CRITICAL
GHSASUPPLY-CHAINCVE-2025-8943LLM05:2025 Supply Chain Vulnerabilities
2026-08-04
A patch bypass enables unauthenticated remote code execution on default Flowise deployments via npm_config_yes and npx auto-install.
HIGH
GHSASUPPLY-CHAINLLM06:2025 Sensitive Information Disclosure
2026-08-06
Scoped reads can leak one tenant's stored data into another tenant's results due to namespace boundary failures.
2026-08-04
Any authenticated user may access internal services or cloud metadata through the server, exposing sensitive data and enabling SSRF-style abuse.
2026-08-04
Read-only users can view server-side tool code and exposed secrets, enabling further compromise of shared AI tooling.
2026-08-04
Revoked users can still trigger server-side image generation, bypassing admin policy and consuming restricted AI resources.
MEDIUM
NVDSUPPLY-CHAINCVE-2026-27765
2026-08-11
Authenticated local input validation flaw can crash affected vLLM Gaudi components and reduce service availability.
MEDIUM
NVDSUPPLY-CHAINCVE-2026-14549
2026-08-11
Any logged-in user can change or remove site languages, causing unauthorized configuration changes and possible service disruption.
MEDIUM
NVDSUPPLY-CHAINCVE-2026-14548
2026-08-11
Low-privilege users can replace the translation API token, disrupting service or redirecting translation traffic.