tag
Llm
Critical
Flowise CustomMCP Unauthenticated Remote Code Execution via Function() Constructor (CVE-2025-59528)
CVE-2025-59528·
Flowise (FlowiseAI/Flowise)
patched
High
OpenWebUI "Tools" Unsandboxed exec() Remote Code Execution — CVE-2026-0766
CVE-2026-0766 (ZDI-26-032, GHSA-cggw-334c-f4mj)·
OpenWebUI (self-hosted LLM web interface)
unpatched