|
881
|
4.3 |
MEDIUM
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI has a Broken Object Level Authorization (BOLA) vulnerability in the built…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-54016
|
2026-06-25 23:31 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
882
|
7.7 |
HIGH
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the SafePlaywrightURLLoader implements a validate_url function to prevent SSRF attac…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-54018
|
2026-06-25 23:30 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
883
|
7.8 |
HIGH
Local
|
-
|
-
|
Warp is an agentic development environment. From 0.2025.04.09.08.11.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command execution policy bypass in Agent code search tools. The affec…
New
|
CWE-78
OS Command
|
CVE-2026-48703
|
2026-06-25 23:29 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
884
|
8.8 |
HIGH
Network
|
-
|
-
|
Warp is an agentic development environment. From 0.2023.10.24.08.03.stable_00 until 0.2026.05.06.15.42.stable_01, Warp may open executable local files through the operating system default file handle…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-48704
|
2026-06-25 23:29 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
885
|
8.0 |
HIGH
Network
|
-
|
-
|
Warp is an agentic development environment. From 0.2025.08.06.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection in the prompt branch selector. A user who can publi…
New
|
CWE-78
OS Command
|
CVE-2026-48719
|
2026-06-25 23:29 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
886
|
8.1 |
HIGH
Network
|
-
|
-
|
Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp allows terminal output to request access to the local system clipboard. A malici…
New
|
CWE-276
Incorrect Default Permissions
|
CVE-2026-48725
|
2026-06-25 23:29 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
887
|
7.8 |
HIGH
Local
|
-
|
-
|
Warp is an agentic development environment. From 0.2024.02.20.08.01.stable_01 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection issue in the Linux external editor launcher. Warp e…
New
|
CWE-78
OS Command
|
CVE-2026-48731
|
2026-06-25 23:29 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
888
|
8.8 |
HIGH
Network
|
-
|
-
|
Warp is an agentic development environment. From 0.2023.03.21.08.02.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection issue in the legacy SSH background command path. Wa…
New
|
CWE-78
OS Command
|
CVE-2026-48732
|
2026-06-25 23:29 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
889
|
7.7 |
HIGH
Local
|
-
|
-
|
Warp is an agentic development environment. From 0.2024.03.12.08.02.stable_01 until 0.2026.05.06.15.42.stable_01, Warp contains an OS command injection vulnerability in the WSL URL-opening fallback. …
New
|
CWE-78 CWE-116
OS Command Improper Encoding or Escaping of Output
|
CVE-2026-54699
|
2026-06-25 23:29 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
890
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Broken Access Control in MainWP Child <= 6.1.1 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-27366
|
2026-06-25 23:29 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|