2026-08-25
A malicious site can send unauthenticated requests to the local MCP server and trigger actions in the victim's browser session.
HIGH
GHSASUPPLY-CHAINCVE-2026-45019LLM07:2025 System Prompt Leakage
2026-08-25
Unauthenticated users can make the server reach internal services or metadata endpoints and send attacker-controlled headers.
2026-08-20
Unsanitized MongoDB filters can expose other tenants' data through operator injection in affected methods.
2026-08-25
A malicious MCP client or injected page can write attacker-controlled files to arbitrary paths, which can lead to host code execution.
HIGH
NVDSUPPLY-CHAINCVE-2026-82275
2026-08-28
Unauthenticated attackers can read arbitrary server files via path traversal, exposing secrets, config, or user data.
HIGH
NVDSUPPLY-CHAINCVE-2026-82288
2026-08-28
Unauthenticated users can read cleartext login credentials and then access the Stable Diffusion WebUI interface.
HIGH
NVDSUPPLY-CHAINCVE-2026-82268
2026-08-28
Unauthenticated SSRF can hit internal services and expose fetched data through document parsing output.
HIGH
NVDSUPPLY-CHAINCVE-2026-37237
2026-08-28
A remote user can crash or starve a vLLM service by forcing it to read oversized media into memory.