CVE MEDIUM CVE-2025-67743

Local Deep Research is Vulnerable to Server-Side Request Forgery (SSRF) in Download Service

CVSS 6.3 local-deep-research View details

SearXNG MCP Server: DNS-resolved Private Hostname SSRF in `web_url_read

CVSS 7.1 mcp-searxng View details

Atlassian: DNS-rebinding TOCTOU bypass of the SSRF

CVSS 6.5 mcp-atlassian View details

Open WebUI Vulnerable to SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py

CVSS 7.7 open-webui View details

Flowise: SSRF Protection Bypass via Unprotected Built-in HTTP Modules in Custom Function Sandbox

CVSS 7.1 flowise-components View details

Atlassian has SSRF via unvalidated X-Atlassian-Jira-Url / X-Atlassian-Confluence-Url headers

CVSS 8.2 mcp-atlassian View details

Budibase: SSRF via DNS rebinding in the REST datasource integration

CVSS 8.5 @budibase/server View details

Flowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Failure

flowise-components View details

auth-fetch-mcp has SSRF Protection Bypass via IPv4-mapped IPv6 Loopback

CVSS 7.4 auth-fetch-mcp View details

PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding

CVSS 7.2 praisonai View details

PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter

CVSS 8.8 praisonaiagents View details

praisonaiagents: SSRF guard validates literal IPs only and never resolves

CVSS 8.5 praisonaiagents View details

Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling

CVSS 8.5 open-webui View details

auth-fetch-mcp: SSRF and disk exfiltration via unvalidated auth_fetch and download_media URLs

CVSS 8.2 auth-fetch-mcp View details

DeepSeek TUI has SSRF via HTTP Redirect Bypass in fetch_url Tool

CVSS 7.4 deepseek-tui View details

customized large language model flow. Prior to 3.1.0, a Server-Side Request Forgery (SSRF) protection bypass vulnerability exists in the Custom Function feature. While the application implements SSRF protection

CVSS 8.3 flowise View details

Flowise: APIChain Prompt Injection SSRF in GET/POST API Chains

CVSS 7.1 flowise-components View details

Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) protection bypass vulnerability in the API Request component. An authenticated attacker with low-level privileges (flow author role

CVSS 8.5 langflow View details

budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation

CVSS 8.5 @budibase/backend-core View details

PraisonAI: SpiderTools redirect-target SSRF protection bypass

CVSS 6.5 praisonaiagents View details
Page 1 of 9 Next