CWE-155
CVEs classified under CWE-155, newest first.
4 CVEsRSS
CVE-2026-87016High· 8.1PoCOpen WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.41 until 0.11.1, get_user_by_oauth_sub and get_user_by_scim_external_id in backend/open_webui/models/users.py used JSON contains matching that…
CVE-2026-68939NonePyenv provides simple Python version management
Pyenv provides simple Python version management. Prior to 2.8.0, is_version_safe() in libexec/pyenv-version-file-read accepts shell glob metacharacters in .python-version values, and unquoted PYENV_VERSION expansion in libexec/pyenv-vers…
CVE-2026-73412NoneShescape is a simple shell escape library for JavaScript
Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, this impacts users of Shescape on Unix systems that explicitly configure shell to Zsh, or true when the default shell is Zsh, using the escape and escap…
GHSA-6v4m-fw66-8r4xMediumShescape: Path disclosure on Unix with Zsh
Shescape: Path disclosure on Unix with Zsh