Unauthenticated Remote Code Execution on windows-hosted servers
Security advisories
Every advisory the tracked projects have published, newest first, with the release that carries the fix. Severity is the one its publisher assigned. Nothing here is our judgement.
- Advisories
- 640across 21 products
- critical
- 48
- high
- 242
- medium
- 304
- low
- 46
- Newest
- 25 Aug 20262 days ago
An advisory is listed only when its publisher has published it with an identifier. Release notes that use the word security without one are not listed here, because a security page is worth reading only if every line on it can be checked. 545 of these carry a CVE, and 340 are matched to the release in the archive that fixed them.
Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
Unauthenticated audio decompression-bomb DoS in /v1/chat/completions: VLLM_MAX_AUDIO_DECODE_DURATION_S guard not wired into the chat audio path (sibling of CVE-2026-5497)
IDOR in AppMCPServer PUT Endpoint Allows Modification of Other Apps' MCP Servers
Insights API Missing Per-Project Authorization Exposes Workflow Names and Execution Stats Across Projects
Legacy Request Helper SSRF Check Validates uri While Axios Dispatches url
Strapi, SeaTable, and Mailcheck Nodes Leak Decrypted Credential Secrets into Persisted Execution Error Data
Gmail and Brevo nodes accept non-string content, enabling local file read and SSRF
Expression Sandbox Escape via $fromAI Prototype Leak Leads to Host RCE
Git Node Remote Code Execution via Incomplete Repository-Local Configuration Neutralization
Query Injection in Elasticsearch and Google Cloud Firestore Nodes via Unescaped Expression Interpolation
Shared-Workflow Editor Can Exfiltrate Credentials via Workflow Tool Node Inline Sub-Workflow
Expression Sandbox SpreadElement Bypass Enables Persistent Cross-Evaluation Native Object Mutation
SSRF + arbitrary local file read in MiMoV2OmniMultiModalProcessor `_fetch_image` and audio loader bypass MediaConnector protections
Cross-User Data Leak Vulnerability
vLLM Unauthenticated Requests Exploit DeepStream Backend Confusion for DoS
SSRF Protection Bypass via SearXNG Tool Allows Member Users to Read Internal Service Responses
Code execution in the n8n Git node via unchecked repository-local git configuration
Sandbox Escape in JavaScript Code Node via Prototype Pollution
ReDoS in Filter and Switch Node Regex Matching Allows Worker Denial of Service
GraphQL Node Allowed-Domains Bypass Permits Restricted Credential Exfiltration
Snowflake Node Arbitrary File Read and Write via Client-Side Commands
Custom-role deletion's reassignment path bypasses project-scoped authorization
JavaScript Task Runner VM Sandbox Escape via EventEmitter Prototype Pollution Leads to Remote Code Execution
GraphQL Node Raw Error Re-throw Leaks Decrypted Credential Headers into Persisted Execution Data
Resource Locator Link Preview Expression Injection Allows Cross-User Script Execution
Edit Image Node Injection Enables Blind SSRF
MCP create_workflow_from_code Accepts Cross-Project Credentials When Auth Type Is an Expression
Form Node Completion Page Sandbox CSP Bypass Leads to Stored XSS
Supabase Node PostgREST Filter Injection in Row Get Many, Delete, and Update Operations
MongoDB Node NoSQL Injection in Find, Delete, and Aggregate Operations via Unescaped Expression Interpolation
SSRF Protection Bypass via OAuth2 Credential Token Exchange Reflects Internal Response Body
RCE in the n8n Main Process via Path Traversal in MCP Node-Schema Loading
Any authenticated user can reach internal services via DNS rebinding on server-side URL fetches
Cross-user file content disclosure via request-scoped direct model knowledge metadata
Deletion of directories and file embeddings in other knowledge bases via sync cleanup
Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check
Users denied the image-generation permission can still generate images via chat completions
Stored XSS via unescaped KaTeX render-error fallback in rendered messages
Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite chart rendering
Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
Tool source code disclosed to read-only users via the tool list and get endpoints
Any authenticated user can cancel another user's chat generation via the chat delete endpoint
A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder
SSRF into internal services via unvalidated sub-resource requests in the Playwright web loader
Any authenticated user can reach internal services and cloud metadata via NAT64-encoded URLs
Any member with write access to a standard channel can edit or delete other members' messages
Instance-wide stall via automation recurrence rules that force multi-second parsing
Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically
Account takeover via OAuth token exchange accepting tokens issued to any client
Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
Completion prompt lists fan out into unbounded engine requests
Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances
Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`
Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base Directory
Account Takeover via Unverified Email Claim in Token Exchange Embed Login
Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes
Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction
Prototype Pollution via VM Expression Engine Sandbox Escape Leads to Code Execution
SSRF Protection Bypass via MCP Client Node
Authenticated code execution in the n8n Git node
Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
Expression sandbox escape via arrow-function bodies enabling command execution
Cross-Tenant Module-Cache Poisoning in the JS Task Runner
Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON
Edit Image Node Format Injection Allows Arbitrary File Write
Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service
Unauthenticated disclosure of internal Server Function endpoints
Denial of Service in the Image Optimization API using SVGs
Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
Denial of Service in App Router using Server Actions
Middleware / Proxy bypass in App Router applications using Turbopack and single locale
Cache confusion of response bodies for requests with bodies
Server-Side Request Forgery in Server Actions on custom servers
Unbounded Server Action payload in Edge runtime
Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
Denial of Service in Server Functions
Cross-site scripting via unescaped transition:* directive values on hydrated islands
XSS via unescaped spread attribute names in custom element rendering
composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered
Unauthenticated path override in the @astrojs/vercel ISR function
Reflected XSS via unescaped View Transition animation properties
Backslash-prefixed paths not recognized as internal by trailing-slash redirect in @astrojs/node
XML injection in @astrojs/rss via unescaped source and enclosure fields
@astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped
Cross-Tenant External API Detail Disclosure
Cross-Tenant External API Usage Enumeration
Cross-Tenant File Preview via Unscoped Console `file_id`
Google Service Account Private Key Exposed in JWT Header
Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution
DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction
Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs
Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check
Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
Stored DOM XSS via Resource Locator `cachedResultUrl`
Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
computer-use Shell Sandbox Not Enforced on Linux and Windows
Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
AI Agents Project Viewer Privilege Escalation via run_node_tool
Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook
ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends
Remote DoS in vLLM via Invalid Recovered Token Reinjection
DoS caused by sending `/v1/completions` with prompt embeds payload with models that use M-RoPE
Speech-to-text upload size limit is enforced after full UploadFile read
Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)
/api/v1/channels/{id}/members exposes full user model including sensitive credentials
`WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)
Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
Private channel messages can be disclosed through cross-channel thread parent_id binding
Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)
Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
Model meta.knowledge read-only file access can be upgraded to file write/delete
Arena task endpoints can bypass underlying model access controls
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch
Account enumeration via observable login timing discrepancy
Same-origin Pyodide code execution allows server-side RCE via a shared chat
ReDoS in skill-mention regexes causes whole-instance DoS on default config
POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
Scheduled automations continue after pending-user deactivation and stored model ACL revocation
Shared Credential Header Leak via HTTP Request Pagination Expression
External Secrets Permission Bypass via Expression Parser Mismatch
Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
MySQL v1 Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration
"Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector
External Secrets Accessible via Workflow Expressions Outside Credentials
Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects
Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads
Denial of service via non-ASCII bytes in WebSocket response headers
Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution
Reflected XSS via unescaped slot name
@astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN config
XSS via Unescaped Attribute Names in Spread Props
Host header SSRF in prerendered error page fetch
Path traversal and sandbox escape in LangChain file-search middleware and loaders
vLLM image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations
GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving
OOM Denial of Service via Audio Decompression Bomb
temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels
vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router (CWE-532)
SSRF Protection Bypass in Playwright Web Loader via HTTP Redirects
Path traversal / SSRF in terminal server proxy via encoded path traversal
Any authenticated user can read other users' private notes via Socket.IO
Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameter
Cross-origin postMessage confirmation bypass via action:submit
Stored XSS in Mermaid Markdown Preview
IDOR: Calendar event re-parenting allows writing events into another user's calendar
Cross-user file disclosure via /api/chat/completions image_url field
Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling of CVE-2026-45401)
Stored XSS to Account Takeover via Model Profile Images in Open WebUI
RAG ACL Bypass in Milvus Multitenancy Mode
Forged chat-file link allows cross-user file read and deletion
Forged model meta.knowledge allows cross-user file read and deletion
Prompt history IDOR: unbound history_id allows cross-prompt read and deletion
Sibling-Prefix Path Traversal via /cache/{path} in open-webui/open-webui
Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration
Artifact Pin Decay in vLLM allows pinned deployments to load unpinned code, weights, and processors
Public API Execution Retry Authorization Bypass
Python Code Node AST Validator Bypass
Stored XSS in Chat Trigger Node
Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints
Microsoft SQL Node Prototype Pollution
Merge Node SQL Mode Prototype Pollution
Prototype Pollution enables confused-deputy execution via public webhooks
Same-Origin XSS in Respond to Webhook Node
Missing Token Validation on Microsoft Agent 365 Trigger and Stripe Nodes
Wrong OAuth Scope On Evaluations Test Run Creation Endpoint
NoSQL Injection in MongoDB Node Find And Replace Operation
SQL Injection in Postgres v1/TimesclaeDB Nodes
SecurityScorecard Node Leaks API Token to User-Controlled Host
n8n MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions
Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints
Credential Exfiltration via Permission Bypass
Wrong OAuth Scope on Evaluation Test Runs Endpoints
Denial of Service via ZIP decompression in webhook workflow
Dependency Confusion Vulnerability in vLLM Dockerfile
OpenAI API Auth Bypass
`server.fs.deny` bypass on Windows alternate paths
Git Node Clone and Push Operations Bypass File Sandbox
Python sandbox escape
Command Injection via spawnSync & spawn on Windows
TLS retry copies stale upgrade hook, risking plaintext traffic
BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictions
Miller-Rabin Primality Test Allows Zero Rounds
Deno Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)
Deno Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checks
`fetch()` API sandbox bypass via missing DNS resolution check
WebSocket API sandbox bypass via missing post-DNS check
process.loadEnvFile() bypasses env permission checks and mutates process.env with only read access
Dify API Extension has SSRF Vulnerability
Unauthenticated Server-Side Request Forgery in /console/api/remote-files/upload endpoint
SSR XSS via Insecure Promise Serialization in hydratable
Cross-site scripting via spread attributes in Svelte SSR
ReDoS in `<svelte:element>` Tag Validation
XSS via DOM Clobbering of Internal Framework State
Rate limit bypass on auth routes due to invalid prefix checking
Password Reset Does Not Revoke Existing Refresh Sessions
SQL Injection in Content Type Builder
Upload Plugin MIME Validation Bypass via Content API
Leaking sensitive data via relational filtering due to lack of query sanitization
Legacy ExecuteWorkflow Node Bypassed File Path Restrictions
Credential exfiltration via Allowed HTTP Request Domains Bypass
Arbitrary File Read via Git Node
HTTP Request Node Pagination Prototype Pollution to RCE
Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints
Source Control Pull SQL Injection
XML Node Prototype Pollution Patch Bypass
Indirect Object Reference (IDOR) in user notes
Stored XSS in Banner Component via Improper Sanitization Order
Unauthenticated endpoint can trigger embedding generation (cost/DoS)
shared-chat branch ignores access_type, allowing unauthorized file deletion
Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed
LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts
Sharing models for others to use (read permission) also exposes model details (system prompt leakage)
Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints
Authenticated users can bypass model access control via exposed query parameter [AI-ASSISTED]
Server-Side Request Forgery (SSRF) bypass in `validate_url`
SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)
IDOR: Retrieval API Bypasses Knowledge Base Access Controls
An IDOR vulnerability exists in the update_message_by_id API endpoint
An IDOR vulnerability exists in the pin_channel_message API endpoint
Low-privilege authenticated users can enumerate and stop global background tasks, causing system-wide chat disruption
Stored XSS via OAuth picture claim stored as SVG data URI in profile_image_url
Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code Execution
Unauthenticated RAG Configuration Disclosure
Mass Assignment via FeedbackForm extra=allow Allows Feedback User ID Spoofing and Evaluation Data Manipulation
Full SSRF Vulnerability in the RAG Web Search Feature
Missing authorization check at the model update function - models from other users can be updated
Blind server side request forgery (SSRF) via the PDF generate function
Stored Cross-Site Scripting in SVG Renderer
Broken Access Control for Completions API
Exposure of System Prompt to Regular User [Non-Admin]
Cross-Site Request Forgery (CSRF) via Image URL Manipulation
Chat completion API allows tool restrictions to be bypassed
API key endpoint restrictions bypassed via `x-api-key` header — full message processing on restricted endpoints
SSRF via OAuth Profile Picture URL in _process_picture_url (oauth.py)
XSS via SVG in /api/v1/channels/webhooks/{webhook_id}/profile/image
Stored XSS via unsanitized Office/Excel/DOCX file preview rendering ({@html} without DOMPurify)
Stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions
Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access)
Missing permission check in files API allows authenticated users to list, access and delete every uploaded file
Stored XSS via the HTML renedering view
Stored Cross-Site Scripting In Profile Picture
Server island encrypted parameters vulnerable to cross-component replay
Middleware / Proxy bypass in App Router applications via segment-prefetch routes - Incomplete Fix Follow-Up
Middleware / Proxy redirects can be cache-poisoned
Denial of Service with Server Components
Middleware / Proxy bypass in Pages Router applications using i18n
Cache poisoning in React Server Component responses
Server-side request forgery in applications using WebSocket upgrades
Denial of Service in the Image Optimization API
Middleware / Proxy bypass through dynamic route parameter injection
Denial of Service via connection exhaustion in applications using Cache Components
Cross-site scripting in beforeInteractive scripts with untrusted input
Cache poisoning via collisions in React Server Component cache-busting
Cross-site scripting in App Router applications using CSP nonces
Middleware / Proxy bypass in App Router applications via segment-prefetch routes
Denial of Service Vulnerability in React Server Components
KL-CAN-2024-002
KL-CAN-2024-004: Open WebUI Improper Authorization Control
KL-CAN-2024-005: Open WebUI Arbitrary File Write, Delete via Path Traversal
GitHub Security Lab (GHSL) Vulnerability Report, open-webui: GHSL-2024-174, GHSL-2024-175
Insecure Message Access Breaks Authorization
Inconsistent authorization controls within memories API
Full SSRF with user role on endpoint /api/v1/retrieval/process/web via location redirect
Stored XSS in excel file preview
Improper Authorization in Standard Channels Allows Message Updates with Read Permission
Stored XSS in Pending User Overlay via Incorrect DOMPurify Application Order
responses passthrough endpoint lacks access control authorization
Deactivated Channel Members Retain Full Access to Group/DM Channels
Read-Only Users Can Modify Collaborative Documents via Socket.IO
Missing Access Check on Channel Members Endpoint for Standard Channels
Unauthorized File and Knowledge Base Content Access via RAG Vector Search
Model Import Overwrites Any Model Without Ownership Check
Ollama Model Access Control Bypass via /api/generate, /api/embed, /api/embeddings, and /api/show
LDAP Empty Password Authentication Bypass
Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwrite
Global Knowledge Base Enumeration via knowledge-bases Meta-Collection
Channel Access Grants Bypass filter_allowed_access_grants
Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access
Base Model Routing Bypasses Access Control via Model Chaining
Mass Assignment via Pydantic extra='allow' Allows Creating Folders in Other Users' Accounts
Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning
Unsafe deserialization of attacker-controlled LangChain objects through overly broad `load()` allowlists
Stored XSS via Model Description
extract_hidden_states speculative decoding crashes server on any request with penalty parameters
Remote DoS via Special-Token Placeholders
Open Redirect in MCP OAuth Consent Flow
Python Task Runner Sandbox Escape
SQL Injection in Oracle Database Node via Limit Field