Skip to content

All advisories

14,463 advisories for 277 projects, newest first

60 of 197 advisories

Advisory
agno contains a SQL injection vulnerability
agnoHigh8.3May 29
OpenBao's Kerberos Auth Method Accumulates Unaccessible Tokens
OpenBaoMedium5.3May 28
OpenBao's Inline Auth Incorrectly Redacted Headers
OpenBaoMediumMay 28
OpenBao's cross-namespace lease revocation via legacy sys/revoke path bypasses ACL
OpenBaoHighMay 28
MCP Toolbox for Databases vulnerable to DNS rebinding attacks
mcp-toolboxCriticalMay 28
Google: remote code execution
GoogleCritical9.8May 28
Gradio contains a cookie injection vulnerability
GradioHigh6.8May 27
vllm has Improper Resource Shutdown or Release
vLLMMedium5.3May 26
Apache ECharts has a cross-site scripting (XSS) vulnerability
echartsMedium6.1May 26
MLflow allows unauthorized access to multipart upload endpoints when the `--serve-artifacts` mode is enabled
MLflowCritical9.0May 26
HuggingFace transformers vulnerable to remote code execution
TransformersHigh7.8May 26
hermes-agent has an Incorrect Comparison
hermes-agentLow5.3May 26
hermes-agent has a sandbox issue
hermes-agentMedium7.3May 26
hermes-agent has an Injection issue
hermes-agentMedium7.3May 26
hermes-agent has an Injection issue
hermes-agentMedium7.3May 26
Prefect has an Argument Injection issue
PrefectHigh8.5May 26
Tool Execution Without Authorization via Piped Stdin in Kiro CLI
AWSUnratedMay 22
Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)
pydantic-aiMedium6.8May 21
LiteLLM allows a user to modify their own user_role via the /user/update endpoint
LiteLLMHigh8.8May 21
LiteLLM: privilege escalation
LiteLLMHigh8.8May 21
lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out
LMDeployHigh7.8May 21
LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization
LMDeployHigh7.8May 21
MLflow: information disclosure
MLflowMedium6.5May 21
Cursor Desktop sandbox escape via Claude hook configuration
CursorHigh8.5May 21
HTTP/2-to-HTTP/1 Request Smuggling via unvalidated :path pseudo-header in HTTP2ToHTTP1Codec
AppleLowMay 21
NIOHTTPRequestDecompressor ratio limit bypass via inflated Content-Length
AppleMediumMay 21
NIOHTTP1 HTTPDecoder accepts unbounded HTTP/1 header blocks, enabling remote DoS
AppleMediumMay 21
Out-of-bounds write via ByteBuffer index and length UInt32 overflow
AppleHighMay 21
CRLF Injection in outbound HTTP request URI via NIOHTTPRequestHeadersValidator
AppleMediumMay 21
Flowise: Cross-Workspace Chatflow Disclosure via chatflows/apikey Endpoint Returns All Unprotected Chatflows
FlowiseMedium7.7May 20
Flowise: mass assignment
FlowiseMediumMay 20
Flowise: Hardcoded CORS wildcard on TTS endpoint enables cross-origin credential abuse from any webpage
FlowiseMediumMay 20
OpenTofu: Excessive resource usage in "tofu init" when installing dependencies from attacker-controlled server
OpenTofuLow3.1May 20
Diffusers: TOCTOU Trust Remote Code Bypass
diffusersHigh7.5May 20
Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration
AnthropicMedium5.3May 20
Arbitrary file read in rabbitmq-aws plugin
AWSUnratedMay 20
SillyTavern: SSRF in SearXNG Search Proxy via Unvalidated baseUrl
SillyTavernHigh8.5May 19
n8n: Credential exfiltration via Allowed HTTP Request Domains Bypass
n8nMedium9.1May 19
n8n: Legacy ExecuteWorkflow Node Bypassed File Path Restrictions
n8nMedium6.4May 19
MLflow: origin validation error
MLflowCritical9.6May 19
MLFlow Creates a Temporary File With Insecure Permissions
MLflowHigh7.0May 18
ChromaDB Python project has a pre-authentication code injection vulnerability
ChromaCriticalMay 18
SGLang: Unauthenticated RCE via --enable-custom-logit-processor
SGLangCritical9.8May 18
SGLanG: Multimodal scheduler deserializes untrusted pickle data on 0.0.0.0 ROUTER socket
SGLangCritical9.8May 18
SGLang's multimodal generation runtime has an unauthenticated path traversal vulnerability
SGLangCritical9.1May 18
Remote Code Execution in amazon-redshift-python-driver
AWSUnratedMay 18
MLflow: unauthenticated access to certain FastAPI routes
MLflowHigh8.6May 15
Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts
Open WebUIHigh8.1May 14
Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` , feature gate bypassed
Open WebUIHigh8.8May 14
Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion
Open WebUIHigh8.0May 14
Open WebUI: Unauthenticated endpoint can trigger embedding generation (cost/DoS)
Open WebUIMedium6.5May 14
Open WebUI has an Indirect Object Reference (IDOR) in user notes
Open WebUIMedium6.5May 14
Open WebUI: insecure direct object reference
Open WebUIHigh8.1May 14
Open WebUI vulnerable to stored XSS via OAuth picture claim stored as SVG data URI in profile_image_url
Open WebUIHigh7.3May 14
Open WebUI: server-side request forgery
Open WebUIHigh8.5May 14
Open WebUI has a Server-Side Request Forgery (SSRF) bypass in `validate_url`
Open WebUIHigh8.5May 14
Open WebUI: missing authorization
Open WebUIHigh7.1May 14
Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base Access Controls
Open WebUIHigh7.5May 14
Open WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure
Open WebUIMedium5.3May 14
Open WebUI: spoofing
Open WebUIMedium5.4May 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.