Skip to content

All advisories

14,478 advisories for 277 projects, newest first

45 advisories

Advisory
Llama Stack exposes secret in initialization log
Llama StackLow3.2Jan 30
vLLM vulnerable to Server-Side Request Forgery (SSRF) through MediaConnector
vLLMHigh7.1Jan 28
PyTorch: code execution
PyTorchHigh8.8Jan 27
n8n Unsafe Workflow Expression Evaluation Allows Remote Code Execution
n8nCritical9.9Jan 27
BentoML has a Path Traversal via Bentofile Configuration
BentoMLHigh7.4Jan 26
Langflow affected by Remote Code Execution via validate_code() exec()
LangflowHighJan 23
SurrealDB Affected by Confused Deputy Privilege Escalation through Future Fields and Functions
SurrealDBHighJan 22
Python Wheel (Zip) Parser Differential Vulnerability v2.0
GoogleMediumJan 22
Archive extraction does not guard against escapes from extraction base directory
AppleLowJan 22
OpenTofu has High CPU usage in "tofu init" with maliciously-crafted module packages in .zip format
OpenTofuLow3.1Jan 21
Argo Workflows affected by stored XSS in the artifact directory listing
argo-workflowsHighJan 21
vLLM affected by RCE via auto_map dynamic module loading during model initialization
vLLMHigh8.8Jan 21
Apache Solr: Unauthorized bypass of certain "predefined permission" rules in the RuleBasedAuthorizationPlugin
Apache SolrHigh8.2Jan 21
Apache Solr: Insufficient file-access checking in standalone core-creation requests
Apache SolrHigh7.1Jan 21
OS Command Injection in `wrangler pages deploy`
CloudflareHigh7.7Jan 21
Chainlit contain a server-side request forgery (SSRF) vulnerability
chainlitHigh7.7Jan 20
chainlit: arbitrary file read
chainlitMedium6.5Jan 20
Anthropic: information disclosure
AnthropicMedium5.3Jan 20
Apache Linkis: Arbitrary File Read via Double URL Encoding Bypass
linkisHigh7.5Jan 19
Apache Airflow secrets in rendered templates could contain parts of sensitive values when truncated
Apache AirflowHigh7.5Jan 16
Apache Airflow proxy credentials for various providers might leak in task logs
Apache AirflowHigh7.5Jan 16
Chainlit contains an authorization bypass vulnerability
chainlitLow4.2Jan 14
Terminal Tool Allowlist Bypass via Environment Variables
CursorHighJan 14
vLLM is vulnerable to DoS in Idefics3 vision models via image payload with ambiguous dimensions
vLLMMedium6.5Jan 13
n8n: Webhook Node IP Whitelist Bypass via Partial String Matching
n8nMedium5.3Jan 13
LlamaIndex: unsafe deserialization
LlamaIndexHigh7.8Jan 12
LlamaIndex: resource exhaustion
LlamaIndexHigh7.5Jan 12
Label Studio: cross-site scripting
Label StudioHighJan 12
MindsDB has improper sanitation of filepath that leads to information disclosure and DOS
MindsDBHigh8.1Jan 12
MLFlow is vulnerable to DNS rebinding attacks due to a lack of Origin header validation
MLflowHigh8.1Jan 12
WeKnora has Command Injection in MCP stdio test
WeKnoraCritical9.9Jan 9
WeKnora vulnerable to SQL Injection
WeKnoraMedium5.6Jan 9
Defense in depth enhancement for region parameter value in AWS SDK for Go v2
AWSLow3.7Jan 9
vLLM introduced enhanced protection for CVE-2025-62164
vLLMHigh8.8Jan 8
Defense in depth enhancement for region parameter value in AWS SDK for .NET V4
AWSLow3.7Jan 8
Defense in depth enhancement for region parameter value in AWS SDK for C++
AWSLow3.7Jan 8
Defense in depth enhancement for region parameter value in AWS SDK for JavaScript v3
AWSLow3.7Jan 8
n8n's Missing Stripe-Signature Verification Allows Unauthenticated Forged Webhooks
n8nMedium6.5Jan 7
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
n8nCritical10.0Jan 7
n8n Vulnerable to RCE via Arbitrary File Write
n8nCritical9.9Jan 6
TrustZone Break-in Vulnerabilities in Ampere UEFI MM Drivers (Buffer Overflow and Stack Information Leak)
GoogleMedium4.6Jan 6
TrustZone Break-in Vulnerabilities in Ampere UEFI MM Drivers (Arbitrary Out-of-Bounds Write)
GoogleMedium4.6Jan 6
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
MCP SDKsHighJan 5
Langflow Missing Authentication on Critical API Endpoints
LangflowHighJan 2
Feast vulnerable to Deserialization of Untrusted Data
FeastHigh7.8Jan 1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.