Server-Side Request Forgery (SSRF) vulnerability exists in the Web Research Retriever component of langchain-ai/langchain version 0.1.5. The vulnerability arises because the Web Research Retriever does not restrict

CVSS 7.7 langchain View details

Server-Side Request Forgery (SSRF) vulnerability exists in the gradio-app/gradio version 4.21.0, specifically within the `/queue/join` endpoint and the `save_url_to_cache` function. The vulnerability arises when

CVSS 8.6 gradio View details
CVE UNKNOWN CVE-2024-1183

SSRF (Server-Side Request Forgery) vulnerability exists in the gradio-app/gradio repository, allowing attackers to scan and identify open ports within an internal network. By manipulating the 'file' parameter

CVE MEDIUM CVE-2024-2206

SSRF vulnerability exists in the gradio-app/gradio due to insufficient validation of user-supplied URLs in the `/proxy` route. Attackers can exploit this vulnerability by manipulating the `self.replica_urls

CVSS 6.5 gradio View details

attacker to force the service to retrieve data from an arbitrary URL, essentially providing SSRF and potentially injecting content into downstream tasks

CVSS 7.5 langchain View details

LangChain before 0.0.317 allows SSRF via document_loaders/recursive_url_loader.py because crawling can proceed from an external server to an internal server

CVSS 8.8 langchain View details

PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of

CVSS 9.8 praisonai View details
CVE MEDIUM CVE-2026-54009

Open WebUI: Cross-user file disclosure via /api/chat/completions image_url

CVSS 6.5 open-webui View details
CVE MEDIUM CVE-2026-48148

Budibase: Unvalidated VectorDB Host Parameter Enables SSRF

@budibase/server View details
CVE MEDIUM CVE-2026-47395

PraisonAI CLI automatically resolves @url mentions in prompt text and

CVSS 5.5 PraisonAI View details
CVE MEDIUM CVE-2026-46678

Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete

CVSS 6.8 pydantic-ai-slim View details
CVE MEDIUM CVE-2026-46341

Apify Model Context Protocol (MCP) server: Domain Allowlist Bypass in

CVSS 6.1 @apify/actors-mcp-server View details

Open WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed

CVSS 8.5 open-webui View details
CVE UNKNOWN CVE-2026-44694

webhook and API client paths has an authenticated SSRF

OpenClaw: Agent gateway config mutations could change protected operator settings

OpenClaw: CDP /json/version WebSocket URL could pivot to untrusted second

OpenClaw: Browser press/type interaction routes missed complete navigation guard coverage

PraisonAI: Unauthenticated Allow-List Manipulation Bypasses Agent Tool Approval Safety

CVSS 7.9 PraisonAI View details
CVE MEDIUM CVE-2026-6011

OpenClaw vulnerable to SSRF in src/agents/tools/web-fetch.ts

CVSS 5.6 openclaw View details

PraisonAI Has SSRF in FileTools.download_file() via Unvalidated

CVSS 8.6 praisonaiagents View details
Previous Page 6 of 7 Next