| May 29 | agno contains a SQL injection vulnerability agnoHigh8.3May 29 | agno | High8.3 | No fix yet |
| May 28 | OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens OpenBaoMedium5.3May 28 | OpenBao | Medium5.3 | 2.5.4 |
| May 28 | OpenBao's Inline Auth Incorrectly Redacted Headers OpenBaoMediumMay 28 | OpenBao | Medium | 2.5.4 |
| May 28 | OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL OpenBaoHighMay 28 | OpenBao | High | 2.5.4 |
| May 28 | MCP Toolbox for Databases vulnerable to DNS rebinding attacks mcp-toolboxCriticalMay 28 | mcp-toolbox | Critical | 1.2.0 |
| May 28 | Google: remote code execution GoogleCritical9.8May 28 | Google | Critical9.8 | 0.23.0 |
| May 27 | Gradio contains a cookie injection vulnerability GradioHigh6.8May 27 | Gradio | High6.8 | 6.15.0 |
| May 26 | vllm has Improper Resource Shutdown or Release vLLMMedium5.3May 26 | vLLM | Medium5.3 | No fix yet |
| May 26 | Apache ECharts has a cross-site scripting (XSS) vulnerability echartsMedium6.1May 26 | echarts | Medium6.1 | 6.1.0 |
| May 26 | MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled MLflowCritical9.0May 26 | MLflow | Critical9.0 | 3.11.0rc1 |
| May 26 | HuggingFace transformers vulnerable to remote code execution TransformersHigh7.8May 26 | Transformers | High7.8 | 5.3.0 |
| May 26 | hermes-agent has an Incorrect Comparison hermes-agentLow5.3May 26 | hermes-agent | Low5.3 | 0.15.0 |
| May 26 | hermes-agent has a sandbox issue hermes-agentMedium7.3May 26 | hermes-agent | Medium7.3 | 0.11.0 |
| May 26 | hermes-agent has an Injection issue hermes-agentMedium7.3May 26 | hermes-agent | Medium7.3 | 0.15.0 |
| May 26 | hermes-agent has an Injection issue hermes-agentMedium7.3May 26 | hermes-agent | Medium7.3 | 0.15.0 |
| May 26 | Prefect has an Argument Injection issue PrefectHigh8.5May 26 | Prefect | High8.5 | No fix yet |
| May 22 | Tool Execution Without Authorization via Piped Stdin in Kiro CLI AWSUnratedMay 22 | AWS | Unrated | No fix yet |
| May 21 | Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580) pydantic-aiMedium6.8May 21 | pydantic-ai | Medium6.8 | 1.99.0 |
| May 21 | LiteLLM allows a user to modify their own user_role via the /user/update endpoint LiteLLMHigh8.8May 21 | LiteLLM | High8.8 | 1.83.10 |
| May 21 | LiteLLM: privilege escalation LiteLLMHigh8.8May 21 | LiteLLM | High8.8 | 1.83.14 |
| May 21 | lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out LMDeployHigh7.8May 21 | LMDeploy | High7.8 | 0.13.0 |
| May 21 | LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization LMDeployHigh7.8May 21 | LMDeploy | High7.8 | 0.13.0 |
| May 21 | MLflow: information disclosure MLflowMedium6.5May 21 | MLflow | Medium6.5 | 3.10.0 |
| May 21 | Cursor Desktop sandbox escape via Claude hook configuration CursorHigh8.5May 21 | Cursor | High8.5 | 3.0.0 |
| May 21 | HTTP/2-to-HTTP/1 Request Smuggling via unvalidated :path pseudo-header in HTTP2ToHTTP1Codec AppleLowMay 21 | Apple | Low | 1.44.0 |
| May 21 | NIOHTTPRequestDecompressor ratio limit bypass via inflated Content-Length AppleMediumMay 21 | Apple | Medium | 1.34.1 |
| May 21 | NIOHTTP1 HTTPDecoder accepts unbounded HTTP/1 header blocks, enabling remote DoS AppleMediumMay 21 | Apple | Medium | 2.100.0 |
| May 21 | Out-of-bounds write via ByteBuffer index and length UInt32 overflow AppleHighMay 21 | Apple | High | 2.100.0 |
| May 21 | CRLF Injection in outbound HTTP request URI via NIOHTTPRequestHeadersValidator AppleMediumMay 21 | Apple | Medium | 2.100.0 |
| May 20 | Flowise: Cross-Workspace Chatflow Disclosure via chatflows/apikey Endpoint Returns All Unprotected Chatflows FlowiseMedium7.7May 20 | Flowise | Medium7.7 | 3.1.2 |
| May 20 | Flowise: mass assignment FlowiseMediumMay 20 | Flowise | Medium | 3.1.2 |
| May 20 | Flowise: Hardcoded CORS wildcard on TTS endpoint enables cross-origin credential abuse from any webpage FlowiseMediumMay 20 | Flowise | Medium | 3.1.2 |
| May 20 | OpenTofu: Excessive resource usage in "tofu init" when installing dependencies from attacker-controlled server OpenTofuLow3.1May 20 | OpenTofu | Low3.1 | 1.11.8 |
| May 20 | Diffusers: TOCTOU Trust Remote Code Bypass diffusersHigh7.5May 20 | diffusers | High7.5 | 0.38.0 |
| May 20 | Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration AnthropicMedium5.3May 20 | Anthropic | Medium5.3 | 1.0.74 |
| May 20 | Arbitrary file read in rabbitmq-aws plugin AWSUnratedMay 20 | AWS | Unrated | No fix yet |
| May 19 | SillyTavern: SSRF in SearXNG Search Proxy via Unvalidated baseUrl SillyTavernHigh8.5May 19 | SillyTavern | High8.5 | 1.18.0 |
| May 19 | n8n: Credential exfiltration via Allowed HTTP Request Domains Bypass n8nMedium9.1May 19 | n8n | Medium9.1 | 2.20.0 |
| May 19 | n8n: Legacy ExecuteWorkflow Node Bypassed File Path Restrictions n8nMedium6.4May 19 | n8n | Medium6.4 | 2.19.3 |
| May 19 | MLflow: origin validation error MLflowCritical9.6May 19 | MLflow | Critical9.6 | 3.10.0 |
| May 18 | MLFlow Creates a Temporary File With Insecure Permissions MLflowHigh7.0May 18 | MLflow | High7.0 | 3.11.0 |
| May 18 | ChromaDB Python project has a pre-authentication code injection vulnerability ChromaCriticalMay 18 | Chroma | Critical | No fix yet |
| May 18 | SGLang: Unauthenticated RCE via --enable-custom-logit-processor SGLangCritical9.8May 18 | SGLang | Critical9.8 | No fix yet |
| May 18 | SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket SGLangCritical9.8May 18 | SGLang | Critical9.8 | No fix yet |
| May 18 | SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability SGLangCritical9.1May 18 | SGLang | Critical9.1 | No fix yet |
| May 18 | Remote Code Execution in amazon-redshift-python-driver AWSUnratedMay 18 | AWS | Unrated | No fix yet |
| May 15 | MLflow: unauthenticated access to certain FastAPI routes MLflowHigh8.6May 15 | MLflow | High8.6 | 3.11.0 |
| May 14 | Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts Open WebUIHigh8.1May 14 | Open WebUI | High8.1 | 0.9.0 |
| May 14 | Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` , feature gate bypassed Open WebUIHigh8.8May 14 | Open WebUI | High8.8 | 0.8.12 |
| May 14 | Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion Open WebUIHigh8.0May 14 | Open WebUI | High8.0 | 0.9.0 |
| May 14 | Open WebUI: Unauthenticated endpoint can trigger embedding generation (cost/DoS) Open WebUIMedium6.5May 14 | Open WebUI | Medium6.5 | 0.8.0 |
| May 14 | Open WebUI has an Indirect Object Reference (IDOR) in user notes Open WebUIMedium6.5May 14 | Open WebUI | Medium6.5 | 0.8.11 |
| May 14 | Open WebUI: insecure direct object reference Open WebUIHigh8.1May 14 | Open WebUI | High8.1 | 0.9.5 |
| May 14 | Open WebUI vulnerable to stored XSS via OAuth picture claim stored as SVG data URI in profile_image_url Open WebUIHigh7.3May 14 | Open WebUI | High7.3 | 0.9.5 |
| May 14 | Open WebUI: server-side request forgery Open WebUIHigh8.5May 14 | Open WebUI | High8.5 | 0.9.5 |
| May 14 | Open WebUI has a Server-Side Request Forgery (SSRF) bypass in `validate_url` Open WebUIHigh8.5May 14 | Open WebUI | High8.5 | 0.9.5 |
| May 14 | Open WebUI: missing authorization Open WebUIHigh7.1May 14 | Open WebUI | High7.1 | 0.9.0 |
| May 14 | Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base Access Controls Open WebUIHigh7.5May 14 | Open WebUI | High7.5 | 0.9.5 |
| May 14 | Open WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure Open WebUIMedium5.3May 14 | Open WebUI | Medium5.3 | 0.9.5 |
| May 14 | Open WebUI: spoofing Open WebUIMedium5.4May 14 | Open WebUI | Medium5.4 | 0.9.5 |