PoC Archive PoC Archive

tag

Llm

Critical
Flowise CustomMCP Unauthenticated Remote Code Execution via Function() Constructor (CVE-2025-59528)
CVE-2025-59528· Flowise (FlowiseAI/Flowise) patched
High
OpenWebUI "Tools" Unsandboxed exec() Remote Code Execution — CVE-2026-0766
CVE-2026-0766 (ZDI-26-032, GHSA-cggw-334c-f4mj)· OpenWebUI (self-hosted LLM web interface) unpatched