CVE MEDIUM CVE-2025-67743

Local Deep Research is Vulnerable to Server-Side Request Forgery (SSRF) in Download Service

CVSS 6.3 local-deep-research View details

Flowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Failure

flowise-components View details

LangChain Text Splitters: HTMLHeaderTextSplitter.split_text_from_url SSRF Redirect Bypass

CVSS 6.5 langchain-text-splitters View details

OpenClaw validates Zalo outbound photo URLs through the SSRF guard

OpenClaw: Browser tabs action select and close routes bypassed SSRF policy

OpenClaw: Browser SSRF policy default allowed private-network navigation

OpenClaw: QQBot reply media URL handling could trigger SSRF and re-upload fetched bytes

OpenClaw: SSRF via Unguarded `fetch()` in Marketplace Plugin Download and Ollama Model Discovery

CVE MEDIUM CVE-2026-27795

powered applications. Prior to version 1.1.8, a redirect-based Server-Side Request Forgery (SSRF) bypass exists in `RecursiveUrlLoader` in `@langchain/community`. The loader validates the initial URL but allows the underlying

CVE MEDIUM CVE-2025-12058

mode=True, is vulnerable to arbitrary local file loading and Server-Side Request Forgery (SSRF). This vulnerability stems from the way the StringLookup layer is handled during model loading from

OpenClaw: Existing-session browser interaction routes bypassed SSRF policy enforcement

OpenClaw: Browser SSRF hostname validation could be bypassed by DNS rebinding

OpenClaw: Strict browser SSRF bypass in Playwright redirect handling leaves private targets reachable

OpenClaw has Browser SSRF Policy Bypass via Interaction-Triggered Navigation

OpenClaw QQ Bot Extension missing SSRF Protection on All Media Fetch Paths

OpenClaw: Marketplace Plugin Download Follows Redirects Without SSRF Protection

CVE MEDIUM CVE-2022-36551

Heartex - Label Studio Community Edition vulnerable to SSRF in the Data Import module

CVSS 6.5 label-studio View details
CVE MEDIUM CVE-2026-3340

Langflow Desktop 1.0.0 through 1.8.4 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading

CVE MEDIUM CVE-2026-41481

attacker-controlled server could redirect to internal, localhost, or cloud metadata endpoints, bypassing SSRF protections. The resp

OpenClaw: Browser snapshot and screenshot routes could expose internal page

Page 1 of 2 Next