5Oct 28, 2025
Python - Zip64 Locator Offset Vulnerability
GoogleMediumOct 27, 2025
Hashicorp Vault and Vault Enterprise vulnerable to a denial of service when processing JSON
VaultHigh7.5Oct 23, 2025
HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass
VaultHigh8.1Oct 23, 2025
OpenBao and Vault Leak []byte Fields in Audit Logs
OpenBaoMediumOct 22, 2025
OpenBao leaks HTTPRawBody in Audit Logs
OpenBaoMediumOct 22, 2025
Keras framework vulnerable to deserialization of untrusted data
KerasCritical9.8Oct 17, 2025
OpenBao has potential Denial of Service vulnerability when processing malicious unauthenticated JSON requests
OpenBaoHigh7.5Oct 17, 2025
MinIO is Vulnerable to Privilege Escalation via Session Policy Bypass in Service Accounts and STS
MinIOHigh8.1Oct 16, 2025
Apache Spark has Inadequate Encryption Strength
Apache SparkLowOct 15, 2025
Flowise: Authenticated Command Execution and Sandbox Bypass via Puppeteer and Playwright Packages
FlowiseHighOct 14, 2025
llama-index has Insecure Temporary File
LlamaIndexHigh7.1Oct 13, 2025
Flowise is vulnerable to arbitrary file exposure through its ReadFileTool
FlowiseHigh7.7Oct 10, 2025
Elasticsearch: Insertion of Sensitive Information into Log File via reindex API
ElasticsearchMedium5.7Oct 10, 2025
n8n: Execute Command Node Allows Authenticated Users to Run Arbitrary Commands on Host
n8nHigh8.8Oct 9, 2025
Flowise is vulnerable to arbitrary file write through its WriteFileTool
FlowiseCritical9.9Oct 9, 2025
FlowiseAI/Flosise has File Upload vulnerability
FlowiseHigh8.3Oct 8, 2025
vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class
vLLMHigh7.1Oct 7, 2025
LLaMA Factory's Chat API Contains Critical SSRF and LFI Vulnerabilities
LlamaFactoryHigh7.6Oct 7, 2025
vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server
vLLMMedium6.5Oct 7, 2025
vLLM is vulnerable to timing attack at bearer auth
vLLMHigh7.5Oct 7, 2025
SillyTavern Web Interface Vulnerable DNS Rebinding
SillyTavernCritical9.6Oct 6, 2025
Flowise vulnerable to RCE via Dynamic function constructor injection
FlowiseCritical9.8Oct 6, 2025
clearml is vulnerable to Path Traversal through its `safe_extract` function
ClearMLMedium5.8Oct 5, 2025
ZenML is vulnerable to Path Traversal through its `PathMaterializer` class
ZenMLMedium6.3Oct 5, 2025
Flowise Stored XSS vulnerability through logs in chatbot
FlowiseMedium5.3Oct 3, 2025
Flowise is vulnerable to stored XSS via "View Messages" allows credential theft in FlowiseAI admin panel
FlowiseCritical9.3Oct 3, 2025
Flowise vulnerable to XSS
FlowiseMediumOct 3, 2025
Command execution prior to Claude Code startup trust dialog
AnthropicHigh8.7Oct 3, 2025
Permission deny bypass through symlink
AnthropicLow2.3Oct 3, 2025
Apache Kylin Server-Side Request Forgery (SSRF) Vulnerability
kylinHigh7.3Oct 2, 2025
Apache Kylin Authentication Bypass Vulnerability
kylinHigh7.5Oct 2, 2025
Apache Kylin Files or Directories Accessible to External Parties
kylinHigh7.5Oct 2, 2025
Cursor CLI Agent - Sensitive File Overwrite Bypass
CursorHigh7.1Oct 2, 2025
Cursor IDE - Sensitive File Overwrite Bypass
CursorHigh8.0Oct 2, 2025
Remote Code Execution in Cursor CLI via Cursor Agent MCP OAuth2 Communication
CursorHigh8.8Oct 2, 2025
Arbitrary code execution Permissive CLI Config in Cursor CLI
CursorHigh8.8Oct 2, 2025
RCE via .code-workspace files using Prompt Injection
CursorHigh7.5Oct 2, 2025
Potential Information Leakage via Mermaid Diagram
CursorMedium5.9Oct 2, 2025
Improper File Type Handling in Bulk User Import in Auth0 Wordpress plugin CVE-2025-58769...
OktaUnratedOct 1, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.