Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader

CVSS 7.7 open-webui View details
CVE UNKNOWN CVE-2026-69257

Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses

Flyto2 Core is an execution kernel for automation and AI

CVSS 8.5 flyto-core View details

Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion

CVE MEDIUM CVE-2026-34225

Open WebUI has Blind Server Side Request Forgery in its

CVSS 4.3 open-webui View details

OpenClaw: Browser debug/export routes could reuse already-open blocked tabs

CVSS 6.5 openclaw View details

PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of

CVSS 9.8 praisonai View details
CVE MEDIUM CVE-2026-54009

Open WebUI: Cross-user file disclosure via /api/chat/completions image_url

CVSS 6.5 open-webui View details
CVE MEDIUM CVE-2026-48148

Budibase: Unvalidated VectorDB Host Parameter Enables SSRF

@budibase/server View details

Open WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed

CVSS 8.5 open-webui View details
CVE UNKNOWN CVE-2026-44694

webhook and API client paths has an authenticated SSRF

OpenClaw: Agent gateway config mutations could change protected operator settings

OpenClaw: CDP /json/version WebSocket URL could pivot to untrusted second

OpenClaw: Browser press/type interaction routes missed complete navigation guard coverage

PraisonAI: Unauthenticated Allow-List Manipulation Bypasses Agent Tool Approval Safety

CVSS 7.9 PraisonAI View details
CVE MEDIUM CVE-2026-6011

OpenClaw vulnerable to SSRF in src/agents/tools/web-fetch.ts

CVSS 5.6 openclaw View details

PraisonAI Has SSRF in FileTools.download_file() via Unvalidated

CVSS 8.6 praisonaiagents View details

PraisonAI: SSRF via Unvalidated api_base in passthrough() Fallback

CVSS 7.7 praisonai View details

Fickling has a detection bypass via stdlib network-protocol constructors

TaskWeaver has Protection Mechanism Failure and Server-Side Request Forgery (SSRF

CVSS 6.5 agentos-taskweaver View details
Previous Page 8 of 9 Next