CVE MEDIUM CVE-2026-40115

PraisonAI has Unrestricted Upload Size in WSGI Recipe Registry Server

CVSS 6.2 PraisonAI View details
CVE MEDIUM CVE-2026-34753

vLLM: Server-Side Request Forgery (SSRF) in `download_bytes_from

CVSS 5.4 vllm View details
CVE MEDIUM CVE-2026-33682

prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code

CVSS 4.7 Streamlit View details
CVE MEDIUM CVE-2026-33401

Prior to version 4.7.0, the patch introduced in commit e8a513591 (CVE-2026-30840) added SSRF protection to notification test endpoints but left three additional attack surfaces unprotected: the AI Ollama

CVE MEDIUM CVE-2026-32041

allowing browser-control routes to remain accessible without authentication. Local processes or loopback-reachable SSRF paths can exploit this to access browser-control routes including evaluate-capable actions without valid

CVSS 6.9 OpenClaw View details
CVE MEDIUM CVE-2026-32037

supply or influence attachment URLs to force redirects to non-allowlisted targets, bypassing SSRF boundary controls

CVSS 6.0 OpenClaw View details
CVE MEDIUM CVE-2024-48052

gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_url_to_cache function, there are no restrictions

CVSS 6.5 gradio View details
CVE MEDIUM CVE-2024-4940

exploited for phishing attacks, Cross-site Scripting (XSS), Server-Side Request Forgery (SSRF), amongst others. This issue is due to improper validation of user-supplied input in the handling

CVSS 6.1 gradio View details
CVE MEDIUM CVE-2024-2206

SSRF vulnerability exists in the gradio-app/gradio due to insufficient validation of user-supplied URLs in the `/proxy` route. Attackers can exploit this vulnerability by manipulating the `self.replica_urls

CVSS 6.5 gradio View details
CVE MEDIUM CVE-2026-54020

Open WebUI: DNS Rebinding SSRF Bypass

CVSS 6.3 open-webui View details
CVE MEDIUM CVE-2026-34225

Open WebUI has Blind Server Side Request Forgery in its

CVSS 4.3 open-webui View details

OpenClaw: Browser debug/export routes could reuse already-open blocked tabs

CVSS 6.5 openclaw View details
CVE MEDIUM CVE-2026-54009

Open WebUI: Cross-user file disclosure via /api/chat/completions image_url

CVSS 6.5 open-webui View details
CVE MEDIUM CVE-2026-48148

Budibase: Unvalidated VectorDB Host Parameter Enables SSRF

@budibase/server View details

OpenClaw: Agent gateway config mutations could change protected operator settings

OpenClaw: CDP /json/version WebSocket URL could pivot to untrusted second

OpenClaw: Browser press/type interaction routes missed complete navigation guard coverage

CVE MEDIUM CVE-2026-6011

OpenClaw vulnerable to SSRF in src/agents/tools/web-fetch.ts

CVSS 5.6 openclaw View details

TaskWeaver has Protection Mechanism Failure and Server-Side Request Forgery (SSRF

CVSS 6.5 agentos-taskweaver View details
CVE MEDIUM CVE-2025-68477

Langflow is a tool for building and deploying AI-powered

CVSS 6.5 langflow View details
Previous Page 3 of 4 Next