检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-66FX-FQV6-5WWX | Duplicate Advisory: uutils coreutils has a Link Following issue 已撤回 | 中危 | crates.iocoreutils | 已审查 | 2026-04-23 02:31 | 2026-07-07 04:23 |
当前筛选结果 998 条 · 时间按北京时间显示
Duplicate Advisory: uutils coreutils allows unauthorized modification of permissions on existing files 已撤回 |
| 高危 |
crates.iocoreutils |
| 已审查 |
| 2026-04-23 02:31 |
| 2026-07-07 05:53 |
| GHSA-VP6Q-MV9J-J428 | Duplicate Advisory: uutils coreutils incorrectly handles exit codes when processing multiple files 已撤回 | 中危 | crates.iocoreutils | 已审查 | 2026-04-23 02:31 | 2026-07-07 03:27 |
| GHSA-9GQX-53GP-C8G3 | Duplicate Advisory: uutils coreutils allows users to bypass the --preserve-root safety mechanism 已撤回 | 高危 | crates.iocoreutils | 已审查 | 2026-04-23 02:31 | 2026-07-07 01:41 |
| GHSA-88CH-Q68X-36V7 | Duplicate Advisory: uutils coreutils has an Incorrect Check of Function Return Value 已撤回 | 中危 | crates.iocoreutils | 已审查 | 2026-04-23 02:31 | 2026-07-07 03:24 |
| GHSA-2CXP-XQ3C-MJXX | Duplicate Advisory: uutils coreutils' mktemp utility doesn't properly handle an empty TMPDIR environment variable 已撤回 | 低危 | crates.iocoreutils | 已审查 | 2026-04-23 02:31 | 2026-07-07 03:50 |
| GHSA-QC5J-2MQX-X83Q | Duplicate Advisory: OpenClaw: Webchat media embedding enforces local-root containment for tool-result files 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-04-21 02:31 | 2026-05-06 02:12 |
| GHSA-QJFJ-3MM5-VRJG | Withdrawn Advisory: Protobuf: Denial of Service issue through malicious messages containing negative varints or deep recursion 已撤回 | 高危 | Packagistgoogle/protobuf | 已审查 | 2026-04-16 23:31 | 2026-04-17 06:59 |
| GHSA-RP7W-624X-95QV | Duplicate Advisory: LibreNMS affected by an authenticated Cross-site Scripting vulnerability on the showconfig page 已撤回 | 中危 | Packagistlibrenms/librenms | 已审查 | 2026-04-13 20:31 | 2026-05-12 21:39 |
| GHSA-7549-GGPQ-22W8 | Duplicate Advisory: LibreNMS is Vulnerable to Remote Code Execution by Arbitrary File Write 已撤回 | 高危 | Packagistlibrenms/librenms | 已审查 | 2026-04-13 20:31 | 2026-04-15 06:51 |
| GHSA-V8F7-CG9P-W5JX | Duplicate Advisory: GeoNode contains a server-side request forgery vulnerability in the service registration endpoint 已撤回 | 中危 | PyPIgeonode | 已审查 | 2026-04-11 05:31 | 2026-06-08 20:50 |
| GHSA-3926-2JVF-FG29 | Duplicate Advisory: LiteLLM has a sandbox escape in custom-code guardrail 已撤回 | 高危 | PyPIlitellm | 已审查 | 2026-04-10 23:31 | 2026-05-12 00:17 |
| GHSA-R4C2-GQ3J-7RPJ | Duplicate Advisory: OpenClaw: Telegram Webhook Missing Guess Rate Limiting Enables Brute-Force Guessing of Weak Webhook Secret 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-04-10 08:30 | 2026-04-18 08:45 |
| GHSA-R3V5-2GRC-429H | Duplicate Advisory: OpenClaw Gateway: RCE and Privilege Escalation from operator.pairing to operator.admin via device.pair.approve 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-04-10 08:30 | 2026-04-11 04:20 |
| GHSA-PMF3-2Q63-JMP6 | Duplicate Advisory: OpenClaw: Symlink Traversal via IDENTITY.md appendFile in agents.create/update (Incomplete Fix for CVE-2026-32013) 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-04-10 08:30 | 2026-04-18 08:42 |
| GHSA-P6J4-WVMC-VX2H | Duplicate Advisory: OpenClaw: Tlon cite expansion happens before channel and DM authorization is complete 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-04-10 08:30 | 2026-04-11 04:20 |
| GHSA-M5JP-P3R5-MFQP | Duplicate Advisory: OpenClaw: Gateway Plugin Subagent Fallback `deleteSession` Uses Synthetic `operator.admin` 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-04-10 08:30 | 2026-04-18 08:43 |
| GHSA-HM63-VWJ4-MJ2Q | Duplicate Advisory: OpenClaw: Remote media error responses could trigger unbounded memory allocation before failure 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-04-10 08:30 | 2026-04-11 04:19 |
| GHSA-G8MC-C5F2-MQG7 | Duplicate Advisory: OpenClaw Bypasses DM Policy Separation via Synology Chat Webhook Path Collision 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-04-10 08:30 | 2026-04-11 04:19 |
| GHSA-9GVX-VJ57-VQQX | Duplicate Advisory: OpenClaw: Gateway Canvas local-direct requests bypass Canvas HTTP and WebSocket authentication 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-04-10 08:30 | 2026-04-11 04:19 |
| GHSA-8J7F-G9GV-7JHC | Duplicate Advisory: OpenClaw: SSRF via Unguarded Configured Base URLs in Multiple Channel Extensions (Incomplete Fix for CVE-2026-28476) 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-04-10 08:30 | 2026-04-11 04:19 |
| GHSA-8F9R-GR6R-X63Q | Duplicate Advisory: OpenClaw: Feishu webhook reads and parses unauthenticated request bodies before signature validation 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-04-10 08:30 | 2026-04-11 04:21 |
| GHSA-59XC-5V89-R7PR | Duplicate Advisory: OpenClaw: Synology Chat Webhook Pre-Auth Rate-Limit Bypass Enables Brute-Force Guessing of Webhook Token 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-04-10 08:30 | 2026-04-11 04:25 |
| GHSA-36CP-MH65-X882 | Duplicate Advisory: OpenClaw is vulnerable to unauthenticated resource exhaustion through its voice call webhook handling 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-04-10 08:30 | 2026-04-11 04:18 |
| GHSA-2J53-2C28-G9V2 | Duplicate Advisory: OpenClaw: Nostr inbound DMs could trigger unauthenticated crypto work before sender policy enforcement 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-04-10 08:30 | 2026-04-11 04:19 |