VulnSea

Tagged “pip”

CVEs tagged pip, newest first.

4637 CVEsRSS

CVE-2026-45106Medium· 4.6
4mo ago

Weblate: Stored HTML injection in editor search preview

Weblate: Stored HTML injection in editor search preview

▾ Sunlitweblate · weblateEPSS 0.29%via OSV
CVE-2026-44716High· 7.5
4mo ago

Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File Read via `%2F`-Encoded Separator

Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File Read via `%2F`-Encoded Separator

▾ Twilightpipecat-ai · pipecat-aiEPSS 0.56%via OSV
CVE-2026-45078Medium· 5.5
4mo ago

Synapse CPU starvation (Denial of Service)

Synapse CPU starvation (Denial of Service)

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 0.13%via OSV
CVE-2026-45076Medium
4mo ago

Synapse pagination Denial of Service

Synapse pagination Denial of Service

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 0.39%via OSV
CVE-2026-44513High· 8.8
4mo ago

Diffusers is the a library for pretrained diffusion models

Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows arbitrary remote code execution despite the user passing trust_remote_code=False (or omi…

▾ Twilighthuggingface · diffusersEPSS 0.89%via NVD
CVE-2026-45339Medium· 6.5
4mo ago

Open WebUI's API key endpoint restrictions bypassed via `x-api-key` header — full message processing on restricted endpoints

Open WebUI's API key endpoint restrictions bypassed via `x-api-key` header — full message processing on restricted endpoints

▾ Sunlitopen-webu · open-webuEPSS 0.44%via OSV
CVE-2026-56398High· 7.3
4mo ago

Open WebUI vulnerable to stored XSS via OAuth picture claim stored as SVG data URI in profile_image_url

Open WebUI vulnerable to stored XSS via OAuth picture claim stored as SVG data URI in profile_image_url

▾ Twilightopen-webui · open-webuiEPSS 0.64%via OSV
CVE-2026-44968Medium· 6.3
4mo ago

dbt MCP Server has an Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parameters

dbt MCP Server has an Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parameters

▾ Sunlitdbt-mcp · dbt-mcpEPSS 0.21%via OSV
CVE-2026-45666Medium· 6.5
4mo ago

Open WebUI has an Indirect Object Reference (IDOR) in user notes

Open WebUI has an Indirect Object Reference (IDOR) in user notes

▾ Sunlitopen-webui · open-webuiEPSS 0.39%via OSV
CVE-2026-45385Medium· 4.3
4mo ago

Open WebUI has an IDOR vulnerability in the update_message_by_id API endpoint

Open WebUI has an IDOR vulnerability in the update_message_by_id API endpoint

▾ Sunlitopen-webui · open-webuiEPSS 0.29%via OSV
CVE-2026-45306Medium· 6.5
4mo ago

pyLoad Has Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory in pyLoad

pyLoad Has Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory in pyLoad

▾ Sunlitpyload-ng · pyload-ngEPSS 0.41%via OSV
CVE-2026-45365Medium· 5.4
4mo ago

Open WebUI: Authenticated users can bypass model access control via exposed query parameter [AI-ASSISTED]

Open WebUI: Authenticated users can bypass model access control via exposed query parameter [AI-ASSISTED]

▾ Sunlitopen-webui · open-webuiEPSS 0.27%via OSV
CVE-2026-45396Medium· 5.4
4mo ago

Open WebUI: Mass Assignment via FeedbackForm extra=allow Allows Feedback User ID Spoofing and Evaluation Data Manipulation

Open WebUI: Mass Assignment via FeedbackForm extra=allow Allows Feedback User ID Spoofing and Evaluation Data Manipulation

▾ Sunlitopen-webui · open-webuiEPSS 0.36%via OSV
CVE-2026-45401High· 8.5PoC
4mo ago

Open WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)

Open WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)

▾ Midnightopen-webui · open-webuiEPSS 0.33%via OSV
CVE-2026-45301High· 8.1
4mo ago

Open WebUI: Missing permission check in files API allows authenticated users to list, access and delete every uploaded file

Open WebUI: Missing permission check in files API allows authenticated users to list, access and delete every uploaded file

▾ Twilightopen-webui · open-webuiEPSS 0.39%via OSV
CVE-2026-45402High· 8.1
4mo ago

Open WebUI: Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints

Open WebUI: Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints

▾ Twilightopen-webui · open-webuiEPSS 0.39%via OSV
CVE-2026-45315High· 8.7
4mo ago

Open WebUI has stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions

Open WebUI has stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions

▾ Twilightopen-webui · open-webuiEPSS 0.19%via OSV
CVE-2026-45667Medium· 6.5
4mo ago

Open WebUI: Unauthenticated endpoint can trigger embedding generation (cost/DoS)

Open WebUI: Unauthenticated endpoint can trigger embedding generation (cost/DoS)

▾ Sunlitopen-webui · open-webuiEPSS 0.43%via OSV
CVE-2026-45316Low· 3.5PoC
4mo ago

Open WebUI: Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access)

Open WebUI: Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access)

▾ Twilightopen-webui · open-webuiEPSS 0.26%via OSV
CVE-2026-44970Low· 3.1
4mo ago

dbt MCP Server Transmits All MCP Tool Arguments Including Raw SQL and --vars Credentials to dbt Labs Telemetry by Default Without Redaction

dbt MCP Server Transmits All MCP Tool Arguments Including Raw SQL and --vars Credentials to dbt Labs Telemetry by Default Without Redaction

▾ Sunlitdbt-mcp · dbt-mcpEPSS 0.37%via OSV
CVE-2026-45351Medium· 6.5
4mo ago

Open WebUI Exposes System Prompt to Regular User [Non-Admin]

Open WebUI Exposes System Prompt to Regular User [Non-Admin]

▾ Sunlitopen-webui · open-webuiEPSS 0.39%via OSV
CVE-2026-45317Medium· 4.6
4mo ago

Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF) via Image URL Manipulation

Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF) via Image URL Manipulation

▾ Sunlitopen-webui · open-webuiEPSS 0.15%via OSV
CVE-2026-45318Medium· 5.4
4mo ago

Open WebUI has stored XSS via unsanitized Office/Excel/DOCX file preview rendering ({@html} without DOMPurify)

Open WebUI has stored XSS via unsanitized Office/Excel/DOCX file preview rendering ({@html} without DOMPurify)

▾ Sunlitopen-webui · open-webuiEPSS 0.24%via OSV
CVE-2026-45675High· 8.1
4mo ago

Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts

Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts

▾ Twilightopen-webui · open-webuiEPSS 0.51%via OSV
CVE-2026-45387Medium· 4.3
4mo ago

Open WebUI: Sharing models for others to use (read permission) also exposes model details (system prompt leakage)

Open WebUI: Sharing models for others to use (read permission) also exposes model details (system prompt leakage)

▾ Sunlitopen-webui · open-webuiEPSS 0.31%via OSV
CVE-2026-45345Medium· 6.5
4mo ago

Open WebUI missing authorization check at the model update function - models from other users can be updated

Open WebUI missing authorization check at the model update function - models from other users can be updated

▾ Sunlitopen-webui · open-webuiEPSS 0.34%via OSV
CVE-2026-45349High· 7.1
4mo ago

Open WebUI has Broken Access Control for Completions API

Open WebUI has Broken Access Control for Completions API

▾ Twilightopen-webui · open-webuiEPSS 0.33%via OSV
CVE-2026-45348High· 8.7
4mo ago

pyLoad is vulnerable to stored XSS in Downloads view via unsanitized link URL in packages.js template literal

pyLoad is vulnerable to stored XSS in Downloads view via unsanitized link URL in packages.js template literal

▾ Twilightpyload-ng · pyload-ngEPSS 0.35%via OSV
CVE-2026-45347Medium· 4.3
4mo ago

Open WebUI vulnerable to blind server side request forgery (SSRF) via the PDF generate function

Open WebUI vulnerable to blind server side request forgery (SSRF) via the PDF generate function

▾ Sunlitopen-webui · open-webuiEPSS 0.25%via OSV
CVE-2026-44722Medium· 6.2
4mo ago

pyzipper has an encryption bypass for small files encrypted using it

pyzipper has an encryption bypass for small files encrypted using it

▾ Sunlitpyzipper · pyzipperEPSS 0.12%via OSV
CVEs tagged “pip” — page 57 · VulnSea