Summary
OpenClaw: MCP Streamable HTTP redirects could forward configured custom headers to another origin
References
Related vulnerabilities
All Supply chain →- CRITICALGHSA-X223-P2GF-V735
Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
- MEDIUMGHSA-FG94-H982-F3MM
Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch
- MEDIUMGHSA-5JV2-G5WQ-CMR4
vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving
- HIGHGHSA-RM2V-H48J-895M
n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host
- HIGHGHSA-2J5H-858J-5MPF
n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints
- HIGHGHSA-F989-C77F-R2CQ
Crawl4AI: LLM credential exfiltration in Docker server via request base_url and env: token resolution