FIX LIBRARY
Lock it down
Plain-English fixes for the most common AI-stack exposures. Risk, steps, verify command.
- CRITICAL Ollama API open to the internet
- CRITICAL n8n instance open — settings or owner-setup reachable without login
- HIGH Open WebUI reachable from the internet
- HIGH vLLM API open to the internet
- MEDIUM Langfuse reachable from the internet
- CRITICAL ComfyUI open to the internet
- CRITICAL Ray dashboard open to the internet
- CRITICAL n8n CVE-2026-21858 (Ni8mare) — unauthenticated file read / RCE
- CRITICAL Ollama CVE-2024-37032 (Probllama) — remote code execution
- CRITICAL ComfyUI-Manager CVE-2025-67303 — unauthenticated RCE
- CRITICAL Open WebUI CVE-2026-44551 — LDAP empty-password auth bypass
- MEDIUM Langfuse CVE-2025-64504 — cross-organization user enumeration
- MEDIUM Langfuse CVE-2026-41487 — member role can steal LLM provider keys
- CRITICAL vLLM CVE-2026-22778 — remote code execution via video endpoints
- MEDIUM vLLM CVE-2026-54236 — memory addresses leaked in error messages
- CRITICAL Langflow CVE-2026-33017 — unauthenticated RCE via public flow build
- CRITICAL Qdrant vector database open without authentication
- HIGH Qdrant gRPC data plane (:6334) accepts connections
- HIGH Milvus vector database exposed to the internet
- HIGH Milvus gRPC data plane (:19530) accepts connections
- CRITICAL Dify console exposed to the internet
- CRITICAL AnythingLLM open without authentication
- CRITICAL Jupyter notebook server exposed
- HIGH Gradio app exposed to the internet
- HIGH Langflow instance exposed to the internet
- CRITICAL Flowise agent builder / public chatflows exposed
- CRITICAL Chroma vector database open without authentication
- CRITICAL Weaviate vector database open without authentication
- HIGH Weaviate gRPC data plane (:50051) accepts connections
- CRITICAL Redis management console exposed to the internet
- CRITICAL n8n CVE-2025-68613 — authenticated RCE via expression injection
- CRITICAL Langflow CVE-2025-3248 — unauthenticated RCE
- CRITICAL Langflow CVE-2026-0770 — unauthenticated RCE via exec_globals
- CRITICAL Langflow CVE-2026-55255 — IDOR lets users run (and loot) other users' flows
- CRITICAL Langflow CVE-2025-34291 — session hijack to RCE via CORS misconfiguration
- MEDIUM n8n CVE-2026-65014 — n8n: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webh
- HIGH n8n CVE-2026-65015 — n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool
- HIGH n8n CVE-2026-65016 — n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owne
- MEDIUM n8n CVE-2026-65589 — n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution
- MEDIUM n8n CVE-2026-65590 — n8n: computer-use Shell Sandbox Not Enforced on Linux and Windows
- HIGH n8n CVE-2026-65591 — n8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Ex
- HIGH n8n CVE-2026-65592 — n8n: Stored DOM XSS via Resource Locator `cachedResultUrl`
- MEDIUM n8n CVE-2026-65593 — n8n: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Ne
- MEDIUM n8n CVE-2026-65594 — n8n: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows vi
- HIGH n8n CVE-2026-65595 — n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assig
- MEDIUM n8n CVE-2026-65596 — n8n: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction
- HIGH n8n CVE-2026-65597 — n8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
- HIGH n8n CVE-2026-65598 — n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remo
- MEDIUM n8n CVE-2026-65599 — n8n: Google Service Account Private Key Exposed in JWT Header
- CRITICAL LangServe chain API exposed without authentication
- CRITICAL OpenClaw control plane exposed to the internet
- CRITICAL OpenHands agent server exposed to the internet
- HIGH OpenAI-compatible API exposed without authentication
- CRITICAL AutoGen Studio agent API exposed without authentication
- HIGH CrewAI Studio exposed to the internet
- CRITICAL MCP server exposed without authentication
- HIGH MLflow tracking UI/API reachable without authentication
- HIGH LiteLLM proxy reachable without a master key
- HIGH Kubeflow dashboard reachable without authentication
- HIGH LM Studio local API reachable without authentication