ZDI-26-037: (0Day) Langflow PythonFunction Code Injection Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Attack vectors and exploitability will vary... 10/01/2026 Zero-Day Initiative
ZDI-26-036: (0Day) Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit... 10/01/2026 Zero-Day Initiative
ZDI-26-035: (0Day) Langflow eval_custom_component_code Eval Injection Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit... 10/01/2026 Zero-Day Initiative
ZDI-26-034: (0Day) Langflow code Code Injection Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit... 10/01/2026 Zero-Day Initiative
ZDI-26-033: (0Day) Open WebUI Cleartext Transmission of Credentials Information Disclosure Vulnerability This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Open WebUI. Authentication is not required to... 10/01/2026 Zero-Day Initiative
ZDI-26-032: (0Day) Open WebUI load_tool_module_by_id Command Injection Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of Open WebUI. Authentication is required to exploit... 10/01/2026 Zero-Day Initiative
ZDI-26-031: (0Day) Open WebUI PIP install_frontmatter_requirements Command Injection Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of Open WebUI. Authentication is required to exploit... 10/01/2026 Zero-Day Initiative
ZDI-26-030: (0Day) GPT Academic upload Deserialization of Untrusted Data Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of GPT Academic. Authentication is not required to... 10/01/2026 Zero-Day Initiative
ZDI-26-029: (0Day) GPT Academic run_in_subprocess_wrapper_func Deserialization of Untrusted Data Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of GPT Academic. Authentication is not required to... 10/01/2026 Zero-Day Initiative
ZDI-26-028: (0Day) GPT Academic stream_daas Deserialization of Untrusted Data Remote Code Execution Vulnerability This vulnerability allows remote attackers to execute arbitrary code on affected installations of GPT Academic. Interaction with a malicious DAAS... 10/01/2026 Zero-Day Initiative