HIGH
NVDSUPPLY-CHAINCVE-2026-71211
2026-08-05
Any authenticated user may proxy requests to internal services and potentially expose cloud metadata credentials.
HIGH
NVDSUPPLY-CHAINCVE-2026-9081LLM05:2025 Supply Chain Vulnerabilities
2026-08-05
SSRF in Langflow's Ollama provider can let attackers reach internal or private network services through a user-controlled URL.
HIGH
GHSASUPPLY-CHAINLLM02: Sensitive Information Disclosure
2026-08-04
Any authenticated user who knows a file ID can read another user's indexed file content without permission checks.
2026-08-04
Authenticated channel members can alter or delete others' messages, breaking integrity and trust in shared conversations.
2026-08-04
Any authenticated user can trigger regex backtracking that pegs a CPU core and blocks the worker, causing denial of service.
2026-08-04
If enabled, attackers can swap third-party OAuth tokens for a victim's Open WebUI session and take over that account.
2026-08-04
A write collaborator can irreversibly delete another user's chats in shared subfolders when folder sharing is enabled.
HIGH
NVDSUPPLY-CHAINCVE-2026-47487
2026-08-04
Path traversal via model name can expose or alter files outside the repo, causing data disclosure or service disruption.
2026-08-04
Any authenticated user can interrupt another user's active AI tasks, causing denial of service if they know a shared chat ID.