CVE MEDIUM CVE-2024-3099

intended model, as it will open a different model each time. Additionally, an attacker can exploit this vulnerability to perform data model poisoning by creating a model with the same

CVSS 5.4 mlflow View details
CVE CRITICAL CVE-2026-2651

artifacts belonging to other users. This can lead to unauthorized cross-user writes, model supply chain poisoning, and arbitrary code execution when compromised models are loaded. The issue

CVSS 9.0 mlflow/mlflow View details

Python code when loaded, bypassing Picklescan's safety checks and enabling supply-chain poisoning of shared model files

CVSS 8.1 picklescan View details

Picklescan is vulnerable to RCE through missing detection when calling

picklescan View details

Picklescan is vulnerable to RCE via missing detection when calling

picklescan View details

llama-index-core insecurely handles temporary files

CVSS 7.3 llama-index-core View details

Open WebUI's process_files_batch() endpoint missing ownership check

CVSS 7.1 open-webui View details
CVE MEDIUM CVE-2026-45397

Open WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure

CVSS 5.3 open-webui View details

Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base

CVSS 7.5 open-webui View details

Open WebUI: Redis Cache Keys tool_servers and terminal_servers

CVSS 8.7 open-webui View details
CVE CRITICAL CVE-2026-50027

mcp-memory-service: Missing Authentication on Document API Endpoints Allows

CVSS 9.8 mcp-memory-service View details

vLLM is an inference and serving engine for large language

CVSS 8.0 vllm View details
CVE MEDIUM CVE-2026-54497

ViewComponent: Reused Component Instances Retain Stale Render Context

CVSS 6.8 view_component View details
CVE CRITICAL CVE-2026-44336

PraisonAI MCP `tools/call` path-traversal => RCE via Python `.pth` injection

CVSS 9.6 PraisonAI View details