检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-VRHC-3FR6-PC3C CVE-2026-54010 | Open WebUI: Forged chat-file link allows cross-user file read and deletion | 高危 | PyPIopen-webui | 已审查 | 2026-06-17 22:12 | 2026-07-21 05:04 |
| GHSA-WCH8-MHJ5-9FRG CVE-2026-54009 | Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
PyPIopen-webui |
| 已审查 |
| 2026-06-17 22:11 |
| 2026-07-21 05:03 |
| GHSA-226F-F24G-524W CVE-2026-54008 | Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling of CVE-2026-45401) | 高危 | PyPIopen-webui | 已审查 | 2026-06-17 22:10 | 2026-06-17 22:10 |
| GHSA-3VV5-8XXP-4F55 CVE-2026-54007 | Open WebUI: Cross-origin postMessage confirmation bypass via action:submit | 高危 | PyPIopen-webui | 已审查 | 2026-06-17 22:10 | 2026-07-21 05:03 |
| GHSA-F3G7-59QC-PQG6 CVE-2026-54006 | Open WebUI IDOR: Calendar event re-parenting allows writing events into another user's calendar | 中危 | PyPIopen-webui | 已审查 | 2026-06-17 22:09 | 2026-07-21 05:03 |
| GHSA-HMCR-RMJQ-47QR CVE-2026-53931 | NocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint | 中危 | npmnocodb | 已审查 | 2026-06-17 22:08 | 2026-07-21 05:20 |
| GHSA-H6VV-PCQ8-7XM4 CVE-2026-53930 | NocoDB: Server-Side Request Forgery via Base Migration URL | 中危 | npmnocodb | 已审查 | 2026-06-17 22:08 | 2026-07-21 05:20 |
| GHSA-6MHR-74X2-98V9 CVE-2026-53929 | NocoDB: Stored Cross-Site Scripting via Secure Attachment | 中危 | npmnocodb | 已审查 | 2026-06-17 22:07 | 2026-07-21 05:20 |
| GHSA-R989-7G3J-WJHW CVE-2026-53928 | NocoDB: Refresh Tokens Persist Through Password Recovery | 中危 | npmnocodb | 已审查 | 2026-06-17 22:07 | 2026-07-21 05:20 |
| GHSA-GPRH-27J3-G5H4 CVE-2026-53927 | NocoDB: Server-Side Request Forgery via Spreadsheet Fetch URL | 中危 | npmnocodb | 已审查 | 2026-06-17 22:06 | 2026-07-21 05:19 |
| GHSA-6PR9-RP53-2PMC CVE-2026-54233 | vLLM: OOM Denial of Service via Audio Decompression Bomb | 中危 | PyPIvllm | 已审查 | 2026-06-17 22:06 | 2026-07-18 00:39 |
| GHSA-HGG8-FQQC-VFMW CVE-2026-54236 | vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router | 中危 | PyPIvllm | 已审查 | 2026-06-17 22:04 | 2026-07-20 21:36 |
| GHSA-5JV2-G5WQ-CMR4 CVE-2026-53923 | vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving | 中危 | PyPIvllm | 已审查 | 2026-06-17 22:03 | 2026-07-18 00:20 |
| GHSA-8JR5-V98P-W75M CVE-2026-12491 | vLLM: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations | 中危 | PyPIvllm | 已审查 | 2026-06-17 22:02 | 2026-07-18 00:38 |
| GHSA-7H4P-RFFG-7823 CVE-2026-54235 | vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels | 中危 | PyPIvllm | 已审查 | 2026-06-17 22:02 | 2026-07-18 00:40 |
| GHSA-3G6V-2R68-PRFC CVE-2026-54761 | Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services | 中危 | Gogithub.com/traefik/traefik+2 | 已审查 | 2026-06-17 22:01 | 2026-07-21 05:13 |
| GHSA-3PVJ-JV98-QHJQ CVE-2026-53765 | Chrome DevTools for agents: daemon.pid write follows symlinks in /tmp fallback runtime directory | 中危 | npmchrome-devtools-mcp | 已审查 | 2026-06-17 22:01 | 2026-07-21 21:41 |
| GHSA-664H-GPGQ-H6XX | n8n: Wrong OAuth Scope on Evaluation Test Runs Endpoints | 中危 | npmn8n | 已审查 | 2026-06-17 21:55 | 2026-06-17 21:55 |
| GHSA-MQXH-6GQ7-558M CVE-2026-54325 | Pi Agent: Pi loads project-local extensions without approval | 中危 | npm@earendil-works/pi-coding-agent | 已审查 | 2026-06-17 21:55 | 2026-07-21 05:15 |
| GHSA-JFGX-WXX8-MP94 CVE-2026-54328 | Pi Agent: Predictable temporary extension install paths allow local privilege escalation on shared Linux hosts | 高危 | npm@earendil-works/pi-coding-agent+1 | 已审查 | 2026-06-17 21:55 | 2026-07-21 05:13 |
| GHSA-R95R-RJ6R-C39X CVE-2026-54327 | Pi Agent: Race condition in Pi auth.json writes could expose stored credentials | 低危 | npm@earendil-works/pi-coding-agent+1 | 已审查 | 2026-06-17 21:54 | 2026-07-21 05:12 |
| GHSA-CRMM-HGP2-WGRP | Laravel Framework: Temporary Signed URL Path Confusion | 中危 | Packagistlaravel/framework | 已审查 | 2026-06-17 21:54 | 2026-06-17 21:54 |
| GHSA-5VG9-5847-VVMQ | Laravel Framework: CRLF injection in default email rule | 高危 | Packagistlaravel/framework | 已审查 | 2026-06-17 21:53 | 2026-06-17 21:53 |
| GHSA-7V5M-PR3Q-6453 CVE-2026-54326 | Pi Agent: Potential XSS in HTML session exports via Markdown URL sanitization bypass | 低危 | npm@earendil-works/pi-coding-agent+1 | 已审查 | 2026-06-17 07:43 | 2026-07-21 05:13 |
| GHSA-CR4G-F395-H25H CVE-2026-20706 | Gitea: Token scope bypass on web archive download endpoint | 中危 | Gocode.gitea.io/gitea | 已审查 | 2026-06-17 07:42 | 2026-06-17 07:42 |