VulnScope — 以套件為主體的 CVE 查詢工具- HIGH7.5CVE-2026-54695Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
- LOW2.2BBOT: Symlink-Following Arbitrary Write via github_workflows Module
- MEDIUM6.5BBOT: Arbitrary File Write in postman_download Module
- LOW3.1BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing
- MEDIUM5.3BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284
- MEDIUM6.1marimo contains a reflected cross-site scripting vulnerability in the notebook page
- MEDIUM6.0OpenStack Horizon RC file generation does not escape special characters in project names
- HIGH8.4pdfkit: Path traversal in from_string
- MEDIUM5.3Open WebUI: Any authenticated user can read other users' private notes via Socket.IO
- MEDIUM6.3Open WebUI: Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameter
- MEDIUM6.5Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode
- HIGH7.7Open WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP Redirects
- HIGH7.7Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversal
- MEDIUM4.3Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration
- MEDIUM6.4Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion
- MEDIUM4.3Open WebUI: Sibling-Prefix Path Traversal via /cache/{path}
- HIGH7.6Open WebUI: Stored XSS to Account Takeover via Model Profile Images
- HIGH7.1Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion
- HIGH8.7Open WebUI: Stored XSS in Mermaid Markdown Preview
- HIGH8.3Open WebUI: Forged chat-file link allows cross-user file read and deletion
- MEDIUM6.5Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field
- HIGH8.5Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling of CVE-2026-45401)
- MEDIUM4.3Open WebUI IDOR: Calendar event re-parenting allows writing events into another user's calendar
- MEDIUM6.5vLLM: OOM Denial of Service via Audio Decompression Bomb
- MEDIUM4.8vLLM: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations