CVE MEDIUM CVE-2025-67743

Local Deep Research is Vulnerable to Server-Side Request Forgery (SSRF) in Download Service

CVSS 6.3 local-deep-research View details
CVE MEDIUM CVE-2026-27795

powered applications. Prior to version 1.1.8, a redirect-based Server-Side Request Forgery (SSRF) bypass exists in `RecursiveUrlLoader` in `@langchain/community`. The loader validates the initial URL but allows the underlying

CVE MEDIUM CVE-2025-12058

mode=True, is vulnerable to arbitrary local file loading and Server-Side Request Forgery (SSRF). This vulnerability stems from the way the StringLookup layer is handled during model loading from

CVE MEDIUM CVE-2022-36551

Heartex - Label Studio Community Edition vulnerable to SSRF in the Data Import module

CVSS 6.5 label-studio View details
CVE MEDIUM CVE-2024-48052

gradio <=4.42.0, the gr.DownloadButton function has a hidden server-side request forgery (SSRF) vulnerability. The reason is that within the save_url_to_cache function, there are no restrictions

CVSS 6.5 gradio View details
CVE MEDIUM CVE-2024-4940

exploited for phishing attacks, Cross-site Scripting (XSS), Server-Side Request Forgery (SSRF), amongst others. This issue is due to improper validation of user-supplied input in the handling

CVSS 6.1 gradio View details
CVE MEDIUM CVE-2024-2206

SSRF vulnerability exists in the gradio-app/gradio due to insufficient validation of user-supplied URLs in the `/proxy` route. Attackers can exploit this vulnerability by manipulating the `self.replica_urls

CVSS 6.5 gradio View details

TaskWeaver has Protection Mechanism Failure and Server-Side Request Forgery (SSRF

CVSS 6.5 agentos-taskweaver View details
CVE MEDIUM CVE-2025-68477

Langflow is a tool for building and deploying AI-powered

CVSS 6.5 langflow View details