Flowise: Parameter Override Bypass Remote Command Execution
files, which leads to a server side template injection vulnerability within langchaingo, allowing an attacker to insert a statement into a prompt to read the "etc/passwd" file
Open WebUI: Cross-user file disclosure via /api/chat/completions image_url
vLLM Vulnerable to Remote DoS via Special-Token Placeholders
@rtk-ai/rtk-rewrite transparently rewrites shell commands executed via OpenClaw
nnU-Net is a semantic segmentation framework that automatically adapts
Open WebUI Affected by an External Model Server (Direct Connections
PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass
npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining
Mistune Image Directive CSS Injection Vulnerability
npm PraisonAI utility shell safe-command wrapper allowlist bypass via
praisonai-platform: Comment endpoints accept any issue_id without workspace
PraisonAI: HTTPApproval dashboard renders tool arguments as raw HTML, allowing
Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data
praisonai-platform: IDOR in dependency endpoints allows cross-workspace issue
Open WebUI's Insecure Message Access Breaks Authorization