VulnWatch VulnWatch
← Back to dashboard
#

Remote Code Execution

654 entries

Every Remote Code Execution entry VulnWatch has indexed, sorted by publication date.

Subscribe to this tag's RSS feed

Critical github

Flowise RCE via SQLite Record Manager Node

============================================================================= Security Advisory...

0.0
CVSS
1 month ago
Critical github

Flowise: Remote Code Execution Vulnerability in CSVAgent

### Summary The CSVAgent node was observed to allow users to write Python code which gets executed via `pyodide`. The original intent was to allow users to utilise the `pandas` library for CSV proces...

0.0
CVSS
1 month ago
Critical github

Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified

## UPDATE 2026-05-20: Full RCE as root VERIFIED **This is not theoretical — a Meterpreter reverse shell session as root has been established on Flowise 3.1.2.** ### Verified Exploit Chain 1. Python...

Remote Code Execution claude code claude llm
0.0
CVSS
1 month ago
Critical github

Flowise Sandbox Escape to RCE

============================================================================= Security Advisory...

Remote Code Execution Agentic / MCP large language model function calling openai gpt-4 gpt-5 groq llm
0.0
CVSS
1 month ago
Critical github

Flowise RCE via TypeORM DataSource

============================================================================= Security Advisory...

0.0
CVSS
1 month ago
High Actively Exploited cisa_kev

IBM Langflow Code Injection Vulnerability

Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.

9.8
CVSS
1 month ago
High nvd

CVE-2026-66065: Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to

Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. Versions prior to 0.42.1 have an incomplete denylist. Severa...

8.4
CVSS
1 month ago
Critical nvd

CVE-2026-68770: sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code e

sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code execution by exploiting a logic flaw in the import_module_class helper within sen...

9.3
CVSS
1 month ago
Critical nvd

CVE-2026-17351: The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_qu

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlparse, as exactly one non-transaction-control statemen...

9.4
CVSS
1 month ago
Medium github

@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification

### Summary A template injection vulnerability in the `create_workflow_for_notification` tool lets a caller embed Jinja2 expressions that the Dynatrace workflow engine evaluates at runtime, exfiltrati...

4.2
CVSS
1 month ago
High nvd

CVE-2026-61536: Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool J

Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool JSON objects from the rendered body of {% completion %} blocks and later resolves...

7.5
CVSS
1 month ago
Unknown nvd

CVE-2026-15976: SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically wi

SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically within the /update_weights_from_disk, where torch.load(..., weights_only=False) fa...

Remote Code Execution huggingface sglang
1 month ago
Unknown nvd

CVE-2026-15971: SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when D

SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when DUMPER_SERVER_PORT is set, enabling code execution on inference requests.

1 month ago
Unknown nvd

CVE-2026-15969: SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denyl

SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denylist, allowing arbitrary command execution through crafted base64-encoded pickle...

1 month ago
Critical nvd

CVE-2026-12940: IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable

IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability...

Remote Code Execution Agentic / MCP model context protocol langflow
9.8
CVSS
1 month ago
High nvd

CVE-2026-47858: Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running applicati

Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products...

8.0
CVSS
1 month ago
Unknown rss_thehackernews

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated rem...

Remote Code Execution claude code anthropic openai claude
1 month ago
High github

Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF)

### Summary The Budibase AI chat-link handoff flow (`GET/POST /api/chat-links/:instance/:token/handoff`) binds an **external chat identity** (Slack/Discord/MS Teams/Telegram) to a **Budibase user acc...

7.7
CVSS
1 month ago
Medium github

Open WebUI: Arena task endpoints can bypass underlying model access controls

## Summary An authenticated non-admin user with read access to an arena wrapper model can reach a restricted underlying model through task endpoints such as `/api/v1/tasks/moa/completions`. The norm...

5.4
CVSS
1 month ago
Critical github

Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer

## Summary The TypeScript Nunjucks renderer evaluated untrusted `.prompty` template bodies with unrestricted JavaScript member access. An attacker-controlled template could traverse constructor and pr...

10.0
CVSS
1 month ago
Medium osv

Ray: Arbitrary code execution via ray.data.read_webdataset default decoder: pickle.loads(value) and torch.load(weights_only=False)

## Summary `ray.data.read_webdataset(paths=...)` is a `@PublicAPI(stability="alpha")` reader for WebDataset-format TAR files. Its default `decoder=True` invokes `_default_decoder` on every sample's k...

4.0
CVSS
1 month ago
Critical nvd

CVE-2026-50517: Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

9.9
CVSS
1 month ago
Critical nvd

CVE-2026-65700: h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthentica

h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbitrary files accessible to th...

9.3
CVSS
1 month ago
Medium osv

LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks

### Impact LiteLLM's Custom Code Guardrails production create/update paths did not apply the same sandboxing and validation used by the test endpoint. A privileged user with access to create or upda...

4.0
CVSS
1 month ago
Medium osv

LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks

### Impact LiteLLM's Custom Code Guardrails production create/update paths did not apply the same sandboxing and validation used by the test endpoint. A privileged user with access to create or upda...

4.0
CVSS
1 month ago