Database/AI/ML frameworks & serving
Jupyter Server Proxy: Unauthenticated web access to a user's proxied processes
CVSS 9.6CVE-2024-35225AI/ML frameworks & servingcurated
Impact
Unauthenticated web access to a user's proxied processes
Who can reach it
Network attacker reaching the hub
What to do
Upgrade
References
Related entries
- Jupyter Server Proxy: Authentication weakness in proxied-process accessCVE-2024-28179 · Jupyter Server ProxyCritical
- Langflow OSS: submitted components run arbitrary Python as root on the serverCVE-2026-12944 · IBM Langflow OSS (component code validation / sandbox)Critical
- Transformers: LightGlue config re-enables trust_remote_code from the model repo, executing repo code at loadCVE-2026-5241 · Hugging Face Transformers 5.2.0 (LightGlue config loading, trust_remote_code propagation)Critical
- GitLab MCP server: attacker-supplied API URL header exfiltrates the configured GitLab tokenCVE-2026-61559 · @zereight/mcp-gitlab MCP server (X-GitLab-API-URL dynamic base URL)Critical
- GitLab MCP server: DNS rebinding reaches the Streamable HTTP endpoint from a web pageCVE-2026-61568 · @zereight/mcp-gitlab MCP server (Streamable HTTP endpoint, Host/Origin validation)Critical
- Gradio: Remotely triggerable local file include via a JSON value in an API requestCVE-2024-0964 · GradioCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.