TOAST-Research/pocs

TOAST-Research/pocs

Releases0

CVE History

CVEPublishedCVSS v3CVSS v2
4.3 MEDIUM

open-webui v0.6.33 is vulnerable to Incorrect Access Control. The API /api/tasks/stop/ directly accesses and cancels tasks without verifying user ownership, enabling attackers (a normal user) to stop arbitrary LLM response tasks.

7.5 HIGH

Directory Traversal vulnerability in ComposioHQ v.0.7.20 allows a remote attacker to obtain sensitive information via the _download_file_or_dir function.