VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2026-70589Medium· 4.8
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to redeem subscription offers that were no longer active. This issue is fixed in version 6.54.1.

▾ Sunlitghost · ghostEPSS 0.27%via NVD
CVE-2026-53944Medium· 5.8
1mo ago

Ghost: Private IP filtering bypass to make server-side requests to internal services

Ghost: Private IP filtering bypass to make server-side requests to internal services

▾ Sunlitghost · ghostEPSS 0.33%via GHSA
CVE-2026-53945Medium· 4.0
1mo ago

Ghost: Server-side request forgery via DNS rebinding in external request handling

Ghost: Server-side request forgery via DNS rebinding in external request handling

▾ Sunlitghost · ghostEPSS 0.21%via GHSA
CVE-2026-53946Medium· 5.4
1mo ago

Ghost: Mobiledoc image-size fetch SSRF

Ghost: Mobiledoc image-size fetch SSRF

▾ Sunlitghost · ghostEPSS 0.21%via GHSA
CVE-2026-70590Medium· 4.8
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through the Ghost Admin API. An offline password-guessing attack against the hashes could lead…

▾ Sunlitghost · ghostEPSS 0.32%via NVD
CVE-2026-70591Medium· 4.1
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed any staff-level user to perform a blind HTTP GET request against internal hosts. No output was re…

▾ Sunlitghost · ghostEPSS 0.37%via NVD
CVE-2026-70592Medium· 5.5
1mo ago

Ghost is a Node.js content management system

Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite certain files on the filesystem through the database backup filename, leading to integrity and availability issu…

▾ Sunlitghost · ghostEPSS 0.44%via NVD
CVE-2026-70481Medium· 5.4PoC
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update and delete handlers accepted any caller holding write access on the channel without checki…

▾ Twilightopenwebui · open_webuiEPSS 0.43%via NVD
CVE-2026-70482High· 8.1
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{provider}/token/exchange accepts a raw provider access token and validates it b…

▾ Twilightopenwebui · open_webuiEPSS 0.57%via NVD
CVE-2026-70483Low· 3.1
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, DELETE /api/v1/chats/{id} cancelled a chat's in-flight tasks before checking whether the caller could delete that chat. Any au…

▾ Sunlitopenwebui · open_webuiEPSS 0.46%via NVD
CVE-2026-70480Medium· 4.1
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.34 until 0.11.0, Open WebUI renders vega and vega-lite fenced code blocks in chat content by building a Vega view in the viewer browser withou…

▾ Sunlitopenwebui · open_webuiEPSS 0.35%via NVD
CVE-2026-70484Medium· 4.3
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legacy chat-completions features block trusted a client-supplied image_generation flag and did not re-check the features.i…

▾ Sunlitopenwebui · open_webuiEPSS 0.41%via NVD
CVE-2026-70485High· 7.1
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebUI checked whether a user-supplied URL destination was globally routable by applying ipaddress.is_global to the litera…

▾ Twilightopenwebui · open_webuiEPSS 0.35%via NVD
CVE-2026-70486High· 8.2
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allow-same-origin together with allow-scripts for HTML files s…

▾ Twilightopenwebui · open_webuiEPSS 0.38%via NVD
CVE-2026-70488Medium· 4.3
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync cleanup endpoint authorized write access to the knowledge base in the URL but then acted on directory and file ids su…

▾ Sunlitopenwebui · open_webuiEPSS 0.37%via NVD
CVE-2026-70487Medium· 5.3
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline direct model metadata accepted client-supplied knowledge attachments without filtering them against the caller's read a…

▾ Sunlitopenwebui · open_webuiEPSS 0.42%via NVD
CVE-2026-54020Medium· 6.3
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.0, Open WebUI resolved a hostname during URL validation and rejected private, loopback, and link-local addresses, but the HTTP clients re…

▾ Sunlitopenwebui · open_webuiEPSS 0.25%via NVD
CVE-2026-70475Medium· 6.5
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1/executions/:id endpoint in packages/server/src/routes/executions/index.ts lacks the checkAnyPermission() middleware …

▾ Sunlitflowiseai · flowiseEPSS 0.46%via NVD
GHSA-8gj2-2cvc-6xx7Medium
1mo ago

Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials

Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials

▾ Sunlitflowise · flowisevia GHSA
CVE-2026-70476High· 8.2
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.route.ts and packages/server/src/enterp…

▾ Twilightflowiseai · flowiseEPSS 0.52%via NVD
CVE-2026-70477Critical· 9.8
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with a malicious Python script that bypass…

▾ Midnightflowiseai · flowiseEPSS 0.81%via NVD
CVE-2026-70478Critical· 10.0
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint is included in WHITELIST_URLS and requires no authentication. The …

▾ Midnightflowiseai · flowiseEPSS 0.61%via NVD
CVE-2026-70479High· 7.7
1mo ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, with WEB_LOADER_ENGINE=playwright, the Playwright web loader validates only the top-level page request and lets sub-resource r…

▾ Twilightopenwebui · open_webuiEPSS 0.47%via NVD
CVE-2026-70471Medium· 6.5
1mo ago

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise injects $vars into the code execution sandbox without requiring variables:view, bypassing the permission-protecte…

▾ Sunlitflowiseai · flowiseEPSS 0.41%via NVD
GHSA-88pr-878c-24wfHigh
1mo ago

Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys

Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys

▾ Twilightflowise-components · flowise-componentsvia GHSA
CVE-2026-69264Critical· 9.8
1mo ago

Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that is then executed by Pyodide

Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that is then executed by Pyodide. Because Pyodide is loaded with the default js bridge to gl…

▾ Midnightflowiseai · flowiseEPSS 1.1%via NVD
CVE-2026-70472High· 8.8
1mo ago

Flowise is a drag & drop user interface to build a customized large language model flow

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assistants-vector-store endpoints accept a client-controlled credential parameter and load credentials by id without …

▾ Twilightflowiseai · flowiseEPSS 0.52%via NVD
CVE-2026-70473High· 8.5
1mo ago

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert history instead of being scoped to the requestin…

▾ Twilightflowiseai · flowiseEPSS 0.45%via NVD
GHSA-rwrp-9823-p2xqMedium· 6.5
1mo ago

Flowise: Incomplete Credential Redaction Exposes Secrets via API

Flowise: Incomplete Credential Redaction Exposes Secrets via API

▾ Sunlitflowise · flowisevia GHSA
CVE-2026-70474High· 8.1
1mo ago

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise has three OAuth2 credential endpoints that look up credentials by id alone with no workspaceId filter. The author…

▾ Twilightflowiseai · flowiseEPSS 0.48%via NVD
CVEs tagged “ghsa” — page 54 · VulnSea