Skip to content

All advisories

14,478 advisories for 277 projects, newest first

60 of 80 advisories

Advisory
Vitess users with backup storage access can write to arbitrary file paths on restore
vitessCriticalFeb 27
Langflow has Remote Code Execution in CSV Agent
LangflowCritical9.8Feb 27
Vitess users with backup storage access can gain unauthorized access to production deployment environments
vitessHighFeb 26
n8n has Webhook Forgery on Zendesk Trigger Node
n8nMedium4.0Feb 26
n8n has a Guardrail Node Bypass
n8nMedium3.7Feb 26
n8n has an Authentication Bypass in its Chat Trigger Node
n8nMedium4.8Feb 26
n8n has an SSO Enforcement Bypass in its Self-Service Settings API
n8nMedium6.3Feb 26
n8n: Webhook Forgery on Github Webhook Trigger
n8nMedium4.0Feb 26
n8n: SQL Injection in MySQL, PostgreSQL, and Microsoft SQL nodes
n8nMedium8.2Feb 26
LangChain Community: redirect chaining can lead to SSRF bypass via RecursiveUrlLoader
LangChainMedium4.1Feb 25
n8n Vulnerable to Stored XSS via Various Nodes
n8nHigh5.4Feb 25
n8n: Expression Sandbox Escape Leads to RCE
n8nCritical9.9Feb 25
n8n has Arbitrary Command Execution via File Write and Git Operations
n8nCritical8.5Feb 25
n8n has Potential Remote Code Execution via Merge Node
n8nCritical9.9Feb 25
n8n has a Sandbox Escape in its JavaScript Task Runner
n8nCriticalFeb 25
n8n has Arbitrary File Read via Python Code Node Sandbox Escape
n8nHigh9.9Feb 25
n8n has Unauthenticated Expression Evaluation via Form Node
n8nCritical9.0Feb 25
cli_history database does not restrict file permissions on Unix systems
AWSMedium5.9Feb 25
MindsDB: Path Traversal in /api/files Leading to Remote Code Execution
MindsDBHigh8.8Feb 24
nats-server websockets are vulnerable to pre-auth memory DoS
nats-serverMedium5.9Feb 24
Apache Superset Improper Authorization allows low-privileged users to bypass access controls
Apache SupersetHighFeb 24
Apache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine
Apache SupersetMediumFeb 24
Apache Superset allows privileged users to conduct error-based SQL Injection
Apache SupersetMediumFeb 24
Apache Superset allows authenticated users to view sensitive data without explicit permissions
Apache SupersetLowFeb 24
Apache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections
Apache SupersetHighFeb 24
Apache Airflow exposes sensitive information in its log files
Apache AirflowMedium6.5Feb 24
Apache Airflow vulnerable to Code Injection in the web-server context via LogTemplate table
Apache AirflowHigh8.4Feb 24
Incorrect calculation in circl secp384r1 CombinedMult
CloudflareLowFeb 24
Apache Airflow error reporting may expose full kwargs
Apache AirflowMedium6.5Feb 21
MLflow Use of Default Password Authentication Bypass Vulnerability
MLflowCritical9.8Feb 21
MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability
MLflowHigh8.1Feb 21
Ray dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion)
RayMedium5.9Feb 20
Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution
Semantic KernelCritical9.9Feb 19
Keras has a Local File Disclosure via HDF5 External Storage During Keras Weight Loading
KerasHigh7.1Feb 18
NLTK has a Zip Slip Vulnerability
NLTKCritical10.0Feb 18
Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering
Apache ArrowHigh7.0Feb 17
MindsDB affected by a SSRF vulnerability
MindsDBLow6.3Feb 16
Cloudflare Agents has a Reflected Cross-Site Scripting (XSS) vulnerability in AI Playground site
agentsMediumFeb 13
agents: cross-site scripting
agentsMediumFeb 13
Sandbox escape via Git hooks
CursorHigh8.0Feb 13
SurrealDB vulnerable to Denial of Service through scripting function memory edge case
SurrealDBMediumFeb 12
Milvus: Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise
MilvusCritical9.8Feb 11
@langchain/community affected by SSRF Bypass in RecursiveUrlLoader via insufficient URL origin validation
LangChainMedium4.1Feb 11
LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages
LangChainLow3.7Feb 11
Terminal auto replies restriction
MicrosoftHigh8.0Feb 10
Workspace trust for MCP servers
MicrosoftLowFeb 10
Apache Airflow UI Exposes DAG Import Errors to Unauthorized Authenticated Users
Apache AirflowMedium6.5Feb 9
Apache Airflow Has an Authorization Bypass That Allows Unauthorized Task Log Access
Apache AirflowMedium6.5Feb 9
Pydantic AI has Stored XSS via Path Traversal in Web UI CDN URL
pydantic-aiHigh7.1Feb 6
Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK
Semantic KernelCritical9.9Feb 6
Pydantic AI has Server-Side Request Forgery (SSRF) in URL Download Handling
pydantic-aiHigh8.6Feb 6
Command Injection via Directory Change Bypasses Write Protection
AnthropicHigh7.7Feb 6
Command Injection via Piped sed Command Bypasses File Write Restrictions
AnthropicHigh7.7Feb 6
Sandbox Escape via Persistent Configuration Injection in settings.json
AnthropicHigh7.7Feb 6
Permission Deny Bypass Through Symbolic Links
AnthropicLow2.3Feb 6
qdrant has arbitrary file write via `/logger` endpoint
QdrantHigh8.5Feb 5
n8n's domain allowlist bypass enables credential exfiltration
n8nMediumFeb 4
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
MCP SDKsHigh7.1Feb 4
n8n has a Python sandbox escape
n8nCritical9.9Feb 4
n8n Merge Node has Arbitrary File Write leading to RCE
n8nCriticalFeb 4

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.