Skip to content

All advisories

14,478 advisories for 277 projects, newest first

60 of 154 advisories

Advisory
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
JupyterHighApr 30
`container system dns create` unvalidated domain name allows pf rule injection
AppleLowApr 30
Insecure Hostname Validation Allows HTTP Downgrade Attack
AppleMedium6.9Apr 30
OS Command Injection in Amazon ECS Agent via FSx Windows File Server Volume Credentials
AWSHigh7.2Apr 30
OS Command Injection in Amazon ECS Agent via FSx Windows File Server Volume Credentials
AWSUnratedApr 30
n8n has XML Node Prototype Pollution that to RCE
n8nCritical9.9Apr 29
n8n has Prototype Pollution in XML Webhook Body Parser that Leads to RCE
n8nCritical10.0Apr 29
n8n Vulnerable to XSS via MCP OAuth client
n8nHigh8.2Apr 29
n8n's Credential Authorization Bypass in dynamic-node-parameters Allows Foreign API Key Replay
n8nHigh8.5Apr 29
n8n has a Python Task Runner Sandbox Escape Vulnerability
n8nHigh7.5Apr 29
n8n has Public API Variables IDOR that Allows Cross-Project Secret Disclosure
n8nMedium7.7Apr 29
n8n Vulnerable to Unauthenticated Denial of Service via MCP Client Registration
n8nHigh7.5Apr 29
n8n Vulnerable to Hijacking of Unauthenticated Chat Execution
n8nMedium5.4Apr 29
n8n has SQL Injection in SeaTable Node
n8nMedium6.8Apr 29
n8n has Open Redirect in MCP OAuth Consent Flow
n8nMedium4.7Apr 29
n8n has SQL Injection in Oracle Database Node via Limit Field
n8nMedium9.8Apr 29
n8n has SQL Injection in Snowflake and MySQL Nodes
n8nMedium8.2Apr 29
Issue with FreeRTOS-Plus-TCP - MAC Address Validation Bypass and ICMP Echo Reply Integer...
AWSUnratedApr 29
Integer Underflow in DHCPv6 Sub-Option Parser in FreeRTOS-Plus-TCP
AWSUnratedApr 29
Issue with FreeRTOS-Plus-TCP - IPv6 Router Advertisement Memory Safety Issues
AWSUnratedApr 29
vLLM makes Use of Uninitialized Resource
vLLMLow5.6Apr 27
Arbitrary Code Execution via Sandbox Bypass in QnABot on AWS
AWSUnratedApr 27
Ollama is Vulnerable to Path Traversal
OllamaLow5.6Apr 26
LiteLLM: Authenticated command execution via MCP stdio test endpoints
LiteLLMHigh8.8Apr 25
Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses
gemini-cliCritical10.0Apr 24
LiteLLM has SQL Injection in Proxy API key verification
LiteLLMCritical9.8Apr 24
Dgraph: Unauthenticated Admin Token Disclosure Leading to Authentication Bypass via /debug/vars
DgraphCritical9.8Apr 24
Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization
RayHighApr 24
LiteLLM: Server-Side Template Injection in /prompts/test endpoint
LiteLLMHighApr 24
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in NQuad Lang Field
DgraphCritical9.1Apr 24
Dgraph: Pre-Auth Full Database Exfiltration via DQL Injection in Upsert Condition Field
DgraphCritical9.1Apr 24
Apache Airflow: improper access control
Apache AirflowMedium4.3Apr 24
Apache Airflow's asset dependency graph did not restrict nodes by the viewer's DAG read permissions
Apache AirflowMedium4.3Apr 24
Apache DolphinScheduler has an Incorrect Authorization Vulnerability
dolphinschedulerHigh8.1Apr 24
Apache DolphinScheduler RPC module has a Deserialization of Untrusted Data vulnerability
dolphinschedulerMedium6.3Apr 24
Grafana Tempo has an Uncontrolled Resource Consumption issue
TempoHigh7.5Apr 24
Claude SDK for TypeScript has Insecure Default File Permissions in Local Filesystem Memory Tool
AnthropicMedium4.8Apr 24
Trust Dialog Bypass via Git Worktree Spoofing Allows Arbitrary Code Execution
AnthropicHigh7.7Apr 24
Issue with AWS Ops Wheel (CVE-2026-6911 and CVE-2026-6912
AWSUnratedApr 24
H2O-3: remote code execution
H2O-3Critical9.8Apr 23
Malicious code in xinference (PyPI)
XinferenceUnratedApr 22
Title: Sandbox escape via JavaScript prototype chain traversal in cohere-terrarium
CohereCritical9.3Apr 22
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
FlowiseCritical9.8Apr 21
OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation
OpenBaoLowApr 21
OpenBao's SQL Injection in PostgreSQL database secrets engine
OpenBaoMedium4.9Apr 21
OpenBao: Decompression Bomb via Unbounded Copy in OCI Plugin Extraction (DoS)
OpenBaoLow3.1Apr 21
OpenBao's Certificate Authentication Allows Token Renewal With Different Certificate
OpenBaoLow3.1Apr 21
nbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image Embedding
JupyterMedium6.5Apr 21
nbconvert has an Arbitrary File Write via Path Traversal in Cell Attachment Filenames
JupyterMedium6.5Apr 21
LMDeploy has Server-Side Request Forgery (SSRF) via Vision-Language Image Loading
LMDeployHigh7.5Apr 21
Apache Kafka does not validate JWT tokens in its OAUTHBEARER authentication implementation
Apache KafkaCritical9.1Apr 20
Apache Kafka exposes sensitive information in its DEBUG logs
Apache KafkaMedium5.3Apr 20
FastChat has Denial of Service Through Blocking Event Loop in Model Workers (Incomplete Fix for ff66426)
FastChatMedium5.3Apr 20
AgentScope vulnerable to Server-Side Request Forgery
agentscopeMedium7.3Apr 20
FastChat has a Content Moderation Bypass via Arena Side-by-Side Views
FastChatMedium5.3Apr 20
AgentScope vulnerable to Server-Side Request Forgery
agentscopeMedium7.3Apr 20
AgentScope vulnerable to Server-Side Request Forgery
agentscopeMedium7.3Apr 20
Langflow: Cleartext Storage of Authentication Settings in Project Creation Endpoint
LangflowLow4.3Apr 20
AgentScope Vulnerable to Remote Code Injection
agentscopeMedium7.3Apr 20
Langflow vulnerable to injection
LangflowLow6.3Apr 20

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.