Skip to content

All advisories

14,478 advisories for 277 projects, newest first

34 advisories

Advisory
Ray's New Token Authentication is Disabled By Default
RayCriticalNov 27, 2025
Ray is vulnerable to Critical RCE via Safari & Firefox Browsers through DNS Rebinding Attack
RayCriticalNov 26, 2025
VictoriaMetrics' Snappy Decoder DoS Vulnerability is Causing OOM
VictoriaMetricsLow2.7Nov 25, 2025
Malicious code in @browserbasehq/stagehand (npm)
stagehandUnratedNov 25, 2025
OpenBao is Vulnerable to Privileged Operator Identity Group Root Escalation
OpenBaoHighNov 24, 2025
Malicious code in @mcp-use/inspector (npm)
mcp-useUnratedNov 24, 2025
Malicious code in @posthog/agent (npm)
PostHogUnratedNov 24, 2025
vLLM: resource exhaustion
vLLMMedium6.5Nov 20, 2025
vLLM vulnerable to DoS with incorrect shape of multimodal embedding inputs
vLLMHigh6.5Nov 20, 2025
vLLM deserialization vulnerability leading to DoS and potential RCE
vLLMHigh8.8Nov 20, 2025
LangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates
LangChainHighNov 20, 2025
Sed Command Validation Bypass Allows Arbitrary File Writes
AnthropicHigh8.7Nov 20, 2025
Command execution prior to Claude Code startup trust dialog
AnthropicHigh7.7Nov 19, 2025
Modular Max Serve has Unsafe Deserialization vulnerability
modularCriticalNov 18, 2025
"Astral-tokio-tar" / "uv" Arbitrary Write Path Traversal Vulnerability
GoogleMediumNov 18, 2025
Flowise has Authentication Bypass Using Unprotected Registration Endpoint (/register)
FlowiseHighNov 17, 2025
Flowise Fails to Invalidate Existing Sessions After Password Changes
FlowiseHigh8.1Nov 14, 2025
Milvus Proxy has a Critical Authentication Bypass Vulnerability
MilvusCriticalNov 13, 2025
DuckDB is a SQL database management system
DuckDBMedium6.5Nov 12, 2025
PyTorch: denial of service
PyTorchLow3.3Nov 12, 2025
Datadog Linux Host Agent affected by local privilege escalation due to insufficient pycache permissions
DatadogHigh7.0Nov 11, 2025
Privilege Escalation in Aurora PostgreSQL instance using AWS-JDBC Wrapper
AWSHigh8.0Nov 10, 2025
Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
Open WebUIHigh7.3Nov 7, 2025
Open WebUI: cross-site scripting
Open WebUIHigh8.7Nov 7, 2025
OpenTofu affected denials of service in "tofu init" with maliciously-crafted module package responses
OpenTofuLow3.1Nov 6, 2025
Open redirect endpoint in Datasette
datasetteLowNov 6, 2025
Argo Workflow has a Zipslip Vulnerability in github.com/argoproj/argo-workflows
argo-workflowsUnratedNov 5, 2025
Argo Workflow may expose artifact repository credentials in github.com/argoproj/argo-workflows
argo-workflowsUnratedNov 5, 2025
Missing validation of redirect_uri on OAuth callback handler
CloudflareMedium4.8Nov 4, 2025
Cursorignore Bypass via New Cursorignore Write
CursorHighNov 3, 2025
Command Injection via Untrusted MCP Configuration in Cursor CLI Beta
CursorHigh8.8Nov 3, 2025
Speedbump Modal Bypass in Cursor MCP Server Deep-Link
CursorHigh8.8Nov 3, 2025
Sensitive File Modification - NTFS Path Quirks
CursorHigh8.8Nov 3, 2025
Sensitive File Protection Bypass - Path Manipulation Using Backslashes on Windows
CursorHigh8.8Nov 3, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.