PoC Archive PoC Archive

tag

Fastapi

Critical
Ormar ORM SQL Injection via min()/max() Aggregate Methods (CVE-2026-26198)
CVE-2026-26198 (GHSA-xxh2-68g9-8jqr)· Ormar (async Python ORM, commonly used with FastAPI/Starlette) patched
Critical
LiteLLM Proxy Unauthenticated Auth Bypass via Host-Header Route Confusion (CVE-2026-49468)
CVE-2026-49468· LiteLLM (BerriAI) proxy patched
High
AutoGPT Platform Chat Session IDOR / Session Hijack — CVE-2026-30950
CVE-2026-30950 (GHSA-q58p-v9r9-7gqj)· AutoGPT Platform (autogpt-platform-backend, chat/copilot feature) unpatched