检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-RVP7-W75Q-9FV2 CVE-2026-12567 | BBOT: Symlink-Following Arbitrary Write via github_workflows Module | 低危 | PyPIbbot | 已审查 | 2026-06-18 23:04 | 2026-06-18 23:04 |
| GHSA-M54H-VHF9-3W3M CVE-2026-12568 | BBOT: Arbitrary File Write in postman_download Module |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
PyPIbbot |
| 已审查 |
| 2026-06-18 23:03 |
| 2026-06-18 23:03 |
| GHSA-3MP7-VP6J-2MXX CVE-2026-12566 | BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing | 低危 | PyPIbbot | 已审查 | 2026-06-18 23:03 | 2026-06-18 23:03 |
| GHSA-3VGW-585J-4M45 CVE-2026-12565 | BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284 | 中危 | PyPIbbot | 已审查 | 2026-06-18 23:02 | 2026-06-18 23:02 |
| GHSA-C226-Q6FX-6J6C CVE-2026-53861 | OpenClaw: macOS Swift exec allowlist missed combined POSIX inline flags | 中危 | npmopenclaw | 已审查 | 2026-06-18 22:52 | 2026-06-18 22:52 |
| GHSA-PMF8-G7C8-7V54 CVE-2026-55890 | Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style() — incomplete patch of GHSA-r7fx-8g49-7hhr | 中危 | Packagistgetgrav/grav | 已审查 | 2026-06-18 22:49 | 2026-06-18 22:49 |
| GHSA-2FJJ-QQG8-FG7X | praisonai-platform: Authorization Bypass Through User-Controlled Key | 中危 | PyPIpraisonai-platform | 已审查 | 2026-06-18 22:48 | 2026-06-18 22:48 |
| GHSA-2F86-9CP8-6HCF CVE-2026-55885 | Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets | 中危 | Packagistgetgrav/grav | 已审查 | 2026-06-18 22:31 | 2026-06-18 22:31 |
| GHSA-J99Q-93C9-H869 CVE-2026-57441 | MCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalence | 中危 | npm@bitbonsai/mcpvault | 已审查 | 2026-06-18 22:30 | 2026-07-21 05:30 |
| GHSA-JM82-FX9C-MX94 | pypdf: Missing stream length values ignore defined limits | 中危 | PyPIpypdf | 已审查 | 2026-06-18 22:28 | 2026-06-18 22:28 |
| GHSA-Q6R4-3WMG-FWCQ CVE-2026-55686 | Podman: WORKDIR symlink traversal vulnerability | 中危 | Gogithub.com/containers/podman/v3+2 | 已审查 | 2026-06-18 22:28 | 2026-06-18 22:28 |
| GHSA-VMH5-MC38-953G CVE-2026-9697 | undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent | 高危 | npmundici | 已审查 | 2026-06-18 22:28 | 2026-06-18 22:28 |
| GHSA-PR7R-676H-XCF6 CVE-2026-9678 | undici vulnerable to cross-user information disclosure via shared cache whitespace bypass | 中危 | npmundici | 已审查 | 2026-06-18 22:28 | 2026-06-18 22:28 |
| GHSA-38RV-X7PX-6HHQ CVE-2026-9675 | undici WebSocket client vulnerable to denial of service via cumulative fragment bypass | 高危 | npmundici | 已审查 | 2026-06-18 22:28 | 2026-06-18 22:28 |
| GHSA-P6GQ-J5CR-W38F CVE-2026-82659 | Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message | 高危 | npmnodemailer | 已审查 | 2026-06-18 22:28 | 2026-09-02 22:47 |
| GHSA-V4JC-PM6R-3VJ8 CVE-2026-47103 | python-statemachine SCXML <data expr> Eval Injection | 严重 | PyPIpython-statemachine | 已审查 | 2026-06-18 22:28 | 2026-06-18 22:28 |
| GHSA-CMWH-PVXP-8882 CVE-2026-65898 | DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch) | 中危 | npmdompurify | 已审查 | 2026-06-18 22:27 | 2026-07-23 21:58 |
| GHSA-CWJ8-7GP2-GGCW CVE-2026-57147 | praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery | 严重 | PyPIpraisonai-platform | 已审查 | 2026-06-18 22:27 | 2026-07-21 05:28 |
| GHSA-6JCQ-6546-QRRW CVE-2026-57144 | PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable | 高危 | PyPIpraisonai | 已审查 | 2026-06-18 22:27 | 2026-07-21 05:28 |
| GHSA-8CCJ-P46R-JWQQ CVE-2026-57132 | PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication | 高危 | PyPIpraisonai | 已审查 | 2026-06-18 22:27 | 2026-07-21 05:26 |
| GHSA-4PCV-MG8V-VRGF CVE-2026-57143 | PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter | 高危 | PyPIpraisonaiagents | 已审查 | 2026-06-18 22:27 | 2026-07-21 04:49 |
| GHSA-F38V-77QJ-H4JQ CVE-2026-57148 | praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard) | 严重 | PyPIpraisonai-platform | 已审查 | 2026-06-18 22:27 | 2026-07-21 05:28 |
| GHSA-29W3-P9W9-WC47 CVE-2026-57145 | PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation | 严重 | PyPIpraisonai | 已审查 | 2026-06-18 22:27 | 2026-07-21 05:28 |
| GHSA-JXCW-QP4H-6JFQ CVE-2026-57146 | PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default | 高危 | PyPIpraisonai | 已审查 | 2026-06-18 22:27 | 2026-07-21 05:31 |
| GHSA-7QW2-W5RC-37X2 CVE-2026-57142 | PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml | 高危 | PyPIpraisonai | 已审查 | 2026-06-18 22:26 | 2026-07-21 05:28 |