检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-QF6P-P7WW-CWR9 CVE-2026-52806 | Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge | 严重 | Gogogs.io/gogs | 已审查 | 2026-06-24 01:02 | 2026-07-21 21:35 |
| GHSA-G2F5-GJR4-QJVM CVE-2026-52805 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Gogogs.io/gogs |
| 已审查 |
| 2026-06-24 01:01 |
| 2026-07-21 21:36 |
| GHSA-4565-R4X7-HG8J CVE-2026-52804 | Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation | 中危 | Gogogs.io/gogs | 已审查 | 2026-06-24 00:52 | 2026-07-21 21:17 |
| GHSA-XXHQ-69MF-W8CR CVE-2026-52802 | Gogs has an Open Redirect via redirect_to | 中危 | Gogogs.io/gogs | 已审查 | 2026-06-24 00:42 | 2026-07-21 21:36 |
| GHSA-WV27-2VQP-J7G5 CVE-2026-52801 | Gogs has the ability to import local repositories via Mirror Settings | 高危 | Gogogs.io/gogs | 已审查 | 2026-06-23 08:03 | 2026-07-21 21:36 |
| GHSA-PWX3-QCGW-VH7H CVE-2026-52800 | Gogs Vulnerable to CSRF Leading to Organization Owner Takeover | 高危 | Gogogs.io/gogs | 已审查 | 2026-06-23 08:02 | 2026-07-21 21:36 |
| GHSA-P9F5-H3RX-J5QW CVE-2026-52799 | Gogs Missing Authorization in Attachment Download | 高危 | Gogogs.io/gogs | 已审查 | 2026-06-23 07:59 | 2026-07-21 21:36 |
| GHSA-JQ8V-RMF6-65JW CVE-2026-52798 | Gogs has Stored XSS in `.ipynb` Preview | 高危 | Gogogs.io/gogs | 已审查 | 2026-06-23 07:58 | 2026-07-21 21:26 |
| GHSA-4J89-2C4F-44C6 CVE-2026-52796 | Gogs has DoS in rendering issue index pattern | 低危 | Gogogs.io/gogs | 已审查 | 2026-06-23 07:58 | 2026-07-21 21:17 |
| GHSA-XQJM-27PC-RVWM CVE-2026-50179 | @actual-app/web has CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields | 中危 | npm@actual-app/web | 已审查 | 2026-06-23 07:48 | 2026-06-23 07:48 |
| GHSA-GFQ7-5X4G-3XHF CVE-2026-54353 | @budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation | 高危 | npm@budibase/backend-core | 已审查 | 2026-06-23 07:39 | 2026-08-13 02:57 |
| GHSA-W7MQ-R738-X278 CVE-2026-54352 | Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload | 严重 | npm@budibase/server | 已审查 | 2026-06-23 07:33 | 2026-08-13 02:57 |
| GHSA-RGVG-3WPC-H44P CVE-2026-54351 | Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override | 高危 | npm@budibase/server | 已审查 | 2026-06-23 07:20 | 2026-07-21 23:04 |
| GHSA-CQ9C-6W48-QMFG CVE-2026-49229 | @actual-app/sync-server: Disabled OpenID users keep access through existing session tokens | 高危 | npm@actual-app/sync-server | 已审查 | 2026-06-23 07:19 | 2026-06-23 07:19 |
| GHSA-35C4-RVC8-FRHM CVE-2026-50137 | Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials | 高危 | npm@budibase/server | 已审查 | 2026-06-23 07:19 | 2026-07-21 23:04 |
| GHSA-JJ36-R9W3-3PFH CVE-2026-50136 | Budibase: Unauthenticated S3 signed upload URL generation allows arbitrary writes with stored datasource credentials | 高危 | npm@budibase/server | 已审查 | 2026-06-23 07:15 | 2026-07-18 00:59 |
| GHSA-V7J5-VC4M-723W CVE-2026-50132 | Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF | 高危 | npm@budibase/server | 已审查 | 2026-06-23 07:08 | 2026-07-21 23:04 |
| GHSA-QC2X-6F54-M6H9 CVE-2026-48487 | zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corruption via crafted mDNS packet | 中危 | PyPIzeroconf | 已审查 | 2026-06-23 07:07 | 2026-06-23 07:07 |
| GHSA-HVQH-JW65-WCPQ | devbridge-autocomplete has XSS in its default formatters: formatGroup and formatResult fail to escape HTML in untrusted inputs | 中危 | npmdevbridge-autocomplete | 已审查 | 2026-06-23 07:00 | 2026-06-23 07:00 |
| GHSA-9M6G-WC8R-Q59C CVE-2026-48170 | scimPatch vulnerable to prototype pollution via unfiltered keys in patch | 严重 | npmscim-patch | 已审查 | 2026-06-23 06:57 | 2026-06-23 06:57 |
| GHSA-GHMH-JHMJ-WCMF | nebula-mesh's stores enrollment tokens unhashed in SQLite | 中危 | Gogithub.com/juev/nebula-mesh | 已审查 | 2026-06-23 06:57 | 2026-06-23 06:57 |
| GHSA-4Q6H-8P4V-67VQ CVE-2026-48153 | Budibase: SSRF via OAuth2 token endpoint URL reaches internal hosts and cloud metadata | 高危 | npm@budibase/server | 已审查 | 2026-06-23 06:45 | 2026-06-23 06:45 |
| GHSA-74P7-6H78-GW8P | skillctl: argument injection, path traversal in --dest, FIFO/device DoS, hardlink exfiltration, and commit-trailer forgery | 高危 | crates.ioskillctl | 已审查 | 2026-06-23 06:45 | 2026-06-23 06:45 |
| GHSA-C4V7-XG93-QF8G CVE-2026-47267 | Gogs has SSRF in webhook deliveries | 高危 | Gogogs.io/gogs | 已审查 | 2026-06-23 06:44 | 2026-07-21 21:16 |
| GHSA-3F62-QV96-4P78 CVE-2026-46700 | @actual-app/sync-server's missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets | 中危 | npm@actual-app/sync-server | 已审查 | 2026-06-23 05:42 | 2026-06-23 05:42 |