| Jun 29 | MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints mcp-toolboxCritical9.1Jun 29 | mcp-toolbox | Critical9.1 | 1.3.0 |
| Jun 26 | pydantic-ai: server-side request forgery pydantic-aiMedium6.8Jun 26 | pydantic-ai | Medium6.8 | 1.102.0+1 more |
| Jun 25 | Argo has Missing Authorization in its Sync ConfigMap Provider in github.com/argoproj/argo-workflows argo-workflowsHigh8.3Jun 25 | argo-workflows | High8.3 | No fix yet |
| Jun 25 | Argo Affected by SSO RBAC Delegation Nil Pointer Dereference DoS argo-workflowsMedium6.5Jun 25 | argo-workflows | Medium6.5 | No fix yet |
| Jun 25 | Argo Vulnerable to Unauthenticated Memory Exhaustion argo-workflowsHigh7.5Jun 25 | argo-workflows | High7.5 | No fix yet |
| Jun 25 | GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusion github-mcp-serverMedium6.0Jun 25 | github-mcp-server | Medium6.0 | 1.1.2 |
| Jun 25 | Argo vulnerable to exposure of artifact repository credentials in github.com/argoproj/argo-workflows argo-workflowsMedium4.9Jun 25 | argo-workflows | Medium4.9 | No fix yet |
| Jun 25 | Argo has incomplete fix for CVE-2026-31892 argo-workflowsHigh8.1Jun 25 | argo-workflows | High8.1 | No fix yet |
| Jun 25 | Grafana Loki Path Traversal - CVE-2021-36156 Bypass in github.com/grafana/loki LokiMedium5.3Jun 25 | Loki | Medium5.3 | No fix yet |
| Jun 25 | Argo Workflows: Unchecked annotation parsing in pod informer crashes Argo... argo-workflowsUnratedJun 25 | argo-workflows | Unrated | No fix yet |
| Jun 25 | Insecure Temporary File in /copy Command Enables Response Disclosure and Symlink-Based File Write AnthropicMedium4.4Jun 25 | Anthropic | Medium4.4 | 2.1.128 |
| Jun 25 | Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution AnthropicHigh7.7Jun 25 | Anthropic | High7.7 | 2.1.163 |
| Jun 23 | ## Summary If a symlink already exists under the `.terraform/providers`... OpenTofuMedium6.1Jun 23 | OpenTofu | Medium6.1 | 1.10.10+1 more |
| Jun 22 | vLLM: code execution vLLMHigh8.8Jun 22 | vLLM | High8.8 | 0.22.1 |
| Jun 22 | Chainlit contains a session hijacking vulnerability chainlitCritical7.4Jun 22 | chainlit | Critical7.4 | 2.10.1 |
| Jun 22 | Keras: DiskIOStore permits path traversal through crafted layer names KerasMedium6.1Jun 22 | Keras | Medium6.1 | 3.12.3+1 more |
| Jun 22 | Unbounded W3C tracestate parsing may lead to DoS DatadogHigh7.5Jun 22 | Datadog | High7.5 | 0.3.3 |
| Jun 21 | BerriAI litellm has SSRF via Unvalidated spec_path URL in MCP OpenAPI Spec Loader LiteLLMLow6.3Jun 21 | LiteLLM | Low6.3 | No fix yet |
| Jun 21 | BerriAI litellm: UI User Enumeration leads to System-Wide Information Disclosure LiteLLMLow4.3Jun 21 | LiteLLM | Low4.3 | No fix yet |
| Jun 21 | LiteLLM: improper authorization LiteLLMLow6.3Jun 21 | LiteLLM | Low6.3 | No fix yet |
| Jun 21 | BerriAI litellm: SSO Login Does Not Invalidate Previous UI Session Tokens LiteLLMLow6.3Jun 21 | LiteLLM | Low6.3 | No fix yet |
| Jun 21 | LiteLLM: SSO Debug Flow Has Improper Authentication LiteLLMMedium7.3Jun 21 | LiteLLM | Medium7.3 | No fix yet |
| Jun 21 | LiteLLM: MCP Proxy Has Improper Authentication LiteLLMMedium7.3Jun 21 | LiteLLM | Medium7.3 | 1.84.0 |
| Jun 21 | LiteLLM: Admin Key Handler Has Improper Authorization LiteLLMLow5.4Jun 21 | LiteLLM | Low5.4 | No fix yet |
| Jun 21 | LiteLLM: PROXY_ADMIN database API Key Generator Has Insufficient Session Expiration LiteLLMLow6.3Jun 21 | LiteLLM | Low6.3 | No fix yet |
| Jun 21 | LiteLLM: M2M JWT Handler Has Improper Authorization LiteLLMLow5.0Jun 21 | LiteLLM | Low5.0 | No fix yet |
| Jun 19 | SurrealDB: Denial of Service via deep operator chains SurrealDBMedium6.5Jun 19 | SurrealDB | Medium6.5 | 3.1.5 |
| Jun 19 | SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals SurrealDBMedium4.3Jun 19 | SurrealDB | Medium4.3 | 3.1.5 |
| Jun 19 | SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field SurrealDBMedium4.3Jun 19 | SurrealDB | Medium4.3 | 3.1.5 |
| Jun 19 | SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter SurrealDBHigh7.7Jun 19 | SurrealDB | High7.7 | 3.1.5 |
| Jun 19 | SurrealDB: SSRF via JWKS URL , Redirect Following in JWT Key Fetch SurrealDBMedium4.1Jun 19 | SurrealDB | Medium4.1 | 3.1.5 |
| Jun 19 | OpenBao: Transit secrets engine crashes on key creation with `derived: true` for asymmetric key types OpenBaoMedium6.5Jun 19 | OpenBao | Medium6.5 | 0.0.0-20260617104123-db57c62602b2 |
| Jun 19 | OpenBao's System Backend allows Unauthorized Management of the containing Namespace OpenBaoLowJun 19 | OpenBao | Low | 0.0.0-20260617103935-d3c1cc64b1ae |
| Jun 19 | OpenBao: improper authorization OpenBaoLowJun 19 | OpenBao | Low | 0.0.0-20260617103932-b20b999dd404 |
| Jun 19 | OpenBao: LDAPi ldaputil (wrong escape func) OpenBaoMedium6.8Jun 19 | OpenBao | Medium6.8 | 0.0.0-20260617104213-10b7825c714c |
| Jun 19 | Grafana Tempo vulnerable to an out-of-memory crash TempoMedium6.5Jun 19 | Tempo | Medium6.5 | 1.5.1-0.20260303204923-b13f74291d48 |
| Jun 19 | Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit LangflowCritical9.6Jun 19 | Langflow | Critical9.6 | 1.9.2 |
| Jun 19 | Langflow: Unauthenticated DoS through multipart form boundary file upload LangflowHigh7.5Jun 19 | Langflow | High7.5 | 1.0.19 |
| Jun 19 | Langflow: Logout button does not clear session LangflowMedium6.1Jun 19 | Langflow | Medium6.1 | 1.7.0 |
| Jun 19 | Langflow: insecure direct object reference LangflowHigh8.4Jun 19 | Langflow | High8.4 | 1.9.1 |
| Jun 19 | OpenTofu: Possible arbitrary file read during certain git operations via a maliciously crafted URL OpenTofuHigh7.5Jun 19 | OpenTofu | High7.5 | 1.11.10+1 more |
| Jun 19 | JupyterLab: Stored XSS in extension manager through package metadata unsanitized URI protocol JupyterMediumJun 19 | Jupyter | Medium | 4.5.9 |
| Jun 19 | Use-after-free in connection ID iterator FFI functions CloudflareMedium5.6Jun 19 | Cloudflare | Medium5.6 | 0.29.2 |
| Jun 18 | MCP Toolbox for Databases: authenticated authorization bypass mcp-toolboxHighJun 18 | mcp-toolbox | High | 1.4.0 |
| Jun 18 | mcp-toolbox: authentication bypass mcp-toolboxCriticalJun 18 | mcp-toolbox | Critical | 1.4.0 |
| Jun 18 | mcp-toolbox: authentication bypass mcp-toolboxCriticalJun 18 | mcp-toolbox | Critical | 1.4.0 |
| Jun 18 | Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP JupyterCritical5.4Jun 18 | Jupyter | Critical5.4 | 2.20.0 |
| Jun 17 | hermes-agent: missing authentication hermes-agentHigh7.5Jun 17 | hermes-agent | High7.5 | 0.16.0 |
| Jun 17 | hermes-agent: insecure default permissions hermes-agentMedium5.5Jun 17 | hermes-agent | Medium5.5 | 0.16.0 |
| Jun 17 | Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak LangflowCritical9.3Jun 17 | Langflow | Critical9.3 | 1.9.1 |
| Jun 17 | Open WebUI: Any authenticated user can read other users' private notes via Socket.IO Open WebUIMedium5.3Jun 17 | Open WebUI | Medium5.3 | 0.8.11 |
| Jun 17 | Open WebUI: improper access control Open WebUIMedium6.3Jun 17 | Open WebUI | Medium6.3 | 0.9.6 |
| Jun 17 | Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode Open WebUIMedium6.5Jun 17 | Open WebUI | Medium6.5 | 0.9.6 |
| Jun 17 | Open WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP Redirects Open WebUIHigh7.7Jun 17 | Open WebUI | High7.7 | 0.9.6 |
| Jun 17 | Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversal Open WebUIHigh7.7Jun 17 | Open WebUI | High7.7 | 0.9.6 |
| Jun 17 | Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration Open WebUIMedium4.3Jun 17 | Open WebUI | Medium4.3 | 0.9.6 |
| Jun 17 | Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion Open WebUIMedium6.4Jun 17 | Open WebUI | Medium6.4 | 0.9.6 |
| Jun 17 | Open WebUI: Sibling-Prefix Path Traversal via /cache/{path} Open WebUIMedium4.3Jun 17 | Open WebUI | Medium4.3 | 0.9.6 |
| Jun 17 | Open WebUI: Stored XSS to Account Takeover via Model Profile Images Open WebUIHigh7.6Jun 17 | Open WebUI | High7.6 | 0.9.6 |
| Jun 17 | Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion Open WebUIHigh7.1Jun 17 | Open WebUI | High7.1 | 0.9.6 |