Local Deep Research is Vulnerable to Server-Side Request Forgery (SSRF) in Download Service
SearXNG MCP Server: DNS-resolved Private Hostname SSRF in `web_url_read
Open WebUI Vulnerable to SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py
Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox
Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers
PraisonAI spider_tools SSRF protection bypass via alternate loopback host encodings
Flowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Failure
PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding
PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter
praisonaiagents: SSRF guard validates literal IPs only and never resolves
Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling
auth-fetch-mcp: SSRF and disk exfiltration via unvalidated auth_fetch and download_media URLs
DeepSeek TUI has SSRF via HTTP Redirect Bypass in fetch_url Tool
customized large language model flow. Prior to 3.1.0, a Server-Side Request Forgery (SSRF) protection bypass vulnerability exists in the Custom Function feature. While the application implements SSRF protection
Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains
budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation
PraisonAI: SpiderTools redirect-target SSRF protection bypass
Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversal
Budibase: SSRF via OAuth2 Config Validation — Missing fetchWithBlacklist Protection
local-deep-research is Vulnerable to HTML Injection via Unescaped