| Dec 262025 | FastMCP updated to MCP 1.23+ due to CVE-2025-66416 fastmcpHighDec 26, 2025 | fastmcp | High | 2.14.0 |
| Dec 262025 | Self-hosted n8n has Legacy Code node that enables arbitrary file read/write n8nHigh7.1Dec 26, 2025 | n8n | High7.1 | 2.0.0 |
| Dec 262025 | n8n Vulnerable to Arbitrary Command Execution in Pyodide based Python Code Node n8nCritical9.9Dec 26, 2025 | n8n | Critical9.9 | 2.0.0 |
| Dec 262025 | lmdeploy vulnerable to Arbitrary Code Execution via Insecure Deserialization in torch.load() LMDeployHigh8.8Dec 26, 2025 | LMDeploy | High8.8 | 0.11.1 |
| Dec 262025 | n8n's Possible Stored XSS in "Respond to Webhook" Node May Execute Outside iframe Sandbox n8nHigh7.3Dec 26, 2025 | n8n | High7.3 | 1.114.0 |
| Dec 232025 | Transformers: code injection TransformersHigh7.8Dec 23, 2025 | Transformers | High7.8 | No fix yet |
| Dec 232025 | Transformers: unsafe deserialization TransformersHigh7.8Dec 23, 2025 | Transformers | High7.8 | No fix yet |
| Dec 232025 | Transformers: unsafe deserialization TransformersHigh7.8Dec 23, 2025 | Transformers | High7.8 | No fix yet |
| Dec 232025 | Transformers: unsafe deserialization TransformersHigh7.8Dec 23, 2025 | Transformers | High7.8 | No fix yet |
| Dec 232025 | Transformers: unsafe deserialization TransformersHigh7.8Dec 23, 2025 | Transformers | High7.8 | No fix yet |
| Dec 232025 | Transformers: unsafe deserialization TransformersHigh7.8Dec 23, 2025 | Transformers | High7.8 | No fix yet |
| Dec 232025 | Transformers: code injection TransformersHigh7.8Dec 23, 2025 | Transformers | High7.8 | No fix yet |
| Dec 232025 | Transformers: code injection TransformersHigh7.8Dec 23, 2025 | Transformers | High7.8 | No fix yet |
| Dec 232025 | LangChain serialization injection vulnerability enables secret extraction LangChainHigh8.6Dec 23, 2025 | LangChain | High8.6 | 0.3.37+3 more |
| Dec 232025 | LangChain serialization injection vulnerability enables secret extraction in dumps/loads APIs LangChainCritical9.3Dec 23, 2025 | LangChain | Critical9.3 | 0.3.81+1 more |
| Dec 222025 | n8n Vulnerable to Remote Code Execution via Expression Injection n8nCritical9.9Dec 22, 2025 | n8n | Critical9.9 | 1.120.4+1 more |
| Dec 192025 | External Control of File Name or Path in Langflow LangflowHigh7.1Dec 19, 2025 | Langflow | High7.1 | 1.7.1 |
| Dec 192025 | Langflow vulnerable to Server-Side Request Forgery LangflowHigh7.7Dec 19, 2025 | Langflow | High7.7 | 1.7.1 |
| Dec 182025 | nbconvert has an uncontrolled search path that leads to unauthorized code execution on Windows JupyterHighDec 18, 2025 | Jupyter | High | 7.17.0 |
| Dec 182025 | Dify: insecure permissions DifyHigh7.5Dec 18, 2025 | Dify | High7.5 | No fix yet |
| Dec 182025 | Ollama Platform has missing authentication enabling attackers to perform model management operations OllamaCriticalDec 18, 2025 | Ollama | Critical | No fix yet |
| Dec 182025 | Palo Alto Vulnerability Report GoogleHighDec 18, 2025 | Google | High | TBD |
| Dec 172025 | Edge3 Worker RPC RCE on Airflow 2 Apache AirflowCritical9.8Dec 17, 2025 | Apache Airflow | Critical9.8 | 2.0.0 |
| Dec 172025 | Key Commitment issue in S3 Encryption Client AWSMedium5.3Dec 17, 2025 | AWS | Medium5.3 | 3.368.0 |
| Dec 172025 | Key Commitment issue in S3 Encryption Client AWSMedium5.3Dec 17, 2025 | AWS | Medium5.3 | 1.208.0 |
| Dec 172025 | Key Commitment issue in S3 Encryption Client AWSMedium5.3Dec 17, 2025 | AWS | Medium5.3 | 1.11.712 |
| Dec 152025 | Apache Airflow exposes secret values to authenticated UI users via rendered templates Apache AirflowMedium6.5Dec 15, 2025 | Apache Airflow | Medium6.5 | 3.1.5 |
| Dec 152025 | Elasticsearch: improper authentication ElasticsearchMedium6.8Dec 15, 2025 | Elasticsearch | Medium6.8 | 8.19.8+2 more |
| Dec 152025 | Token Leak via Open Redirection and CSRF in the Callback Handler of cloudflare/workers-oauth-provider GoogleMediumDec 15, 2025 | Google | Medium | v0.0.12 |
| Dec 122025 | Weaviate OSS has a Path Traversal Vulnerability via Backup ZipSlip WeaviateHighDec 12, 2025 | Weaviate | High | 1.30.20+3 more |
| Dec 122025 | Weaviate OSS has path traversal vulnerability via the Shard Movement API WeaviateHighDec 12, 2025 | Weaviate | High | 1.30.20+3 more |
| Dec 102025 | Improper Memory Cleanup in the Okta Java SDK CVE-2025-66033 - Dec 10, 2025 OktaUnratedDec 10, 2025 | Okta | Unrated | No fix yet |
| Dec 102025 | Improper Validation of Query Parameters in Auth0 Next.js SDK CVE-2025-67716 - Dec 10, 2025 Auth0 Next.js SDKUnratedDec 10, 2025 | Auth0 Next.js SDK | Unrated | No fix yet |
| Dec 102025 | Improper Request Caching Lookup in the Auth0 Next.js SDK CVE-2025-67490 - Dec 10, 2025 OktaUnratedDec 10, 2025 | Okta | Unrated | No fix yet |
| Dec 102025 | Race condition in the Okta Java SDK CVE-2025-67505 - Dec 10, 2025 OktaUnratedDec 10, 2025 | Okta | Unrated | No fix yet |
| Dec 92025 | When OpenTofu is acting as a TLS client authenticating a certificate chain... OpenTofuMedium5.9Dec 9, 2025 | OpenTofu | Medium5.9 | 1.10.8 |
| Dec 92025 | RCE via ZipSlip and symbolic links in argoproj/argo-workflows argo-workflowsHigh8.1Dec 9, 2025 | argo-workflows | High8.1 | No fix yet |
| Dec 82025 | n8n vulnerable to Remote Code Execution via Git Node Custom Pre-Commit Hook n8nCriticalDec 8, 2025 | n8n | Critical | 1.119.2 |
| Dec 62025 | Langflow CORS misconfiguration enables Account Takeover and RCE LangflowCritical8.8Dec 6, 2025 | Langflow | Critical8.8 | 1.7.0 |
| Dec 42025 | Open WebUI: server-side request forgery Open WebUIHigh8.5Dec 4, 2025 | Open WebUI | High8.5 | 0.6.37 |
| Dec 42025 | ComposioHQ has a directory traversal vulnerability composioMedium7.5Dec 4, 2025 | composio | Medium7.5 | No fix yet |
| Dec 42025 | open-webui is Vulnerable to Incorrect Access Control Open WebUILowDec 4, 2025 | Open WebUI | Low | No fix yet |
| Dec 42025 | Network Sandboxing Escape AnthropicLow1.8Dec 4, 2025 | Anthropic | Low1.8 | 0.0.16 |
| Dec 42025 | Improper HMAC Signature Verification in auth0/node-jws CVE-2025-65945 - Dec 4, 2025 OktaUnratedDec 4, 2025 | Okta | Unrated | No fix yet |
| Dec 32025 | Command Validation Bypass Allows Arbitrary Code Execution AnthropicHigh8.7Dec 3, 2025 | Anthropic | High8.7 | v1.0.93 |
| Dec 22025 | vLLM vulnerable to remote code execution via transformers_utils/get_config vLLMHigh7.1Dec 2, 2025 | vLLM | High7.1 | 0.11.1 |
| Dec 22025 | Model Context Protocol (MCP) Python SDK does not enable DNS rebinding protection by default MCP SDKsHighDec 2, 2025 | MCP SDKs | High | 1.23.0 |
| Dec 22025 | Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default MCP SDKsHighDec 2, 2025 | MCP SDKs | High | 1.24.0 |
| Dec 22025 | Portkey.ai Gateway: Server-Side Request Forgery (SSRF) in Custom Host gatewayMediumDec 2, 2025 | gateway | Medium | 1.14.0 |
| Dec 22025 | Keras Directory Traversal Vulnerability KerasHigh9.8Dec 2, 2025 | Keras | High9.8 | 3.12.0 |