检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-FFHM-8FWQ-7Q27 | Duplicate Advisory: OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-06-13 08:34 | 2026-08-26 00:39 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| GHSA-3QG8-HQ7J-JJ33 |
Duplicate Advisory: OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers 已撤回 |
| 高危 |
npmopenclaw |
| 已审查 |
| 2026-06-13 08:34 |
| 2026-08-28 23:55 |
| GHSA-35C7-4R45-9GV3 | Duplicate Advisory: OpenClaw: QQBot pre-dispatch slash commands could skip allowFrom checks 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-06-13 08:34 | 2026-08-28 23:55 |
| GHSA-8C9Q-7855-WFXQ CVE-2026-54090 | File Browser has a Command Execution Allowlist Bypass via Shell Metacharacter Injection | 高危 | Gogithub.com/filebrowser/filebrowser/v2 | 已审查 | 2026-06-13 06:52 | 2026-07-21 21:54 |
| GHSA-J9JX-HP4C-GHHH CVE-2026-54091 | File Browser has incorrect access control for public directory shares via rule path rebasing | 高危 | Gogithub.com/filebrowser/filebrowser/v2 | 已审查 | 2026-06-13 05:53 | 2026-07-21 22:43 |
| GHSA-GXJX-7M74-HCQ8 CVE-2026-54093 | File Browser: FilePath traversal in download-as-zip/tar via Windows-style backslash separators in stored filenames | 中危 | Gogithub.com/filebrowser/filebrowser+1 | 已审查 | 2026-06-13 05:53 | 2026-06-13 05:53 |
| GHSA-239W-M3H6-CH8V CVE-2026-54094 | File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope | 中危 | Gogithub.com/filebrowser/filebrowser+1 | 已审查 | 2026-06-13 05:53 | 2026-06-13 05:53 |
| GHSA-W5FM-68J4-FPC4 CVE-2026-54092 | File Browser has a DoS Vulnerability via Public Login API | 高危 | Gogithub.com/filebrowser/filebrowser+1 | 已审查 | 2026-06-13 05:51 | 2026-07-21 22:42 |
| GHSA-3Q2P-72CJ-682C CVE-2026-54096 | File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path | 高危 | Gogithub.com/filebrowser/filebrowser+1 | 已审查 | 2026-06-13 05:07 | 2026-07-21 22:45 |
| GHSA-VC8P-8PXG-RFWG CVE-2026-54697 | ConnectBot SSH Client Library: Excessive allocation and integer overflow in DER private-key parsing | 中危 | Mavenorg.connectbot.sshlib:sshlib | 已审查 | 2026-06-13 05:02 | 2026-07-09 01:35 |
| GHSA-CH3Q-CW5R-F4HG CVE-2026-54700 | ConnectBot SSH Client Library: Unbounded SSH field lengths can cause excessive memory allocation | 中危 | Mavenorg.connectbot.sshlib:sshlib | 已审查 | 2026-06-13 05:02 | 2026-07-09 01:35 |
| GHSA-5WW9-JG6Q-38R7 CVE-2026-54097 | File Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix | 高危 | Gogithub.com/filebrowser/filebrowser+1 | 已审查 | 2026-06-13 05:00 | 2026-07-21 22:44 |
| GHSA-X4QR-QW6H-WVXQ CVE-2026-46371 | Fleet: Observer-level enrollment secret extraction via ORDER BY oracle on Apple MDM commands endpoint | 中危 | Gogithub.com/fleetdm/fleet/v4 | 已审查 | 2026-06-13 05:00 | 2026-06-27 04:20 |
| GHSA-VXM7-9X8V-8GM4 CVE-2026-46370 | Fleet has observer-level enrollment secret extraction via ORDER BY oracle on labels host-listing endpoint | 中危 | Gogithub.com/fleetdm/fleet/v4 | 已审查 | 2026-06-13 05:00 | 2026-06-27 04:20 |
| GHSA-W22M-HVVM-XMWX CVE-2026-44311 | Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization | 中危 | npmfabric | 已审查 | 2026-06-13 05:00 | 2026-07-19 01:26 |
| GHSA-CHGR-C6PX-7XPP | PyO3 has a missing `Sync` bound on `PyCFunction::new_closure` closures | 中危 | crates.iopyo3 | 已审查 | 2026-06-13 04:09 | 2026-06-13 04:09 |
| GHSA-GV7W-RQVM-QJHR | Withdrawn Advisory: esbuild: Missing binary integrity verification in Deno module enables remote code execution via NPM_CONFIG_REGISTRY 已撤回 | 高危 | npmesbuild | 已审查 | 2026-06-13 04:08 | 2026-06-17 21:42 |
| GHSA-G7R4-M6W7-QQQR | esbuild allows arbitrary file read when running the development server on Windows | 低危 | npmesbuild | 已审查 | 2026-06-13 04:08 | 2026-06-13 04:08 |
| GHSA-FP5J-4FJ2-4JVQ CVE-2026-53999 | Radius Controller May Delete a Container Resource via an Injected Deployment Annotation (Multi-Tenant Installs) | 高危 | Gogithub.com/radius-project/radius | 已审查 | 2026-06-13 04:08 | 2026-06-13 04:08 |
| GHSA-PJPJ-V387-X4VQ CVE-2026-11607 | TYPO3 CMS has Broken Access Control in its Form Framework | 高危 | Packagisttypo3/cms-core+1 | 已审查 | 2026-06-13 04:08 | 2026-06-13 04:08 |
| GHSA-F34X-RX2W-7PM3 CVE-2026-47349 | TYPO3 CMS has Broken Access Control in the Recycler Module | 中危 | Packagisttypo3/cms-core+1 | 已审查 | 2026-06-13 04:08 | 2026-06-13 04:08 |
| GHSA-3P42-W5CH-GG42 CVE-2026-47347 | TYPO3 CMS has an Open Redirect Vulnerability via Core Utilities | 中危 | Packagisttypo3/cms-core | 已审查 | 2026-06-13 04:07 | 2026-06-13 04:07 |
| GHSA-3V8V-4WG6-R7QH CVE-2026-47343 | TYPO3 CMS: Destructive Actions on File Mount Folders | 高危 | Packagisttypo3/cms-core | 已审查 | 2026-06-13 04:07 | 2026-06-13 04:07 |
| GHSA-P5J5-4J3Q-8MQ8 CVE-2026-47345 | TYPO3 HTML Sanitizer allows Cross-site Scripting | 中危 | Packagisttypo3/html-sanitizer | 已审查 | 2026-06-13 04:07 | 2026-06-13 04:07 |
| GHSA-36HH-V3QG-5JQ4 | PyO3 has an Out-of-bounds Read in `nth` / `nth_back` for `PyList` and `PyTuple` iterators | 高危 | crates.iopyo3 | 已审查 | 2026-06-13 03:32 | 2026-06-13 03:32 |