检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-C3XH-98XP-6QHF | githubtoplanguages: Command Injection via Issue Title in Discord Notification Workflow | 高危 | GitHub Actionsgouef/githubtoplanguages | 已审查 | 2026-06-20 06:10 | 2026-06-20 06:10 |
| GHSA-MH64-PH39-MRC9 CVE-2026-11941 | Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
crates.ioquiche |
| 已审查 |
| 2026-06-20 06:10 |
| 2026-06-20 06:10 |
| GHSA-4CC2-G9W2-FHF6 | Zeep: Server-Side Request Forgery (SSRF) | 中危 | PyPIzeep | 已审查 | 2026-06-20 06:10 | 2026-06-20 06:10 |
| GHSA-CW6H-FFMH-X6VH | Anki: User scripts in iframes have access to the internal Anki API | 中危 | PyPIaqt | 已审查 | 2026-06-20 06:10 | 2026-06-20 06:10 |
| GHSA-WVRH-2F4M-924V | ChatterBot: Symlink-Following Arbitrary Write via UbuntuCorpusTrainer | 中危 | PyPIChatterBot | 已审查 | 2026-06-20 06:08 | 2026-06-20 06:08 |
| GHSA-H3M5-97JQ-QJRF CVE-2026-57168 | OpenRemote Manager: removeAlarms cross-realm IDOR (bulk delete) | 严重 | Mavenio.openremote:openremote-manager | 已审查 | 2026-06-20 05:43 | 2026-07-03 04:12 |
| GHSA-X975-RGX4-5FH4 | appium-mcp: Unescaped Locator Data XSS in MCP-UI Resource (createLocatorGeneratorUI) | 高危 | npmappium-mcp | 已审查 | 2026-06-20 05:43 | 2026-06-20 05:43 |
| GHSA-C795-2G9C-J48M | EverOS: Path traversal in EverOS /api/v1/memory/add via unvalidated sender_id | 高危 | PyPIeveros | 已审查 | 2026-06-20 05:43 | 2026-06-20 05:43 |
| GHSA-V3F4-W7R7-V3HM | Uni-CLI: Legacy HTTP MCP transport accepted browser-originated localhost requests | 高危 | npm@zenalexa/unicli | 已审查 | 2026-06-20 05:43 | 2026-06-20 05:43 |
| GHSA-6GQW-JQV7-V88M | stigmem-node: decay sweep expires and counts facts across all tenants (cross-tenant BOLA) | 高危 | PyPIstigmem-node | 已审查 | 2026-06-20 05:43 | 2026-06-20 05:43 |
| GHSA-XHV3-Q4XX-349R | stistigmem-node: quarantine review surface exposes and mutates other tenants' quarantined facts (cross-tenant BOLA) | 高危 | PyPIstigmem-node | 已审查 | 2026-06-20 05:43 | 2026-06-20 05:43 |
| GHSA-X26H-XMV8-GXF7 | stigmem-node: RTBF tombstones are mis-attributed and suppress reads tenant-blind (cross-tenant BOLA) | 高危 | PyPIstigmem-node | 已审查 | 2026-06-20 05:42 | 2026-06-20 05:42 |
| GHSA-6V7P-G79W-8964 | MessagePack for Python: Out-of-bounds read / crash on Unpacker reuse after a caught error | 高危 | PyPImsgpack | 已审查 | 2026-06-20 05:42 | 2026-06-20 05:42 |
| GHSA-6VXV-WG6J-5QWP | Gogs: XSS in .ipynb files renderer due to outdated notebookjs | 高危 | Gogogs.io/gogs | 已审查 | 2026-06-20 05:42 | 2026-06-20 05:42 |
| GHSA-97PR-9HGG-3P8R | parse-server: LiveQuery discloses object data to a subscriber across an ACL read-access change | 低危 | npmparse-server | 已审查 | 2026-06-20 05:42 | 2026-06-20 05:42 |
| GHSA-MRVX-JMJW-VGGC | SearXNG MCP Server: DNS-resolved Private Hostname SSRF in `web_url_read` | 高危 | npmmcp-searxng | 已审查 | 2026-06-20 05:42 | 2026-06-20 05:42 |
| GHSA-XCQX-9JF5-W339 | SearXNG MCP Server: Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read` | 高危 | npmmcp-searxng | 已审查 | 2026-06-20 05:42 | 2026-06-20 05:42 |
| GHSA-48X2-6PR9-2JJF | Network-AI: EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment data | 中危 | npmnetwork-ai | 已审查 | 2026-06-20 05:42 | 2026-06-20 05:42 |
| GHSA-6X2M-P4XP-WG22 | Network-AI: EnvironmentManager.backup() follows symlinked directories and copies files outside the environment root into backups | 中危 | npmnetwork-ai | 已审查 | 2026-06-20 05:42 | 2026-06-20 05:42 |
| GHSA-MXJX-28VX-XJJJ | Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions | 中危 | npmnetwork-ai | 已审查 | 2026-06-20 05:42 | 2026-06-20 05:42 |
| GHSA-JVCM-F35G-W78P | Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory | 中危 | npmnetwork-ai | 已审查 | 2026-06-20 05:42 | 2026-06-20 05:42 |
| GHSA-2FMP-9RVW-HC96 | Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning | 高危 | npmnetwork-ai | 已审查 | 2026-06-20 05:42 | 2026-06-20 05:42 |
| GHSA-9C83-RR99-VFWJ CVE-2026-57442 | MCPVault: PathFilter restricted directories (.git/.obsidian/node_modules) only denied at vault root, not nested | 中危 | npm@bitbonsai/mcpvault | 已审查 | 2026-06-20 05:42 | 2026-07-21 05:31 |
| GHSA-H5JC-78HR-3PC9 | Sveltia CMS: Stored XSS in Markdown/RichText preview via unsandboxed same-origin iframe | 低危 | npm@sveltia/cms | 已审查 | 2026-06-20 05:42 | 2026-06-20 05:42 |
| GHSA-P9XJ-FPR2-JF2Q CVE-2026-55878 | symfony/ux-toolkit: Path Traversal Allows Arbitrary File Write and Read via Crafted Recipe Manifest | 高危 | Packagistsymfony/ux-toolkit | 已审查 | 2026-06-20 05:42 | 2026-06-20 05:42 |