Models behaving maliciously only on certain inputs/environments? ...on the hardware of pumps in the nuclear power plant in Iran.. Same thing here right?. Is there a way to scan for such patterns in open weight models?. I would guess another solution would be to run two separate models (from different countries ideally) with one cross checking... r/LocalLLaMA u/dowitex r/LocalLLaMA u/dowitex Sep 24 1d yesterday lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard lightrag: lightrag-hku: SSRF via IPv6-transition address bypass (NAT64, IPv4-compatible, 6to4) of the native-markdown image-download guard Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 22 3d 3 days ago lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks lightrag: lightrag-hku: No Rate Limiting on /login Endpoint Allows Brute-Force Attacks Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 22 3d 3 days ago OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack openbao: OpenBao's Recovery Mode Vulnerable To Token Leakage via Timing Attack Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 22 3d 3 days ago OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters openbao: OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 22 3d 3 days ago For engineers working with Terraform/OpenTofu: what parts of the work are still painful? For engineers who work with Terraform/OpenTofu and cloud infrastructure:. I'm curious about the day-to-day parts of the work that tend to be repetitive, manual, frustrating, or easy to get wrong.. Not really looking for opinions about which tools are better. I'm more interested... r/devops u/MysteriousQuestion99 r/devops u/MysteriousQuestion99 Sep 22 3d 3 days ago September update killed functionality Claude gives false positives and lies about research about 4/5 times (was 1/50 before) ever since the September update Claude App Store reviews Claude App Store reviews Sep 20 5d 5 days ago LMDeploy has an SSRF bypass lmdeploy: LMDeploy has an SSRF bypass Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 18 7d 7 days ago LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading lmdeploy: LMDeploy vulnerable to arbitrary code execution via eval() of untrusted quant_dtype in model config loading Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 18 7d 7 days ago Jupyter Server: 5xx request logging leaks token-bearing Referer header values jupyter: Jupyter Server: 5xx request logging leaks token-bearing Referer header values Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 17 8d 8 days ago LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy lmdeploy: LMdeploy has Remote Code Execution by Pickle Deserialization via zmq_rpc.call_and_response() in InterLM/lmdeploy Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 16 9d 9 days ago vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in processing_llava_onevision2.py that executes with vllm: vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a malicious model with arbitrary code in... Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 12 13d 13 days ago 5 of your servers graded A/B on OpenTrustBench, badges inside Hi, I built OpenTrustBench (OSS scanner that grades MCP servers A-F, 8 OWASP-mapped rules, fully local). I scanned the servers repo at d73f99e and yours did well: mcp-fetch: A (90) mcp-sequentialthinking: A (90) mcp-time: B (88) mcp-everything: B (85) mcp-git: B (79) Full... modelcontextprotocol/servers gautamkishore modelcontextprotocol/servers gautamkishore Sep 11 2w 2 weeks ago Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout open-webui: Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logout Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 10 2w 2 weeks ago Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite open-webui: Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLite Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 10 2w 2 weeks ago n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node n8n: n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 10 2w 2 weeks ago Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin open-webui: Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 10 2w 2 weeks ago Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader open-webui: Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loader Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 10 2w 2 weeks ago Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion open-webui: Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletion Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 10 2w 2 weeks ago Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch open-webui: Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetch Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 10 2w 2 weeks ago NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions nltk: NLTK: ReDoS in nltk.tgrep via unvalidated user-supplied regular expressions Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 8 2w 2 weeks ago NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions nltk: NLTK: ReDoS in nltk.text.Text.findall() via unvalidated user-supplied regular expressions Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 8 2w 2 weeks ago NLTK: Corpus Reader Sandbox Bypass nltk: NLTK: Corpus Reader Sandbox Bypass Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 8 2w 2 weeks ago NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement nltk: NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 8 2w 2 weeks ago NLTK: Allowlisted pickle loaders still permit code execution in current source nltk: NLTK: Allowlisted pickle loaders still permit code execution in current source Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 8 2w 2 weeks ago NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses nltk: NLTK: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 8 2w 2 weeks ago NLTK: pathsec SSRF protection can be bypassed when a proxy is configured nltk: NLTK: pathsec SSRF protection can be bypassed when a proxy is configured Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 8 2w 2 weeks ago NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution nltk: NLTK: Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 8 2w 2 weeks ago NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292) nltk: NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292) Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 8 2w 2 weeks ago NLTK: Stable FrameNet and NKJP readers parse outside-root XML nltk: NLTK: Stable FrameNet and NKJP readers parse outside-root XML Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 8 2w 2 weeks ago NLTK: StreamBackedCorpusView Bypasses pathsec.ENFORCE - Arbitrary Local File Read nltk: NLTK: StreamBackedCorpusView Bypasses pathsec.ENFORCE - Arbitrary Local File Read Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 8 2w 2 weeks ago NLTK: Symlink escape in CorpusReader allows arbitrary local file read outside the corpus root nltk: NLTK: Symlink escape in CorpusReader allows arbitrary local file read outside the corpus root Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 8 2w 2 weeks ago SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path surrealdb: SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 4 3w 3 weeks ago [BUG] Read(**/.env) deny rule prompts on every rg directory search, though rg skips hidden files by default ...deny, then ask, then allow, and hook decisions don't bypass permission rules, there is no way to suppress the prompt short of deleting the deny rule. That forces a choice between guarding `.env` and being able to search a repository without a prompt on every call. In unattended... anthropics/claude-code williamthorsen anthropics/claude-code williamthorsen 10 reactions, 1 replies Sep 3 3w 3 weeks ago Subdomain blocked by profanity filter (false positive) Streamlit Forum Benjamin27 Streamlit Forum Benjamin27 3 likes, 2 replies Sep 2 3w 3 weeks ago SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths seaweedfs: SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 2 3w 3 weeks ago NLTK: Default ENFORCE=False Disables All pathsec Security Controls nltk: NLTK: Default ENFORCE=False Disables All pathsec Security Controls Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 2 3w 3 weeks ago SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control seaweedfs: SeaweedFS: Unauthenticated filer IAM gRPC service grants S3 administrative control Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 2 3w 3 weeks ago NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed roots nltk: NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed roots Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 2 3w 3 weeks ago NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841) nltk: NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841) Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 1 3w 3 weeks ago NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary nltk: NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 1 3w 3 weeks ago MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor , RCE via crafted model artifact mlflow: MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor , RCE via crafted model artifact Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Sep 1 3w 3 weeks ago SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read seaweedfs: SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Aug 28 4w 4 weeks ago Fortigate syslog message parser can be exploited to modify or delete fields from the original message graylog2-server: Fortigate syslog message parser can be exploited to modify or delete fields from the original message Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Aug 28 4w 4 weeks ago LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint litellm: LiteLLM vulnerable to server-side template injection in the /prompts/test endpoint Advisories (advisories.fru.dev) Advisories (advisories.fru.dev) Aug 27 4w 4 weeks ago