intended model, as it will open a different model each time. Additionally, an attacker can exploit this vulnerability to perform data model poisoning by creating a model with the same
artifacts belonging to other users. This can lead to unauthorized cross-user writes, model supply chain poisoning, and arbitrary code execution when compromised models are loaded. The issue
Python code when loaded, bypassing Picklescan's safety checks and enabling supply-chain poisoning of shared model files
llama-index-core insecurely handles temporary files
Open WebUI's process_files_batch() endpoint missing ownership check
Open WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure
Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base
Open WebUI: Redis Cache Keys tool_servers and terminal_servers
mcp-memory-service: Missing Authentication on Document API Endpoints Allows
vLLM is an inference and serving engine for large language
ViewComponent: Reused Component Instances Retain Stale Render Context
PraisonAI MCP `tools/call` path-traversal => RCE via Python `.pth` injection