VulnWatch VulnWatch
← Back to dashboard
#

Auth Bypass

164 entries

Every Auth Bypass entry VulnWatch has indexed, sorted by publication date.

Subscribe to this tag's RSS feed

Critical github

mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete

## Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete ### Summary All HTTP routes under `/api/documents/*` in `mcp-memory-service` are served without an...

Prompt Injection Auth Bypass Agentic / MCP prompt injection transformers huggingface ai agent pytorch
9.8
CVSS
1 month ago
High nvd

CVE-2026-58169: Vibe-Trading before 0.1.10 contains a DNS rebinding authentication bypass vulnerability that allows remote attackers to

Vibe-Trading before 0.1.10 contains a DNS rebinding authentication bypass vulnerability that allows remote attackers to bypass bearer-token authentication by exploiting the server's trust of TCP peer...

7.7
CVSS
1 month ago
Medium osv

LiteLLM: Authentication Bypass via Host Header Injection

### Impact A Host-header parsing flaw in the LiteLLM proxy could, under specific conditions, allow unauthenticated access to protected management routes. The auth layer derived the effective route...

4.0
CVSS
1 month ago
Low osv

MLflow Use of Default Password Authentication Bypass Vulnerability

This vulnerability allows remote attackers to bypass authentication on affected installations of MLflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within...

3.0
CVSS
1 month ago
Low osv

mlflow: FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization

In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the lates...

3.0
CVSS
1 month ago
Medium osv

LiteLLM: Authentication bypass via OIDC userinfo cache key collision

### Impact When JWT authentication is enabled (`enable_jwt_auth: true`), the OIDC userinfo cache uses `token[:20]` as the cache key. JWT headers produced by the same signing algorithm generate ident...

4.0
CVSS
1 month ago
Low osv

Mlflow: Command Injection when serving models with enable_mlserver=True

A command injection vulnerability exists in Mlflow when serving a model with `enable_mlserver=True`. The `model_uri` is embedded directly into a shell command executed via `bash -c` without proper san...

3.0
CVSS
1 month ago
Critical github

Relyra SAML SignatureValue not cryptographically verified -> authentication bypass

## Summary Relyra `1.0.0` and `1.1.0` accept forged SAML signatures because `SignatureValue` was not cryptographically verified before the library returned a successful authentication result. ## Det...

Auth Bypass adversarial
9.1
CVSS
1 month ago
Critical nvd

CVE-2025-71336: Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnera

Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnerability in the Custom MCP feature, which is designed to execute OS commands such...

9.3
CVSS
1 month ago
High nvd

CVE-2026-12112: A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated

A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated attackers to hijack active administrative sessions due to an improper cache of a...

7.8
CVSS
1 month ago
Medium nvd

CVE-2026-54021: Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, sever

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, several direct, index-addressed Ollama proxy routes accept a caller-supplied url_idx...

6.3
CVSS
1 month ago
Low osv

PYSEC-2026-226

vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authenticat...

3.1
CVSS
1 month ago
Critical nvd

CVE-2026-48746: vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in AS

vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authenticat...

Auth Bypass large language model openai vllm llm
9.1
CVSS
1 month ago
High github

Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF

## Title **Chat Identity Link Hijacking — Attacker Can Silently Map Their Slack/Discord Identity to Any Authenticated Budibase User's Account** ## Severity **High** — CVSS 3.1: AV:N/AC:L/PR:L/UI:R/...

7.3
CVSS
1 month ago
Critical github

scimPatch vulnerable to prototype pollution via unfiltered keys in patch

## Summary `scim-patch` performs prototype pollution when applying a SCIM PATCH operation whose `value` object contains a key like `"__proto__.someProp"`. After one such patch, `Object.prototype.some...

9.1
CVSS
1 month ago
Low github

Inspektor Gadget: Unprivileged container can crash USDT note parser via crafted ELF (no shipped gadget affected)

## Summary A malicious container can crash or destabilize the privileged Inspektor Gadget process when a **gadget using USDT probes** is deployed. The vulnerability is in the USDT note parser (`pkg/u...

Auth Bypass adversarial
0.0
CVSS
1 month ago
Critical nvd

CVE-2026-10561: IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with

IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arb...

Auth Bypass langflow
10.0
CVSS
1 month ago
High github

@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized --workspace Argument

## Summary A command injection vulnerability exists in `@cyclonedx/cyclonedx-npm` when the CLI is invoked with the `--workspace ` option while the environment variable `npm_execpath` is unset or empty...

0.0
CVSS
1 month ago
High github

AgenticMail: Cross-agent task authorization bypass in AgenticMail API

## Summary A low-privileged authenticated AgenticMail agent can enumerate another agent's pending/claimed tasks by supplying the target agent name to `GET /api/agenticmail/tasks/pending?assignee=`. T...

0.0
CVSS
1 month ago
Critical github

PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation

## Summary The `multiedit` tool in `src/praisonai/praisonai/tools/multiedit.py` allows LLM-controlled arbitrary file read and write without any path validation, workspace boundary check, or protected...

9.1
CVSS
1 month ago
High github

npm PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation

## Summary The published npm package `praisonai` exports an `MCPSecurity` helper described in source as: ```text MCP Security - Authentication, authorization, and rate limiting Provides security pol...

8.2
CVSS
1 month ago
Critical github

PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai

# Unauthenticated PraisonAI UI MCP connect endpoint executes attacker-chosen local commands ## Summary PraisonAI v4.6.48 exposes the PraisonAIUI MCP client management API through the default UI host...

9.8
CVSS
1 month ago
Critical github

PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints

# PraisonAI `AgentTeam.launch()` exposes unauthenticated remote agent invocation endpoints ## Summary PraisonAI's documented Python `AgentTeam.launch()` / `Agents.launch()` HTTP server starts extern...

9.8
CVSS
1 month ago
High github

Docker MCP Gateway: Argument injection via OCI image label YAML

## Summary A maliciously crafted OCI image label can inject arbitrary arguments into the `docker run` command line constructed by the MCP Gateway. An attacker who controls an image that the victim re...

0.0
CVSS
1 month ago
Medium github

Open WebUI: Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameter

## Summary Several direct, index-addressed Ollama proxy routes accept a caller-supplied `url_idx` path parameter and use it as a raw index into the admin-configured `OLLAMA_BASE_URLS` list. Access co...

6.3
CVSS
1 month ago