检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-3FWP-P5RJ-2PXF CVE-2026-27783 | Gitea: Missing repository-unit authorization on issue-template API endpoints | 中危 | Gocode.gitea.io/gitea | 已审查 | 2026-06-17 07:41 | 2026-06-17 07:41 |
| GHSA-8629-VC8R-5P58 CVE-2026-25714 | Gitea: Incomplete CVE-2025-68941 fix: /user/orgs missing checkTokenPublicOnly + switch-case logic flaw |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Gocode.gitea.io/gitea |
| 已审查 |
| 2026-06-17 07:41 |
| 2026-06-17 07:41 |
| GHSA-MM7C-RHG6-QR4R CVE-2026-26231 | Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo | 高危 | Gocode.gitea.io/gitea | 已审查 | 2026-06-17 07:41 | 2026-06-17 07:41 |
| GHSA-9R5X-WG6M-X2RC CVE-2026-28699 | Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication | 高危 | Gocode.gitea.io/gitea | 已审查 | 2026-06-17 07:40 | 2026-06-17 07:40 |
| GHSA-PM6V-2H4W-4RP2 CVE-2026-52797 | Gogs: Overwriting critical files results in a denial of service | 高危 | Gogogs.io/gogs | 已审查 | 2026-06-17 07:40 | 2026-07-21 21:17 |
| GHSA-QW24-GH76-8RVV CVE-2026-49980 | Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix | 严重 | Gogithub.com/rclone/rclone | 已审查 | 2026-06-17 07:39 | 2026-07-21 21:16 |
| GHSA-X6QJ-4H56-5RJ5 CVE-2026-49993 | @nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when Sec-Fetch-Site, Origin, and Referer are all absent (incomplete fix for GHSA-6m52-m754-pw2g) | 中危 | npm@nuxt/rspack-builder+1 | 已审查 | 2026-06-17 07:39 | 2026-06-17 07:39 |
| GHSA-M3Q2-P4FW-W38M | Cross-site scripting via <NoScript> slot content in Nuxt's head components | 低危 | npmnuxt | 已审查 | 2026-06-17 07:38 | 2026-06-17 07:38 |
| GHSA-4XPC-PV4P-PM3W CVE-2026-49468 | LiteLLM: Authentication Bypass via Host Header Injection | 严重 | PyPIlitellm | 已审查 | 2026-06-17 07:38 | 2026-07-19 01:26 |
| GHSA-CC8W-R4QH-3V65 CVE-2026-28744 | Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens | 高危 | Gocode.gitea.io/gitea | 已审查 | 2026-06-17 07:38 | 2026-06-17 07:38 |
| GHSA-RM2V-H48J-895M CVE-2026-54304 | n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host | 高危 | npmn8n | 已审查 | 2026-06-17 07:34 | 2026-07-20 21:44 |
| GHSA-QRX8-25QR-5R7V CVE-2026-54309 | n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions | 高危 | npmn8n | 已审查 | 2026-06-17 07:32 | 2026-07-20 21:39 |
| GHSA-2J5H-858J-5MPF CVE-2026-54305 | n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints | 高危 | npmn8n | 已审查 | 2026-06-17 07:32 | 2026-07-20 21:44 |
| GHSA-PMQW-72CG-WX85 CVE-2026-54307 | n8n: Credential Exfiltration via Permission Bypass | 高危 | npmn8n | 已审查 | 2026-06-17 07:02 | 2026-07-09 01:37 |
| GHSA-JQPW-QWW5-CJ4C CVE-2026-54314 | n8n: Denial of Service via ZIP decompression in webhook workflow | 中危 | npmn8n | 已审查 | 2026-06-17 07:01 | 2026-07-20 21:39 |
| GHSA-H3JJ-5F3V-3685 | n8n: Public API Execution Retry Authorization Bypass | 中危 | npmn8n | 已审查 | 2026-06-17 06:40 | 2026-06-17 06:40 |
| GHSA-JWM3-QCFW-C5PP | n8n: Python Code Node AST Validator Bypass | 中危 | npmn8n | 已审查 | 2026-06-17 06:39 | 2026-06-17 06:39 |
| GHSA-42H7-M79W-WVG5 CVE-2026-54302 | n8n: Stored XSS in Chat Trigger Node | 高危 | npmn8n | 已审查 | 2026-06-17 06:39 | 2026-07-20 21:44 |
| GHSA-H86Q-FX34-GFJR CVE-2026-54303 | n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints | 中危 | npmn8n | 已审查 | 2026-06-17 06:39 | 2026-07-20 21:39 |
| GHSA-X6P3-M6H9-FX7R CVE-2026-54312 | n8n: Microsoft SQL Node Prototype Pollution | 高危 | npmn8n | 已审查 | 2026-06-17 06:38 | 2026-07-20 21:39 |
| GHSA-69QJ-PVH9-C5WG | yt-dlp: Arbitrary command injection possible if --exec option used with yt-dlp | 高危 | PyPIyt-dlp | 已审查 | 2026-06-17 06:29 | 2026-06-17 06:29 |
| GHSA-MFG3-P6M3-GJGR CVE-2026-46448 | OpenStack Nova: Nova scheduler hint injection bypasses Placement resource claims and scheduling constraints | 中危 | PyPInova | 已审查 | 2026-06-17 05:32 | 2026-07-21 23:04 |
| GHSA-VR6H-VXQJ-3PJX | Duplicate Advisory: Host environment sanitizer missed two Node.js control variables 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-06-17 05:32 | 2026-06-18 21:02 |
| GHSA-V383-2WGG-V483 | Duplicate Advisory: Shell inline-command parsing could miss an allowlist check 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-06-17 05:32 | 2026-06-18 21:03 |
| GHSA-H9H6-PWQV-J9HV | Duplicate Advisory: Bootstrap token replay could widen pending pairing scopes 已撤回 | 低危 | npmopenclaw | 已审查 | 2026-06-17 05:32 | 2026-06-19 04:12 |