Open Source Vulnerabilities
djangorestframework
Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`
djangorestframework
Django REST framework: Potential bypass of Django `DATA_UPLOAD_MAX_MEMORY_SIZE` when parsing oversized JSON and urlencoded request bodies via DRF `request.data`
djangorestframework
Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests
djangorestframework
Django REST framework: AdminRenderer may disclose GET-protected data when rendering invalid write requests
restrictedpython
RestrictedPython guard hooks can be shadowed via positional-only arguments
restrictedpython
RestrictedPython guard hooks can be shadowed via positional-only arguments
plone-app-event
plone.app.event vulnerable to denial of service via iCalendar import
plone-app-event
plone.app.event vulnerable to denial of service via iCalendar import
weblate
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
weblate
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
weblate
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
weblate
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
protego
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching
protego
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching
plone-app-portlets
plone.app.portlets vulnerable to denial of service via RSS feed portlet
plone-app-portlets
plone.app.portlets vulnerable to denial of service via RSS feed portlet
piccolo-admin
piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.
piccolo-admin
piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.
wsgidav
WsgiDAV MySQL provider has a blind SQL injection
compliance-trestle
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
compliance-trestle
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
aiosmtplib
aiosmtplib: STARTTLS response injection
webob
WebOb: Open redirect in Location header normalization via leading C0 control / space characters
webob
WebOb: Open redirect in Location header normalization via leading C0 control / space characters
litellm
LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
litellm
LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint
asyncssh
asyncssh has SCP Path Traversal to Arbitrary File Write
asyncssh
asyncssh has SCP Path Traversal to Arbitrary File Write
asyncssh
asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution
asyncssh
asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution
senaite-core
senaite.core Vulnerable to Eval Injection and Missing Authorization
senaite-core
senaite.core Vulnerable to Eval Injection and Missing Authorization
kas
kas Persistently Disables SSH Host Key Checking
starlette-admin
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
starlette-admin
Starlette-Admin's unvalidated `order_by` parameter allows ordering by hidden columns (info-exposure oracle) and HTTP 500 DoS
jupyterhub
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
jupyterhub
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
icalendar
icalendar has Algorithmic Complexity in Equality
chainlit
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access
chainlit
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access
chainlit
Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution
chainlit
Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution
eml-parser
eml_parser vulnerable to DoS via deeply nested parens in Received headers
eml-parser
eml_parser vulnerable to DoS via deeply nested parens in Received headers
eml-parser
eml_parser has parser DoS via deeply nested parentheses in e-mail headers
eml-parser
eml_parser has parser DoS via deeply nested parentheses in e-mail headers
eml-parser
eml_parser has a URL extraction bypass via HTML entities in URLs
eml-parser
eml_parser has a URL extraction bypass via HTML entities in URLs
reachy-mini
reachy_mini Allows Unrestricted Upload of File with Dangerous Type
reachy-mini
reachy_mini Allows Unrestricted Upload of File with Dangerous Type
qwed
qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`
qwed
qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`
djust
djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls
djust
djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls
nextcloud-mcp-server
nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )
nextcloud-mcp-server
nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )
utcp-websocket
utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
utcp-websocket
utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
utcp-gql
utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
utcp-gql
utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
qwed-mcp
qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
qwed-mcp
qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input
praisonai
PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)
praisonai
PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)
praisonai
PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server
praisonai
PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server
praisonai
PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret
praisonai
PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret
praisonai
PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete
praisonai
PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete
praisonaiagents
praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location
praisonaiagents
praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location
praisonai
PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced
praisonai
PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced
praisonai
PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation
praisonai
PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation
praisonai
PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
praisonai
PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
praisonai
PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated
praisonai
PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated
praisonai
PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks
praisonai
PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks
praisonaiagents
praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool
praisonaiagents
praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool
praisonaiagents
praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)
praisonaiagents
praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)
praisonai
PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution
praisonai
PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution
praisonaiagents
praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)
praisonaiagents
praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)
praisonai
PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)
praisonai
PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)
praisonaiagents
praisonaiagents: AgentServer declares auth_token but never enforces it on any route
praisonaiagents
praisonaiagents: AgentServer declares auth_token but never enforces it on any route
praisonai
PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server
praisonai
PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server
