Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-16052
  • npm/open-item-validator
Malicious code in open-item-validator (npm) 08 Sep
  • No fix available
MAL-2026-12963
  • npm/bnpl-blocks-independent-bnpl-open-api
Malicious code in bnpl-blocks-independent-bnpl-open-api (npm) 05 Aug
  • No fix available
MAL-2026-12366
  • npm/dolyame-boxy-independent-bnpl-open-api
Malicious code in dolyame-boxy-independent-bnpl-open-api (npm) 05 Aug
  • No fix available
MAL-2026-11183
  • npm/def-open-client
Malicious code in def-open-client (npm) 29 Jul
  • No fix available
MAL-2026-11188
  • npm/open-worker-cli
Malicious code in open-worker-cli (npm) 29 Jul
  • No fix available
MAL-2026-5392
  • npm/@open-banking/cabinet-providers
Malicious code in @open-banking/cabinet-providers (npm) 09 Jun
  • No fix available
MAL-2026-4340
  • npm/wm-plugin-open-teach-me-after-deployable-played
Malicious code in wm-plugin-open-teach-me-after-deployable-played (npm) 25 May
  • No fix available
GHSA-4fg7-f244-3j49
  • npm/@haxtheweb/open-apis
HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis 19 May
  • Fix available
  • Severity - 8.7 (High)
GHSA-cqp4-qqvg-3787
  • npm/open-webui
Open WebUI has Stored XSS in Banner Component via Improper Sanitization Order 14 May
  • Fix available
  • Severity - 8.1 (High)
GHSA-p4fx-23fq-jfg6
  • npm/open-webui
Open WebUI: Missing `workspace.tools` Authorization Check on Tool Update Endpoint Allows Privilege Escalation to Code Execution 14 May
  • Fix available
  • Severity - 7.2 (High)
GHSA-r29h-37fj-x2w6
  • npm/open-webui
Open WebUI Has Stored Cross-Site Scripting in SVG Renderer 14 May
  • Fix available
  • Severity - 5.1 (Medium)
GHSA-gf5m-wcrh-7928
  • PyPI/open-webui
  • npm/open-webui
open-webui Vulnerable to Stored XSS via Model Description 08 May
  • Fix available
  • Severity - 7.3 (High)
MAL-2026-3399
  • npm/money-badger-open-rpc-test-bugbount
Malicious code in money-badger-open-rpc-test-bugbount (npm) 08 May
  • No fix available
MAL-2026-3353
  • npm/money-badger-open-rpc
Malicious code in money-badger-open-rpc (npm) 06 May
  • No fix available
GHSA-v228-72c7-fx8j
  • npm/open-websearch
open-websearch has SSRF in `fetchWebContent` MCP tool: bracketed IPv6 literals and non-resolving hostname check bypass `isPrivateOrLocalHostname` 05 May
  • Fix available
  • Severity - 8.2 (High)
MAL-2026-886
  • npm/open-answer-engine-frontend
Malicious code in open-answer-engine-frontend (npm) 13 Feb
  • No fix available