Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Malicious code in random-ua-generator (PyPI)
Malicious code in blessclient (PyPI)
CVE-2026-16796
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
CVE-2026-73568
libp2p: yamux connection DoS via oversized data frame
CVE-2026-16584
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
Malicious code in trongridy (PyPI)
CVE-2026-73652
vantage6: Algorithm developer can edit another developer's algorithm that is pending / under review
GitPython: Environment-variable exfiltration via Repo.create_remote() / Remote.add() URL (incomplete fix of GHSA-rwj8-pgh3-r573)
CVE-2026-59221
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
CVE-2026-59225
Open WebUI: Arena task endpoints can bypass underlying model access controls
CVE-2026-59212
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
CVE-2026-59224
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query...
CVE-2026-59223
Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
CVE-2026-55404
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
Malicious code in discordnv (PyPI)
CVE-2026-59222
Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
CVE-2026-59215
Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding
CVE-2026-59213
Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
CVE-2026-59217
Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
CVE-2026-59216
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
Showing 1 - 20 of 1,000+ results