PraisonAI has Unrestricted Upload Size in WSGI Recipe Registry Server
vLLM: Server-Side Request Forgery (SSRF) in `download_bytes_from
prior to 1.54.0 running on Windows hosts have an unauthenticated Server-Side Request Forgery (SSRF) vulnerability. The vulnerability arises from improper validation of attacker-supplied filesystem paths. In certain code
Prior to version 4.7.0, the patch introduced in commit e8a513591 (CVE-2026-30840) added SSRF protection to notification test endpoints but left three additional attack surfaces unprotected: the AI Ollama
allowing browser-control routes to remain accessible without authentication. Local processes or loopback-reachable SSRF paths can exploit this to access browser-control routes including evaluate-capable actions without valid
supply or influence attachment URLs to force redirects to non-allowlisted targets, bypassing SSRF boundary controls
gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_url_to_cache function, there are no restrictions
exploited for phishing attacks, Cross-site Scripting (XSS), Server-Side Request Forgery (SSRF), amongst others. This issue is due to improper validation of user-supplied input in the handling
SSRF vulnerability exists in the gradio-app/gradio due to insufficient validation of user-supplied URLs in the `/proxy` route. Attackers can exploit this vulnerability by manipulating the `self.replica_urls
Open WebUI has Blind Server Side Request Forgery in its
OpenClaw: Browser debug/export routes could reuse already-open blocked tabs
Open WebUI: Cross-user file disclosure via /api/chat/completions image_url
OpenClaw: Agent gateway config mutations could change protected operator settings
OpenClaw: Browser press/type interaction routes missed complete navigation guard coverage
OpenClaw vulnerable to SSRF in src/agents/tools/web-fetch.ts
TaskWeaver has Protection Mechanism Failure and Server-Side Request Forgery (SSRF
Langflow is a tool for building and deploying AI-powered