Archive // 2026-06

June 2026

Everything the feeds carried with a date in June 2026: still live, or dropped out of the rolling window since. Changes to a CVE's severity, score or exploited status are listed under it.

CVE 30 Jun 2026
CVE-2026-7874 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored credentials due to the use of a weak and reversible key derivation mechanism for…
Critical 9.1first seen 04 Oct 2026live
CVE 30 Jun 2026
CVE-2026-7873 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive files including credentials, enabling complete…
Critical 9.9first seen 04 Oct 2026live
CVE 30 Jun 2026
CVE-2026-7871 IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application privileges, compromising all secrets, data, and…
Critical 9.8first seen 04 Oct 2026live
CVE 30 Jun 2026
CVE-2026-7803 IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow nodes with missing or empty component type fields.
Critical 9.8first seen 04 Oct 2026live
CVE 30 Jun 2026
CVE-2026-7663 IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper…
Critical 9.1first seen 04 Oct 2026live
CVE 30 Jun 2026
CVE-2026-58446 Presenton before 0.8.8-beta bundles an MCP server that, on server/Docker deployments configured with session authentication (AUTH_USERNAME/AUTH_PASSWORD), is reachable…
Medium 6.5first seen 04 Oct 2026live
CVE 30 Jun 2026
CVE-2026-58169 Vibe-Trading before 0.1.10 contains a DNS rebinding authentication bypass vulnerability that allows remote attackers to bypass bearer-token authentication by exploiting…
High 7.5first seen 04 Oct 2026live
CVE 30 Jun 2026
CVE-2026-10564 IBM Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side Request Forgery (SSRF). The legacy RSSReaderComponent in rss.py and SearXNG component in searxng.py make…
High 8.2first seen 04 Oct 2026live
CVE 30 Jun 2026
CVE-2026-10560 IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoints that allows an unauthenticated attacker to…
High 8.2first seen 04 Oct 2026live
CVE 30 Jun 2026
CVE-2026-10546 IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the URL component ( src/lfx/src/lfx/components/data_source/url.py )…
High 7.1first seen 04 Oct 2026live
CVE 30 Jun 2026
CVE-2026-10140 IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. An authenticated…
Critical 9.6first seen 04 Oct 2026live
CVE 30 Jun 2026
CVE-2026-10134 IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversation, message, file…
Critical 10.0first seen 04 Oct 2026live
CVE 30 Jun 2026
CVE-2026-10129 IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) protection bypass vulnerability in the API Request component. An authenticated…
High 8.5first seen 04 Oct 2026live
CVE 29 Jun 2026
CVE-2026-55607 Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of worktrees named ".git" and navigation to worktrees…
High 8.8first seen 04 Oct 2026live
CVE 29 Jun 2026
CVE-2026-13437 Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent read…
Medium 6.5first seen 04 Oct 2026live
CVE 28 Jun 2026
CVE-2026-13493 A flaw has been found in AIDC-AI ComfyUI-Copilot up to 2.0.28. This issue affects some unknown processing of the file backend/controller/conversation_api.py of the…
Low 3.1first seen 04 Oct 2026live
CVE 28 Jun 2026
CVE-2026-13484 A vulnerability has been found in MLflow up to 4666cffc7912ea606d592fc38d6a75e2935f65e7. The impacted element is an unknown function of the component Experiment-scoped…
Medium 5.0first seen 04 Oct 2026live
CVE 26 Jun 2026
CVE-2026-5757 Unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap memory…
High 7.5first seen 04 Oct 2026live
CVE 25 Jun 2026
CVE-2026-55413 ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-lts, any authenticated…
Unscoredfirst seen 04 Oct 2026live
CVE 25 Jun 2026
CVE-2026-55412 ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-lts, there's an SSRF in…
High 8.3first seen 04 Oct 2026live
CVE 25 Jun 2026
CVE-2026-55411 ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.1780-lts, the authenticated…
Medium 6.8first seen 04 Oct 2026live
CVE 24 Jun 2026
CVE-2026-55611 AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.11.1 until 1.14.1, userId/workspaceId…
None 0.0first seen 04 Oct 2026live
CVE 24 Jun 2026
CVE-2026-55583 Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.9.0, Twenty was vulnerable to a cross-workspace insecure direct object reference…
High 7.6first seen 04 Oct 2026live
CVE 24 Jun 2026
CVE-2026-48789 AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, on Windows, the document…
Medium 4.3first seen 04 Oct 2026live
CVE 24 Jun 2026
CVE-2026-48719 Warp is an agentic development environment. From 0.2025.08.06.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection in the prompt branch…
High 8.0first seen 04 Oct 2026live
CVE 23 Jun 2026
CVE-2026-55450 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can upload any amount of data to the server without…
Critical 9.3first seen 04 Oct 2026live
CVE 23 Jun 2026
CVE-2026-55447 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files that are digested into the RAG, an attacker can…
Critical 9.6first seen 04 Oct 2026live
CVE 23 Jun 2026
CVE-2026-55446 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.0.19, an attacker can send a /api/v1/files/upload/ request without any…
High 7.5first seen 04 Oct 2026live
CVE 23 Jun 2026
CVE-2026-55423 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.7.0, the logout button does not clear the session. The previous user stays…
Medium 6.1first seen 04 Oct 2026live
CVE 23 Jun 2026
CVE-2026-55255 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in…
High 8.4Exploitedfirst seen 04 Oct 2026live
CVE 23 Jun 2026
CVE-2026-55249 @rtk-ai/rtk-rewrite transparently rewrites shell commands executed via OpenClaw's exec tool to their RTK equivalents. In 1.0.0, the @rtk-ai/rtk-rewrite OpenClaw plugin…
Medium 6.3first seen 04 Oct 2026live
CVE 23 Jun 2026
CVE-2026-54555 rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.42.2, the permission splitter did not conservatively split or reject several…
High 7.8first seen 04 Oct 2026live
CVE 23 Jun 2026
CVE-2026-54021 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, several direct, index-addressed Ollama proxy routes…
Medium 6.3first seen 04 Oct 2026live
CVE 23 Jun 2026
CVE-2026-54009 Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, POST /api/chat/completions accepts an image_url.url…
Medium 6.5first seen 04 Oct 2026live
CVE 23 Jun 2026
CVE-2026-53755 Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.9, the Docker API server applied its SSRF destination check to the crawl target URL only, not…
High 8.6first seen 04 Oct 2026live
CVE 23 Jun 2026
CVE-2026-53754 Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.8, the Docker API server's SSRF protection (validate_webhook_url / validate_url_destination…
High 7.5first seen 04 Oct 2026live
CVE 23 Jun 2026
CVE-2026-53753 Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in the computed fields feature uses an AST validator…
Critical 9.8first seen 04 Oct 2026live
CVE 23 Jun 2026
CVE-2026-48520 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.10.0, the "Shareable Playground" (or "Public Flows" in code) contains a…
Medium 6.1first seen 04 Oct 2026live
CVE 23 Jun 2026
CVE-2026-48519 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, the "Shareable Playground" (or "Public Flows" in code) contains a critical…
Critical 9.6first seen 04 Oct 2026live
CVE 23 Jun 2026
CVE-2026-45792 rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.32.0, RTK (Rust Token Killer) improperly trusts project-local configuration…
Medium 5.5first seen 04 Oct 2026live
CVE 23 Jun 2026
CVE-2026-42867 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowledge Bases API (POST…
Medium 6.5first seen 04 Oct 2026live
CVE 23 Jun 2026
CVE-2026-33760 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow's /api/v1/monitor router exposes 7 endpoints that perform read…
High 8.8first seen 04 Oct 2026live
CVE 22 Jun 2026
CVE-2026-7664 IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper…
Critical 9.8first seen 04 Oct 2026live
CVE 22 Jun 2026
CVE-2026-55443 LangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components that resolve filesystem paths or expand search…
Medium 5.1first seen 04 Oct 2026live
CVE 22 Jun 2026
CVE-2026-54236 vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, the fix for CVE-2026-22778, which introduced a sanitize_message helper that…
Medium 5.3first seen 04 Oct 2026live
CVE 22 Jun 2026
CVE-2026-54235 vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, ll temperature validation gates use comparison operators (<, >), which…
Medium 6.5first seen 04 Oct 2026live
CVE 22 Jun 2026
CVE-2026-54233 vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, vLLM's /v1/audio/transcriptions endpoint limits compressed upload size but…
Medium 6.5first seen 04 Oct 2026live
CVE 22 Jun 2026
CVE-2026-54232 vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.1, the vLLM Dockerfile is vulnerable to a dependency confusion attack through the…
High 8.8first seen 04 Oct 2026live
CVE 22 Jun 2026
CVE-2026-53923 vLLM is an inference and serving engine for large language models (LLMs). From 0.5.5 until 0.23.1rc0, integer truncation of tensor dimensions in vLLM's GGUF dequantize…
High 7.5first seen 04 Oct 2026live
CVE 22 Jun 2026
CVE-2026-49468 LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, a Host-header parsing flaw in the LiteLLM proxy could, under…
Critical 9.8first seen 04 Oct 2026live
CVE 22 Jun 2026
CVE-2026-48746 vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web…
Critical 9.1first seen 04 Oct 2026live
CVE 22 Jun 2026
CVE-2026-47155 vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, vLLM's revision pinning controls do not consistently apply to all artifacts…
Medium 6.5first seen 04 Oct 2026live
CVE 22 Jun 2026
CVE-2026-41523 vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, an assert-based security check in vLLM's activation function loading allows…
High 7.5first seen 04 Oct 2026live
CVE 22 Jun 2026
CVE-2026-12822 A vulnerability was identified in langflow-ai langflow up to 1.9.3. This affects an unknown function of the component Bundle URL Loader. The manipulation leads to code…
Medium 5.3first seen 04 Oct 2026live
CVE 22 Jun 2026
CVE-2026-10561 IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an…
Critical 10.0first seen 04 Oct 2026live
CVE 22 Jun 2026
CVE-2025-66389 GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore…
High 7.5first seen 04 Oct 2026live
CVE 20 Jun 2026
CVE-2026-56340 vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorch disables sparse tensor invariant checks by…
High 8.8first seen 04 Oct 2026live
CVE 20 Jun 2026
CVE-2025-71379 vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular expression denial of service (ReDoS) vulnerabilities. Several regex patterns — in vllm/lora/utils.py, the…
Medium 4.3first seen 04 Oct 2026live
CVE 20 Jun 2026
CVE-2024-58351 Flowise before 2.1.4 allows configuration to be injected into the Chainflow during execution via the overrideConfig option, supported in both the frontend web…
Critical 9.8first seen 04 Oct 2026live
CVE 19 Jun 2026
CVE-2026-12048 Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text returned by a PostgreSQL server (ErrorResponse messages, including object…
Critical 9.3first seen 04 Oct 2026live
CVE 19 Jun 2026
CVE-2026-12045 Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execute arbitrary SQL with…
Critical 9.0first seen 04 Oct 2026live
CVE 18 Jun 2026
CVE-2026-56075 PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode approval_mode to auto, overriding administrator…
High 8.8first seen 04 Oct 2026live
CVE 18 Jun 2026
CVE-2026-49257 mcp-pinot is a Python-based Model Context Protocol (MCP) server for interacting with Apache Pinot. In versions 3.0.1 and below, mcp-pinot defaults to running an HTTP MCP…
Critical 10.0first seen 04 Oct 2026live
CVE 18 Jun 2026
CVE-2026-46580 In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could override or extend the…
High 8.8first seen 04 Oct 2026live
CVE 18 Jun 2026
CVE-2026-44688 In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without distinguishing them from…
High 8.8first seen 04 Oct 2026live
CVE 18 Jun 2026
CVE-2026-22551 In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitrary external URLs without…
Medium 6.5first seen 04 Oct 2026live
CVE 17 Jun 2026
CVE-2026-48797 Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, the optional Reflex web UI exposes a training…
Unscoredfirst seen 04 Oct 2026live
CVE 17 Jun 2026
CVE-2026-48782 Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.56.0 through 1.101.0, 2.0.0b1, and 2.0.0b2, the…
Medium 6.8first seen 04 Oct 2026live
CVE 17 Jun 2026
CVE-2026-20265 In Splunk AI Toolkit versions below 5.7.4, a low-privileged user that does not hold the "admin" or "power" Splunk roles could cause the Splunk AI Toolkit to make…
Medium 4.3first seen 04 Oct 2026live
CVE 17 Jun 2026
CVE-2026-12491 A flaw was found in vLLM, an open-source library for large language model inference. This vulnerability arises from improper handling of image metadata, specifically…
Medium 4.8first seen 04 Oct 2026live
CVE 13 Jun 2026
CVE-2026-11624 The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming connections to prevent DNS rebinding attacks. Prior to…
Unscoredfirst seen 04 Oct 2026live
CVE 12 Jun 2026
CVE-2026-50287 AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a Streamable HTTP transport when started with…
Unscoredfirst seen 04 Oct 2026live
CVE 11 Jun 2026
CVE-2026-7787 IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object…
High 7.5first seen 04 Oct 2026live
CVE 11 Jun 2026
CVE-2026-5497 vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the…
High 7.5first seen 04 Oct 2026live
CVE 11 Jun 2026
CVE-2026-47250 mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.7.0, the kubectl_generic tool in mcp-server-kubernetes…
Medium 6.1first seen 04 Oct 2026live
CVE 11 Jun 2026
CVE-2026-46519 mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.6.0, mcp-server-kubernetes exposes three environment…
High 8.8first seen 04 Oct 2026live
CVE 11 Jun 2026
CVE-2026-3341 IBM Langflow Desktop 1.0.0 through 1.9.2 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized…
Medium 5.4first seen 04 Oct 2026live
CVE 10 Jun 2026
CVE-2026-46517 LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, hardcoded "trust_remote_code=True" enables HF…
High 7.8first seen 04 Oct 2026live
CVE 10 Jun 2026
CVE-2026-46432 LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, LMDeploy is vulnerable to arbitrary code execution…
High 7.8first seen 04 Oct 2026live
CVE 09 Jun 2026
CVE-2026-49948 Mem0 versions through 0.2.8, fixed in commit ae7f406, contain a missing authorization vulnerability in the self-hosted server component where the POST /configure…
High 8.1first seen 04 Oct 2026live
CVE 08 Jun 2026
CVE-2026-46480 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluator create and update mass-assignment allows…
High 8.8first seen 04 Oct 2026live
CVE 08 Jun 2026
CVE-2026-46479 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluation create and update mass-assignment allows…
High 8.8first seen 04 Oct 2026live
CVE 08 Jun 2026
CVE-2026-46478 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, DatasetRow create and update mass-assignment allows…
High 8.8first seen 04 Oct 2026live
CVE 08 Jun 2026
CVE-2026-46477 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, dataset create and update mass-assignment allows…
High 8.8first seen 04 Oct 2026live
CVE 08 Jun 2026
CVE-2026-46476 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, CustomTemplate create and update mass-assignment allows…
High 8.8first seen 04 Oct 2026live
CVE 08 Jun 2026
CVE-2026-46475 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, assistant create and update mass-assignment allows…
High 8.8first seen 04 Oct 2026live
CVE 08 Jun 2026
CVE-2026-46444 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, all CRUD endpoints for OpenAI Assistants Vector Store…
High 8.8first seen 04 Oct 2026live
CVE 08 Jun 2026
CVE-2026-46443 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, when credentials are fetched with a credentialName…
Medium 6.5first seen 04 Oct 2026live
CVE 08 Jun 2026
CVE-2026-46442 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /api/v1/node-custom-function lacks route-level…
Critical 9.9first seen 04 Oct 2026live
CVE 08 Jun 2026
CVE-2026-46441 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the assistant…
Critical 9.6first seen 04 Oct 2026live
CVE 08 Jun 2026
CVE-2026-46440 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the checkBasicAuth endpoint validates credentials in…
Critical 9.1first seen 04 Oct 2026live
CVE 08 Jun 2026
CVE-2026-42863 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the chatflow…
High 8.1first seen 04 Oct 2026live
CVE 08 Jun 2026
CVE-2026-42862 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the tool…
Medium 5.0first seen 04 Oct 2026live
CVE 08 Jun 2026
CVE-2026-42861 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the variable…
Critical 9.6first seen 04 Oct 2026live