tag
Exec
High
OpenWebUI "Tools" Unsandboxed exec() Remote Code Execution — CVE-2026-0766
CVE-2026-0766 (ZDI-26-032, GHSA-cggw-334c-f4mj)·
OpenWebUI (self-hosted LLM web interface)
unpatched
Critical
Langflow Unauthenticated Remote Code Execution via `validate/code` Endpoint (CVE-2026-0770)
CVE-2026-0770·
Langflow (AI workflow builder)
patched