检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-QQF5-X7MJ-V43P | budibase: Database Connector SQL Injections in PostgreSQL, MS SQL, and MySQL | 高危 | npmbudibase | 已审查 | 2026-06-19 01:24 | 2026-06-19 01:24 |
| GHSA-GFJ5-979R-92PW CVE-2026-58399 | @acastellon/auth: Authentication bypass via spoofable headers in validateToken() |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 严重 |
npm@acastellon/auth |
| 已审查 |
| 2026-06-19 01:22 |
| 2026-07-01 22:30 |
| GHSA-HGW6-8C77-V4GQ CVE-2026-11752 | Armeria: External Control of File Name or Path in xDS SDS DataSource | 中危 | Mavencom.linecorp.armeria:armeria-xds | 已审查 | 2026-06-19 01:22 | 2026-07-16 05:51 |
| GHSA-HXPF-9XVQ-WPH8 CVE-2026-57496 | netlicensing-mcp: REST Path Traversal Bypasses Token Redaction | 严重 | PyPInetlicensing-mcp | 已审查 | 2026-06-19 01:22 | 2026-07-21 21:41 |
| GHSA-FQ4X-789W-JG5H CVE-2026-57495 | AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator's Claude Code session (bridge-wake) | 高危 | npm@agenticmail/claudecode+3 | 已审查 | 2026-06-19 01:21 | 2026-07-21 21:41 |
| GHSA-HJWC-26PJ-V3PM CVE-2026-57494 | AgenticMail: Cross-agent task authorization bypass in AgenticMail API | 高危 | npm@agenticmail/api | 已审查 | 2026-06-19 01:20 | 2026-07-21 06:00 |
| GHSA-JR45-52CW-69H5 CVE-2026-54683 | NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463) | 中危 | Mavennl.nl-portal:documenten-api | 已审查 | 2026-06-19 01:20 | 2026-06-19 01:20 |
| GHSA-FJV8-J4P5-CR9M CVE-2026-54319 | Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape | 中危 | Gogithub.com/daytonaio/daytona | 已审查 | 2026-06-19 01:19 | 2026-07-21 05:15 |
| GHSA-5GF6-GC35-XJPC CVE-2026-11719 | MCP Toolbox for Databases: authenticated authorization bypass | 高危 | Gogithub.com/googleapis/mcp-toolbox | 已审查 | 2026-06-18 23:32 | 2026-06-20 01:00 |
| GHSA-WCPR-6G7X-P44R CVE-2026-11718 | googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) | 严重 | Gogithub.com/googleapis/mcp-toolbox | 已审查 | 2026-06-18 23:32 | 2026-06-20 00:59 |
| GHSA-8FCC-W5HV-4GXV CVE-2026-11717 | googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken) | 严重 | Gogithub.com/googleapis/mcp-toolbox | 已审查 | 2026-06-18 23:32 | 2026-06-20 00:58 |
| GHSA-CF98-J28V-49V6 CVE-2026-55170 | OpenFGA Improper Policy Enforcement | 低危 | Gogithub.com/openfga/openfga | 已审查 | 2026-06-18 23:05 | 2026-07-21 21:59 |
| GHSA-X5MV-8WGW-29HG CVE-2026-55093 | tract-nnef: integer overflow in NNEF `.dat` tensor parser yields an out-of-bounds read on model load | 中危 | crates.iotract-nnef | 已审查 | 2026-06-18 23:05 | 2026-06-18 23:05 |
| GHSA-MPX4-JMPR-VM8V CVE-2026-54711 | PGHoard: Password written to debug log | 低危 | PyPIpghoard | 已审查 | 2026-06-18 23:05 | 2026-06-18 23:05 |
| GHSA-J8CV-X86Q-RJ85 CVE-2026-54695 | Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID | 高危 | PyPIpipecat-ai | 已审查 | 2026-06-18 23:05 | 2026-06-18 23:05 |
| GHSA-W5CV-PW74-4RXC CVE-2026-55701 | opentelemetry-collector-contrib: githubreceiver silently ignores configured required_headers authentication | 中危 | Gogithub.com/open-telemetry/opentelemetry-collector-contrib/receiver/githubreceiver | 已审查 | 2026-06-18 23:05 | 2026-06-18 23:05 |
| GHSA-R3W8-2C5R-H9J9 CVE-2026-54005 | Kirby: `pages.access` permission is not checked in the `site/find` REST API route | 高危 | Packagistgetkirby/cms | 已审查 | 2026-06-18 23:05 | 2026-06-18 23:05 |
| GHSA-89CP-7P28-JFFG CVE-2026-54004 | Kirby: Access to files of top-level drafts is not protected by permissions | 中危 | Packagistgetkirby/cms | 已审查 | 2026-06-18 23:05 | 2026-06-18 23:05 |
| GHSA-WHXW-24JC-CWMV CVE-2026-54003 | Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header | 严重 | Packagistgetkirby/cms | 已审查 | 2026-06-18 23:04 | 2026-06-18 23:04 |
| GHSA-WR9H-4R83-F4V6 CVE-2026-54002 | Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()` | 高危 | Packagistgetkirby/cms | 已审查 | 2026-06-18 23:04 | 2026-06-18 23:04 |
| GHSA-4V4H-M2QQ-PPGW CVE-2026-50188 | Kirby: Request header injection in `Http\Remote` | 中危 | Packagistgetkirby/cms | 已审查 | 2026-06-18 23:04 | 2026-06-18 23:04 |
| GHSA-RHJ6-R49H-5932 CVE-2026-49276 | Kirby: Self cross-site scripting (self-XSS) in the writer field | 高危 | Packagistgetkirby/cms | 已审查 | 2026-06-18 23:04 | 2026-06-18 23:04 |
| GHSA-23Q2-54QV-RQ5X CVE-2026-49274 | Kirby: `pages.access` permission is not checked in the pages picker for parent pages | 中危 | Packagistgetkirby/cms | 已审查 | 2026-06-18 23:04 | 2026-06-18 23:04 |
| GHSA-4JVG-4JFX-FMHC CVE-2026-47256 | opentelemetry-collector-contrib sentryexporter: Path traversal in Sentry exporter via attacker-controlled service.name reaches privileged Sentry API endpoints with operator bearer token | 中危 | Gogithub.com/open-telemetry/opentelemetry-collector-contrib/exporter/sentryexporter | 已审查 | 2026-06-18 23:04 | 2026-06-18 23:04 |
| GHSA-FCW5-X6J4-CCMP CVE-2026-44727 | Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP | 严重 | PyPIjupyter-server | 已审查 | 2026-06-18 23:04 | 2026-08-29 02:31 |