PraisonAI has an SSRF bypass

praisonaiagents View details

LangChain Text Splitters: HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect Bypass

CVSS 6.5 langchain-text-splitters View details
CVE MEDIUM CVE-2026-35673

OpenClaw before 2026.4.29 contains an SSRF policy bypass vulnerability in browser debug and export routes that allows reuse of already-open blocked tabs. Attackers with access to these routes

CVSS 6.5 openclaw View details
CVE MEDIUM CVE-2026-46526

local-deep-research has an SSRF bypass in `safe

CVSS 5.0 local-deep-research View details

Budibase: SSRF in AI Extract File Automation Step via Missing IP Blacklist Validation

CVSS 7.7 @budibase/server View details

Open WebUI has a Server-Side Request Forgery (SSRF) bypass in `validate

CVSS 8.5 open-webui View details
CVE MEDIUM CVE-2026-45347

Open WebUI vulnerable to blind server side request forgery (SSRF) via the PDF generate function

CVSS 4.3 open-webui View details

OpenClaw validates Zalo outbound photo URLs through the SSRF guard

OpenClaw: Browser tabs action select and close routes bypassed SSRF policy

OpenClaw: Browser SSRF policy default allowed private-network navigation

OpenClaw: QQBot reply media URL handling could trigger SSRF and re-upload fetched bytes

langchain-openai: Image token counting SSRF protection can be bypassed via DNS rebinding

CVSS 3.1 langchain-openai View details

OpenClaw: SSRF via Unguarded `fetch()` in Marketplace Plugin Download and Ollama Model Discovery

CVE CRITICAL CVE-2026-25960

vLLM is an inference and serving engine for large language models (LLMs). The SSRF protection fix for CVE-2026-24779 add in 0.15.1 can be bypassed in the load_from

CVSS 9.8 vllm View details

powered applications. Prior to version 1.1.8, a redirect-based Server-Side Request Forgery (SSRF) bypass exists in `RecursiveUrlLoader` in `@langchain/community`. The loader validates the initial URL but allows the underlying

Open WebUI vulnerable to Server-Side Request Forgery (SSRF) via Arbitrary URL Processing in /api/v1/retrieval/process/web

CVSS 8.5 open-webui View details
CVE MEDIUM CVE-2025-12058

mode=True, is vulnerable to arbitrary local file loading and Server-Side Request Forgery (SSRF). This vulnerability stems from the way the StringLookup layer is handled during model loading from

source, AI chat framework. Versions of lobe-chat prior to 1.19.13 have an unauthorized ssrf vulnerability. An attacker can construct malicious requests to cause SSRF without logging in, attack intranet

CVSS 8.6 lobe_chat View details
CVE MEDIUM CVE-2026-55414

Unauthenticated form resolver forwards the privileged Objecten-API token to a caller-supplied URL (SSRF

CVSS 5.3 nl.nl-portal:form View details

IPv4-mapped IPv6 addresses bypass SSRF protection in validateUrlSync(), enabling full SSRF for SDK embedders

CVSS 8.5 n8n-mcp View details
Previous Page 2 of 7 Next