Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader
Flyto2 Core is an execution kernel for automation and AI
Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
Open WebUI has Blind Server Side Request Forgery in its
OpenClaw: Browser debug/export routes could reuse already-open blocked tabs
PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of
Open WebUI: Cross-user file disclosure via /api/chat/completions image_url
Open WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed
OpenClaw: Agent gateway config mutations could change protected operator settings
OpenClaw: Browser press/type interaction routes missed complete navigation guard coverage
PraisonAI: Unauthenticated Allow-List Manipulation Bypasses Agent Tool Approval Safety
OpenClaw vulnerable to SSRF in src/agents/tools/web-fetch.ts
PraisonAI Has SSRF in FileTools.download_file() via Unvalidated
PraisonAI: SSRF via Unvalidated api_base in passthrough() Fallback
TaskWeaver has Protection Mechanism Failure and Server-Side Request Forgery (SSRF