CVE MEDIUM CVE-2025-67743

Local Deep Research is Vulnerable to Server-Side Request Forgery (SSRF) in Download Service

CVSS 6.3 local-deep-research View details
CVE MEDIUM CVE-2026-47390

PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings

CVSS 5.5 PraisonAI View details

Flowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Failure

flowise-components View details

PraisonAI: SpiderTools redirect-target SSRF protection bypass

CVSS 6.5 praisonaiagents View details
CVE MEDIUM CVE-2026-43979

local-deep-research is Vulnerable to HTML Injection via Unescaped

CVSS 5.0 local-deep-research View details

LangChain Text Splitters: HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect Bypass

CVSS 6.5 langchain-text-splitters View details
CVE MEDIUM CVE-2026-35673

OpenClaw before 2026.4.29 contains an SSRF policy bypass vulnerability in browser debug and export routes that allows reuse of already-open blocked tabs. Attackers with access to these routes

CVSS 6.5 openclaw View details
CVE MEDIUM CVE-2026-46526

local-deep-research has an SSRF bypass in `safe

CVSS 5.0 local-deep-research View details
CVE MEDIUM CVE-2026-45347

Open WebUI vulnerable to blind server side request forgery (SSRF) via the PDF generate function

CVSS 4.3 open-webui View details

OpenClaw validates Zalo outbound photo URLs through the SSRF guard

OpenClaw: Browser tabs action select and close routes bypassed SSRF policy

OpenClaw: Browser SSRF policy default allowed private-network navigation

OpenClaw: QQBot reply media URL handling could trigger SSRF and re-upload fetched bytes

OpenClaw: SSRF via Unguarded `fetch()` in Marketplace Plugin Download and Ollama Model Discovery

CVE MEDIUM CVE-2025-12058

mode=True, is vulnerable to arbitrary local file loading and Server-Side Request Forgery (SSRF). This vulnerability stems from the way the StringLookup layer is handled during model loading from

CVE MEDIUM CVE-2026-55414

Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF

CVSS 5.3 nl.nl-portal:form View details

OpenClaw: Existing-session browser interaction routes bypassed SSRF policy enforcement

OpenClaw: Browser SSRF hostname validation could be bypassed by DNS rebinding

OpenClaw: Strict browser SSRF bypass in Playwright redirect handling leaves private targets reachable

OpenClaw has Browser SSRF Policy Bypass via Interaction-Triggered Navigation

Page 1 of 3 Next