Database/AI/ML frameworks & serving

ClearML API server: CSRF against the API server
CVSS 9.6CVE-2024-24593AI/ML frameworks & servingcurated
Impact
CSRF against the API server
Who can reach it
Logged-in operator visiting a malicious page
What to do
Upgrade
References
Related entries
- llama-cpp-python: RCE via Jinja2 template in a GGUF model's metadata (`Llama` class)CVE-2024-34359 · llama-cpp-pythonCritical
- Jupyter Server Proxy: Unauthenticated web access to a user's proxied processesCVE-2024-35225 · Jupyter Server ProxyCritical
- Langflow OSS: submitted components run arbitrary Python as root on the serverCVE-2026-12944 · IBM Langflow OSS (component code validation / sandbox)Critical
- Transformers: LightGlue config re-enables trust_remote_code from the model repo, executing repo code at loadCVE-2026-5241 · Hugging Face Transformers 5.2.0 (LightGlue config loading, trust_remote_code propagation)Critical
- GitLab MCP server: attacker-supplied API URL header exfiltrates the configured GitLab tokenCVE-2026-61559 · @zereight/mcp-gitlab MCP server (X-GitLab-API-URL dynamic base URL)Critical
- GitLab MCP server: DNS rebinding reaches the Streamable HTTP endpoint from a web pageCVE-2026-61568 · @zereight/mcp-gitlab MCP server (Streamable HTTP endpoint, Host/Origin validation)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.