检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-63MC-HW7G-86RR CVE-2026-56812 | Phoenix: Presence keys colliding with `Object.prototype` members break existence checks | 中危 | Hexphoenix | 已审查 | 2026-09-04 04:30 | 2026-09-04 04:30 |
| GHSA-528H-PC64-C93X CVE-2026-71429 | stream-json: pick/ignore/filter/replace filters are O(depth²) on nested input — small crafted JSON blocks the event loop for seconds→minutes (DoS) |
当前筛选结果 366,391 条 · 时间按北京时间显示
| 中危 |
npmstream-json |
| 已审查 |
| 2026-09-04 04:27 |
| 2026-09-04 04:27 |
| GHSA-VH22-H7HF-WWW7 CVE-2026-69084 | SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write | 严重 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-04 04:19 | 2026-09-04 04:19 |
| GHSA-6C5V-HQJR-5XXP CVE-2026-79921 | amqp091-go has a Potential Memory Exhaustion/Protocol Violation via Broker-Controlled Oversized Payload | 高危 | Gogithub.com/rabbitmq/amqp091-go | 已审查 | 2026-09-04 04:15 | 2026-09-04 04:15 |
| GHSA-JXWJ-J7WR-GFRW CVE-2026-63670 | ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close | 中危 | npmsanitize-html | 已审查 | 2026-09-04 04:07 | 2026-09-04 04:07 |
| GHSA-WR5R-WQP2-X4FH CVE-2026-63669 | ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtree | 中危 | npmapostrophe | 已审查 | 2026-09-04 04:05 | 2026-09-04 04:05 |
| GHSA-XVG9-69GF-FJRF CVE-2026-73295 | Material for MkDocs: DOM XSS in search suggestions via query parameter | 中危 | PyPImkdocs-material | 已审查 | 2026-09-04 03:52 | 2026-09-04 03:52 |
| GHSA-P95V-992W-H6C3 CVE-2026-82404 | TOON: Prototype pollution when decoding untrusted TOON input | 高危 | npm@toon-format/toon | 已审查 | 2026-09-04 03:52 | 2026-09-04 03:52 |
| GHSA-79WM-X847-7CVG CVE-2026-73222 | Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio) | 高危 | npmclaude-code-templates | 已审查 | 2026-09-04 03:50 | 2026-09-04 03:50 |
| GHSA-CXVF-GVFQ-36W2 CVE-2026-73293 | Semaphore UI: Manager-to-owner privilege escalation via custom-role slug collision | 高危 | Gogithub.com/semaphoreui/semaphore | 已审查 | 2026-09-04 03:23 | 2026-09-04 03:23 |
| GHSA-8CJ9-R88M-8945 CVE-2026-73292 | Semaphore UI: CSRF vulnerability on password change endpoint - No CSRF token or password confirmation | 高危 | Gogithub.com/semaphoreui/semaphore | 已审查 | 2026-09-04 03:23 | 2026-09-04 03:23 |
| GHSA-FG9P-MRXR-HVQ7 CVE-2026-62681 | Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout) | 严重 | npmorval | 已审查 | 2026-09-04 03:17 | 2026-09-04 03:17 |
| GHSA-88F2-FPV8-89Q2 CVE-2026-62682 | Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification) | 严重 | npmorval | 已审查 | 2026-09-04 03:06 | 2026-09-04 03:06 |
| GHSA-W727-8J6C-2RJ4 CVE-2026-72717 | Orval: Import-time RCE via schema default -> zod module-level template literal | 严重 | npmorval | 已审查 | 2026-09-04 03:03 | 2026-09-04 03:03 |
| GHSA-2H9G-J24R-H63G CVE-2026-71869 | Orval: Import-time RCE via array-items default -> zod module-level template literal | 严重 | npmorval | 已审查 | 2026-09-04 02:38 | 2026-09-04 02:38 |
| GHSA-8J6P-R8JG-MXQH CVE-2026-71871 | Orval: Import-time RCE via header-parameter default -> zod module-level template literal | 严重 | npmorval | 已审查 | 2026-09-04 02:32 | 2026-09-04 02:32 |
| GHSA-QG8C-8R2J-4H27 CVE-2026-85307 | 无摘要 | 中危 | —— | 未审查 | 2026-09-04 02:31 | 2026-09-04 02:31 |
| GHSA-QG72-3QRW-JCXV CVE-2026-83959 | 无摘要 | 高危 | —— | 未审查 | 2026-09-04 02:31 | 2026-09-04 02:31 |
| GHSA-GFH7-M849-P732 CVE-2026-85187 | 无摘要 | 中危 | —— | 未审查 | 2026-09-04 02:31 | 2026-09-04 02:31 |
| GHSA-F3VP-H5HG-9GMP CVE-2026-82023 | 无摘要 | 中危 | —— | 未审查 | 2026-09-04 02:31 | 2026-09-04 02:31 |
| GHSA-8V66-4W9Q-MGG3 CVE-2026-85308 | 无摘要 | 中危 | —— | 未审查 | 2026-09-04 02:31 | 2026-09-04 02:31 |
| GHSA-7C9G-VC8F-3266 CVE-2026-82024 | 无摘要 | 中危 | —— | 未审查 | 2026-09-04 02:31 | 2026-09-04 02:31 |
| GHSA-6JPP-GXX7-G3PQ CVE-2026-85309 | 无摘要 | 中危 | —— | 未审查 | 2026-09-04 02:31 | 2026-09-04 02:31 |
| GHSA-XW7F-V826-83X3 CVE-2026-84776 | 无摘要 | 高危 | —— | 未审查 | 2026-09-04 02:31 | 2026-09-04 02:31 |
| GHSA-X6V6-8GGM-G2Q9 CVE-2026-84812 | 无摘要 | 高危 | —— | 未审查 | 2026-09-04 02:31 | 2026-09-04 02:31 |