Archive // 2026-08

August 2026

Everything the feeds carried with a date in August 2026: still live, or dropped out of the rolling window since. Changes to a CVE's severity, score or exploited status are listed under it.

CVE 31 Aug 2026
CVE-2026-82217 In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI "Agent Mode" file-change tools (writeFileContent, suggestFileContent, and the replacement and…
High 8.8first seen 04 Oct 2026live
CVE 31 Aug 2026
CVE-2026-79745 MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to…
High 7.1first seen 04 Oct 2026live
CVE 30 Aug 2026
CVE-2026-82640 browser-use web-ui versions 2.0.0 through 3.0.0 write configured LLM API keys to disk in cleartext without encryption or access restrictions. Attackers with read access…
Medium 5.5first seen 04 Oct 2026live
CVE 28 Aug 2026
CVE-2026-82233 SiYuan before v3.8.1 contains a path traversal vulnerability in the asset.upload MCP tool that accepts arbitrary absolute file paths without workspace boundary…
Medium 5.7first seen 04 Oct 2026live
CVE 28 Aug 2026
CVE-2026-70331 Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.
Medium 5.4first seen 04 Oct 2026live
CVE 28 Aug 2026
CVE-2026-68929 FastGPT is an open-source LLM platform for building AI applications on a knowledge base. In versions prior to 4.15.2, the WeChat (iLink) share-channel endpoints…
Unscoredfirst seen 04 Oct 2026live
CVE 28 Aug 2026
CVE-2026-54746 Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. From 0.40.0 until 0.91.1, the Dispatcher gRPC service does not…
Medium 6.4first seen 04 Oct 2026live
CVE 28 Aug 2026
CVE-2026-37237 vLLM up to and including 0.17.0 allows remote attackers to cause a Denial of Service via memory exhaustion. The AsyncMediaIO.fetch_audio and AsyncMediaIO.fetch_image…
High 7.5first seen 04 Oct 2026live
CVE 28 Aug 2026
CVE-2026-19295 IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a…
Critical 9.9first seen 04 Oct 2026live
CVE 28 Aug 2026
CVE-2026-19294 IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute and read any user's private flow due to improper authorization.
Medium 6.4first seen 04 Oct 2026live
CVE 28 Aug 2026
CVE-2026-19286 IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public…
Critical 9.8first seen 04 Oct 2026live
CVE 28 Aug 2026
CVE-2026-18904 IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject unauthorized messages due to a namespace collision between…
High 8.2first seen 04 Oct 2026live
CVE 28 Aug 2026
CVE-2026-18899 IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbitrary files due to path traversal.
High 7.5first seen 04 Oct 2026live
CVE 28 Aug 2026
CVE-2026-18891 IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive information due to improper authentication.
High 8.2first seen 04 Oct 2026live
CVE 28 Aug 2026
CVE-2026-18729 IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code.
High 8.8first seen 04 Oct 2026live
CVE 28 Aug 2026
CVE-2026-18545 IBM Langflow OSS 1.0.0 through 1.11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from…
Medium 4.3first seen 04 Oct 2026live
CVE 27 Aug 2026
CVE-2026-37006 A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker to achieve code execution via malicious Model…
Critical 9.8first seen 04 Oct 2026live
CVE 27 Aug 2026
CVE-2026-37003 Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection. The PythonTools and ShellTools components pass unsanitized…
Critical 9.8first seen 04 Oct 2026live
Model 27 Aug 2026
Alibaba / Qwen · open-weightfirst seen 04 Oct 2026live
Model 26 Aug 2026
Alibaba / Qwen · apifirst seen 04 Oct 2026live
CVE 25 Aug 2026
CVE-2026-78684 vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decode path. Unauthenticated attackers can activate…
Medium 5.3first seen 04 Oct 2026live
CVE 25 Aug 2026
CVE-2026-78379 Improper neutralization of input used for LLM prompting in the python_repl tool in Amazon Strands Agents Tools before 0.8.5 might allow remote actors to execute…
High 8.1first seen 04 Oct 2026live
CVE 25 Aug 2026
CVE-2026-55585 QWED is open-source AI verification infrastructure for deterministic verification of LLM outputs, tool calls, code, schemas, and agent state before production execution…
High 8.8first seen 04 Oct 2026live
CVE 25 Aug 2026
CVE-2026-55580 mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, config.go initializes Security.Enabled to false, and when…
Unscoredfirst seen 04 Oct 2026live
CVE 25 Aug 2026
CVE-2026-55557 browse-mcp is a Playwright-based headless-browser MCP server for MCP-capable agents. Prior to 0.8.2, browser_download writes a fetched response body to join(save_dir…
Unscoredfirst seen 04 Oct 2026live
CVE 25 Aug 2026
CVE-2026-53965 The MCP PHP SDK (Composer package mcp/sdk) is the official Model Context Protocol SDK for PHP. In versions 0.5.0 through 0.7.0, the HTTP client transport reads a…
Unscoredfirst seen 04 Oct 2026live
CVE 24 Aug 2026
CVE-2026-76072 The Continue CLI applies an incomplete denylist as its only barrier to destructive shell commands when running unattended. In headless mode and auto mode the default…
High 7.4first seen 04 Oct 2026live
Model 24 Aug 2026
Alibaba / Qwen · open-weightfirst seen 04 Oct 2026live
CVE 21 Aug 2026
CVE-2026-77776 Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in…
Critical 9.1first seen 04 Oct 2026live
CVE 21 Aug 2026
CVE-2026-77775 Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve_openai_upstream_base in…
High 8.6first seen 04 Oct 2026live
CVE 21 Aug 2026
CVE-2026-62677 Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, an authenticated user can upload a session-scoped agent…
High 8.8first seen 04 Oct 2026live
CVE 21 Aug 2026
CVE-2026-62676 Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, the shared shell-command parser in…
High 7.1first seen 04 Oct 2026live
CVE 21 Aug 2026
CVE-2026-62675 Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, multipart POST /v1/sessions accepts an authenticated…
High 8.8first seen 04 Oct 2026live
CVE 21 Aug 2026
CVE-2026-62674 Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /sessions/{session_id}/agent checks LEVEL_EDIT…
Critical 9.0first seen 04 Oct 2026live
CVE 21 Aug 2026
CVE-2026-54457 TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation. Prior to 2026.6.0, the TensorZero…
High 7.7first seen 04 Oct 2026live
CVE 20 Aug 2026
CVE-2026-71492 Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, DirectoryPromptRegistry.set() in src/banks/registries/directory.py…
Unscoredfirst seen 04 Oct 2026live
CVE 20 Aug 2026
CVE-2026-54449 LangBot is a global IM bot platform designed for LLMs. In version 4.10.7 and earlier, any authenticated user can add or change an STDIO MCP server configuration without…
High 8.8first seen 04 Oct 2026live
CVE 20 Aug 2026
CVE-2026-18482 Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server, where the checkSyntax() and…
Critical 9.8first seen 04 Oct 2026live
CVE 20 Aug 2026
CVE-2026-17153 The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.7. This is due to the plugin not properly…
Medium 5.3first seen 04 Oct 2026live
CVE 19 Aug 2026
CVE-2026-76832 Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that allows attackers to read, write, or execute arbitrary files by…
High 8.8first seen 04 Oct 2026live
CVE 19 Aug 2026
CVE-2026-19875 IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email information and abuse the server as an outbound relay due to missing…
High 7.5first seen 04 Oct 2026live
CVE 18 Aug 2026
CVE-2026-75913 CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter…
Critical 9.3first seen 04 Oct 2026live
CVE 18 Aug 2026
CVE-2026-75858 CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval tool. The tool's…
High 7.8first seen 04 Oct 2026live
CVE 18 Aug 2026
CVE-2026-75857 CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool, whose approval_requirement returns…
High 7.0first seen 04 Oct 2026live
CVE 18 Aug 2026
CVE-2026-75130 Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agents by injecting…
Critical 9.0first seen 04 Oct 2026live
CVE 18 Aug 2026
CVE-2026-50143 The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify Store. Prior to…
High 8.1first seen 04 Oct 2026live
CVE 17 Aug 2026
CVE-2026-75110 MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=true) but the undocumented, defaultless…
Critical 9.8first seen 04 Oct 2026live
CVE 17 Aug 2026
CVE-2026-73560 vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the MiMoV2OmniMultiModalProcessor in…
Medium 6.5first seen 04 Oct 2026live
CVE 17 Aug 2026
CVE-2026-71486 vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the /v1/completions/derender and /v1/chat/completions/derender endpoints accept…
Medium 4.3first seen 04 Oct 2026live
CVE 17 Aug 2026
CVE-2026-69148 MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a run_id or…
High 7.1first seen 04 Oct 2026live
CVE 17 Aug 2026
CVE-2026-69146 MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent from…
Medium 6.5first seen 04 Oct 2026live
CVE 17 Aug 2026
CVE-2026-64859 New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs…
Critical 9.1first seen 04 Oct 2026live
CVE 17 Aug 2026
CVE-2026-64849 MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Starting in 3.3.0 and prior to 3.15.0, the…
Critical 9.3Exploitedfirst seen 04 Oct 2026live
CVE 14 Aug 2026
CVE-2026-73678 MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute…
Critical 10.0first seen 04 Oct 2026live
Model 14 Aug 2026
Alibaba / Qwen · apifirst seen 04 Oct 2026live
CVE 13 Aug 2026
CVE-2026-73658 Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() and…
High 8.2first seen 04 Oct 2026live
CVE 13 Aug 2026
CVE-2026-73657 Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.4, `POST /api/v1/runs/:runParam/replay` in…
Medium 4.2first seen 04 Oct 2026live
CVE 13 Aug 2026
CVE-2026-73656 Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/background-workers…
Critical 9.9first seen 04 Oct 2026live
CVE 13 Aug 2026
CVE-2026-73655 Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.2, addGoogleStrategy() in…
High 7.4first seen 04 Oct 2026live
CVE 13 Aug 2026
CVE-2026-73654 Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 3.3.8 until 4.5.6, the PUT /api/v1/runs/:runId/metadata endpoint passes…
High 8.5first seen 04 Oct 2026live
CVE 13 Aug 2026
CVE-2026-73559 vLLM is an inference and serving engine for large language models. From 0.19.0 until 0.26.0, the /v1/completions CompletionRequest.prompt field in…
Medium 6.5first seen 04 Oct 2026live
CVE 13 Aug 2026
CVE-2026-73558 vLLM is an inference and serving engine for large language models. Prior to 0.27.0, an integer overflow in blockIdx.x * 2 * d in activation_kernels.cu can cause…
Medium 5.3first seen 04 Oct 2026live
CVE 13 Aug 2026
CVE-2026-73557 vLLM is an inference and serving engine for large language models. From 0.20.2rc0 until 0.26.0, safe_load_prompt_embeds in vllm/renderers/embed_utils.py uses…
Unscoredfirst seen 04 Oct 2026live
CVE 13 Aug 2026
CVE-2026-73556 vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex parameter in…
Medium 5.3first seen 04 Oct 2026live
CVE 13 Aug 2026
CVE-2026-73555 vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in vllm/entrypoints/openai/server_utils.py converts…
Medium 5.3first seen 04 Oct 2026live
CVE 13 Aug 2026
CVE-2026-73487 Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inject malicious code…
Critical 9.8first seen 04 Oct 2026live
CVE 13 Aug 2026
CVE-2026-73485 Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Python code by…
High 8.8first seen 04 Oct 2026live
CVE 13 Aug 2026
CVE-2026-49856 @jshookmcp/jshook is an MCP server that gives AI agents tools for JavaScript analysis and security research. In version 0.3.1, he network domain has a central SSRF…
Medium 4.3first seen 04 Oct 2026live
CVE 13 Aug 2026
CVE-2026-19753 A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0. Affected is the function explore_url of the file src/mcp-rdf-explorer/server.py of the…
High 7.3first seen 04 Oct 2026live
CVE 13 Aug 2026
CVE-2026-19297 IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication…
Critical 9.1first seen 04 Oct 2026live
Model 13 Aug 2026
Google · proprietaryfirst seen 04 Oct 2026live
Model 13 Aug 2026
NVIDIA · open-weightfirst seen 04 Oct 2026live
Model 13 Aug 2026
Alibaba / Qwen · open-weightfirst seen 04 Oct 2026live
CVE 12 Aug 2026
CVE-2026-73498 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its…
High 7.7first seen 04 Oct 2026live
CVE 12 Aug 2026
CVE-2026-73299 Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .prompty template…
Critical 10.0first seen 04 Oct 2026live
Model 12 Aug 2026
xAI · proprietaryfirst seen 04 Oct 2026live
Model 12 Aug 2026
Alibaba / Qwen · apifirst seen 04 Oct 2026live
CVE 11 Aug 2026
CVE-2026-73068 ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.207, the ToolJet Database…
Medium 5.9first seen 04 Oct 2026live
CVE 11 Aug 2026
CVE-2026-73032 PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary JavaScript by returning malicious code from an LLM…
Critical 9.6first seen 04 Oct 2026live
CVE 11 Aug 2026
CVE-2026-72771 n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoint URLs are…
Medium 6.5first seen 04 Oct 2026live
CVE 11 Aug 2026
CVE-2026-28707 Protection mechanism failure for some LLM-on-Ray before version 1.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software…
Unscoredfirst seen 04 Oct 2026live
CVE 11 Aug 2026
CVE-2026-27765 Improper input validation for some vLLM Hardware Plugin for Intel(R) Gaudi(R) software before version 0.16.0 within Ring 3: User Applications may allow a denial of…
Medium 5.5first seen 04 Oct 2026live
CVE 11 Aug 2026
CVE-2026-21387 Protection mechanism failure for some Intel(R) LLM Library for PyTorch within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software…
Unscoredfirst seen 04 Oct 2026live
CVE 11 Aug 2026
CVE-2026-20755 Protection mechanism failure for some LLM Scaler software within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a…
Unscoredfirst seen 04 Oct 2026live
CVE 10 Aug 2026
CVE-2026-72917 AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.0.0 to 1.15.0, AnythingLLM's…
Medium 5.9first seen 04 Oct 2026live
CVE 10 Aug 2026
CVE-2026-72904 Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file read vulnerability exists in Firecrawl's…
Unscoredfirst seen 04 Oct 2026live
CVE 10 Aug 2026
CVE-2026-72718 goose is general-purpose AI agent that runs on your machine. Prior to 1.44.0, the `goose review` command runs the system `git` executable to gather the diff for review…
Unscoredfirst seen 04 Oct 2026live
CVE 09 Aug 2026
CVE-2026-19334 A flaw has been found in NightTrek Ollama-mcp up to 80cf2e17cfc144963a475b619093a2d13c13dbc9. This affects an unknown part of the file src/index.ts. This manipulation of…
Medium 5.3first seen 04 Oct 2026live
Model 08 Aug 2026
Alibaba / Qwen · open-weightfirst seen 04 Oct 2026live
CVE 07 Aug 2026
CVE-2026-61808 LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with authentication…
Critical 9.8first seen 04 Oct 2026live
CVE 07 Aug 2026
CVE-2026-48039 Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispatch()` at…
Critical 9.1first seen 04 Oct 2026live
CVE 06 Aug 2026
CVE-2026-67531 FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:execute tool exposes live host Zod schema instances…
Unscoredfirst seen 04 Oct 2026live
CVE 06 Aug 2026
CVE-2026-19111 Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands Agents Tools before 0.8.3 might allow remote…
High 8.1first seen 04 Oct 2026live
CVE 05 Aug 2026
CVE-2026-9205 IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.
High 7.4first seen 04 Oct 2026live
CVE 05 Aug 2026
CVE-2026-9201 IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in the custom component validation…
High 8.8first seen 04 Oct 2026live
CVE 05 Aug 2026
CVE-2026-9196 IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to improper handling of…
High 8.1first seen 04 Oct 2026live
CVE 05 Aug 2026
CVE-2026-9130 IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of…
High 7.1first seen 04 Oct 2026live
CVE 05 Aug 2026
CVE-2026-9081 IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_model_provider_key() function…
High 7.1first seen 04 Oct 2026live
CVE 05 Aug 2026
CVE-2026-9077 IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations…
High 8.5first seen 04 Oct 2026live
CVE 05 Aug 2026
CVE-2026-8478 IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.
High 8.8first seen 04 Oct 2026live
CVE 05 Aug 2026
CVE-2026-8470 IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating…
High 7.4first seen 04 Oct 2026live
CVE 05 Aug 2026
CVE-2026-8446 IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP) composer endpoint when mcp_composer_enabled=true…
High 7.5first seen 04 Oct 2026live
CVE 05 Aug 2026
CVE-2026-8183 IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a…
High 7.7first seen 04 Oct 2026live
CVE 05 Aug 2026
CVE-2026-8182 IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via 2 HTTP requests.
High 8.8first seen 04 Oct 2026live
CVE 05 Aug 2026
CVE-2026-7869 IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledge_bases`). This occurs because user-supplied…
Medium 5.4first seen 04 Oct 2026live
CVE 05 Aug 2026
CVE-2026-7658 IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path traversal sequences and bypass containment checks…
Medium 6.5first seen 04 Oct 2026live
CVE 05 Aug 2026
CVE-2026-7657 IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplete and ineffective SSRF protection enforcement.
Medium 6.5first seen 04 Oct 2026live
CVE 05 Aug 2026
CVE-2026-7646 IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other users' uploaded documents, the JWT signing secret…
Medium 6.5first seen 04 Oct 2026live
CVE 05 Aug 2026
CVE-2026-71211 MLflow's AI Gateway accepts an auth_config.api_base value when creating a gateway secret (mlflow/server/handlers.py, _create_gateway_secret) with no validation of…
High 7.1first seen 04 Oct 2026live
CVE 05 Aug 2026
CVE-2026-17633 IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injection.
High 8.5first seen 04 Oct 2026live
CVE 05 Aug 2026
CVE-2026-17632 IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code during AST-based…
High 8.8first seen 04 Oct 2026live
CVE 05 Aug 2026
CVE-2026-17630 IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper validation of configuration parameters.
High 7.2first seen 04 Oct 2026live
CVE 05 Aug 2026
CVE-2026-17626 IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based MCP servers due to…
High 8.8first seen 04 Oct 2026live
CVE 05 Aug 2026
CVE-2026-17625 IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through…
High 7.2first seen 04 Oct 2026live
CVE 05 Aug 2026
CVE-2026-17624 IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through…
High 8.5first seen 04 Oct 2026live
CVE 05 Aug 2026
CVE-2026-17623 IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of the command field in MCP…
High 8.8first seen 04 Oct 2026live
CVE 05 Aug 2026
CVE-2026-10547 IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint, allowing an authenticated…
Medium 5.9first seen 04 Oct 2026live
CVE 05 Aug 2026
CVE-2026-10128 IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbitrary server environment variables, exposing…
Medium 6.5first seen 04 Oct 2026live
Model 05 Aug 2026
Alibaba / Qwen · open-weightfirst seen 04 Oct 2026live
CVE 04 Aug 2026
CVE-2026-70478 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/refresh/:credentialId…
Critical 10.0first seen 04 Oct 2026live
CVE 04 Aug 2026
CVE-2026-70477 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can…
Critical 9.8first seen 04 Oct 2026live
CVE 04 Aug 2026
CVE-2026-70476 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in…
High 8.2first seen 04 Oct 2026live
CVE 04 Aug 2026
CVE-2026-70475 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1/executions/:id endpoint in…
Medium 6.5first seen 04 Oct 2026live
CVE 04 Aug 2026
CVE-2026-70474 Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise has three OAuth2 credential endpoints that…
High 8.1first seen 04 Oct 2026live
CVE 04 Aug 2026
CVE-2026-70473 Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire…
High 8.5first seen 04 Oct 2026live
CVE 04 Aug 2026
CVE-2026-70472 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assistants-vector-store endpoints accept a…
High 8.8first seen 04 Oct 2026live
CVE 04 Aug 2026
CVE-2026-70471 Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise injects $vars into the code execution sandbox…
Medium 6.5first seen 04 Oct 2026live
CVE 04 Aug 2026
CVE-2026-70470 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise validatePythonCodeForDataFrame in…
Critical 9.8first seen 04 Oct 2026live
CVE 04 Aug 2026
CVE-2026-69263 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for CVE-2025-8943 blocked -y and --yes flags on…
Critical 9.8first seen 04 Oct 2026live
CVE 04 Aug 2026
CVE-2026-69262 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1/chatflows/:id` authorized requests with…
High 8.1first seen 04 Oct 2026live
CVE 04 Aug 2026
CVE-2026-69259 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in…
High 8.8first seen 04 Oct 2026live
CVE 04 Aug 2026
CVE-2026-69258 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint…
Critical 9.1first seen 04 Oct 2026live
CVE 04 Aug 2026
CVE-2026-69257 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did not normalize…
High 8.6first seen 04 Oct 2026live
CVE 04 Aug 2026
CVE-2026-69256 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to provide Python code that is…
High 8.8first seen 04 Oct 2026live
CVE 04 Aug 2026
CVE-2026-69255 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in…
High 8.8first seen 04 Oct 2026live
CVE 04 Aug 2026
CVE-2026-69254 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScriptCode() accepted caller-provided nodeVMOptions…
High 8.8first seen 04 Oct 2026live
CVE 04 Aug 2026
CVE-2026-69253 Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1.3, several custom-tool components — AgentAsTool…
High 8.8first seen 04 Oct 2026live
CVE 04 Aug 2026
CVE-2026-69252 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/files route was protected only by the feat:files…
High 8.8first seen 04 Oct 2026live
CVE 04 Aug 2026
CVE-2026-69251 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record manager and agent memory nodes allowed users to…
High 8.8first seen 04 Oct 2026live
CVE 04 Aug 2026
CVE-2026-69250 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the OAuth2 token refresh endpoint POST…
High 7.5first seen 04 Oct 2026live
CVE 04 Aug 2026
CVE-2026-47487 NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository to be read, written to, or modified by…
Medium 4.4first seen 04 Oct 2026live
CVE 03 Aug 2026
CVE-2026-67598 Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attackers to intercept…
High 7.4first seen 04 Oct 2026live
CVE 03 Aug 2026
CVE-2026-66065 Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. Versions prior to 0.42.1 have…
Unscoredfirst seen 04 Oct 2026live
CVE 03 Aug 2026
CVE-2026-18733 A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operating system commands…
High 8.8first seen 04 Oct 2026live
CVE 03 Aug 2026
CVE-2026-18655 Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before 2.0.24 may allow a…
Medium 6.5first seen 04 Oct 2026live