检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-Q27Q-98J4-9PFV CVE-2026-55585 | qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()` | 高危 | PyPIqwed | 已审查 | 2026-08-26 00:25 | 2026-08-26 00:25 |
| GHSA-HQ3H-G68C-HP78 CVE-2026-55553 | urllib's cross-origin redirects preserve credential-bearing request headers, leading to potential credential leakage |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
npmurllib |
| 已审查 |
| 2026-08-26 00:19 |
| 2026-08-26 00:19 |
| GHSA-VFP3-V2GW-7WFQ CVE-2026-55677 | Echo: Encoded slash (%2F) bypasses route-level protection and exposes static files | 高危 | Gogithub.com/labstack/echo+2 | 已审查 | 2026-08-26 00:13 | 2026-08-26 00:13 |
| GHSA-XX4J-W367-7247 CVE-2026-55571 | djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls | 高危 | PyPIdjust | 已审查 | 2026-08-26 00:06 | 2026-08-26 00:06 |
| GHSA-8VH3-G2QG-2H2C CVE-2026-55640 | nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default ) | 严重 | PyPInextcloud-mcp-server | 已审查 | 2026-08-26 00:04 | 2026-08-26 00:04 |
| GHSA-8QX3-8GM5-9CJ2 | pickem vulnerable to terminal escape-sequence injection via unsanitized item text | 高危 | npmpickem | 已审查 | 2026-08-25 23:59 | 2026-08-25 23:59 |
| GHSA-8CP3-QXJ6-PX34 | utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion | 高危 | PyPIutcp-http | 已审查 | 2026-08-25 23:57 | 2026-08-25 23:57 |
| GHSA-PPX3-28RW-8FPF CVE-2026-12210 | utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins | 中危 | PyPIutcp-gql+1 | 已审查 | 2026-08-25 23:52 | 2026-08-26 02:09 |
| GHSA-9QHG-99WW-9MQC | utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target | 高危 | PyPIutcp-http | 已审查 | 2026-08-25 23:48 | 2026-08-25 23:48 |
| GHSA-F5PJ-2738-996M CVE-2026-55580 | mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist | 高危 | Gogithub.com/sonirico/mcp-shell | 已审查 | 2026-08-25 23:46 | 2026-08-25 23:46 |
| GHSA-3X77-WG38-92R3 CVE-2026-55581 | mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable | 高危 | Gogithub.com/sonirico/mcp-shell | 已审查 | 2026-08-25 23:41 | 2026-08-25 23:41 |
| GHSA-74HP-MGGR-HV58 CVE-2026-55582 | mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias | 高危 | Gogithub.com/sonirico/mcp-shell | 已审查 | 2026-08-25 23:39 | 2026-08-25 23:39 |
| GHSA-MW6R-2HVM-4RP2 CVE-2026-55546 | qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input | 严重 | PyPIqwed-mcp | 已审查 | 2026-08-25 23:26 | 2026-08-25 23:26 |
| GHSA-6G6R-Q6GW-W8FG CVE-2026-55536 | PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92) | 严重 | PyPIPraisonAI | 已审查 | 2026-08-25 23:22 | 2026-08-25 23:22 |
| GHSA-PVPH-5J39-V8QC CVE-2026-55532 | PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server | 高危 | PyPIPraisonAI | 已审查 | 2026-08-25 23:18 | 2026-08-25 23:18 |
| GHSA-GFQ8-HMPH-9GJV CVE-2026-55533 | PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret | 高危 | PyPIPraisonAI | 已审查 | 2026-08-25 23:15 | 2026-08-25 23:15 |
| GHSA-2JGC-F764-C5R2 CVE-2026-55539 | PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete | 高危 | PyPIPraisonAI | 已审查 | 2026-08-25 23:14 | 2026-08-25 23:14 |
| GHSA-GXMW-5F7X-6G22 CVE-2026-55527 | praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location | 高危 | PyPIpraisonaiagents | 已审查 | 2026-08-25 23:09 | 2026-08-25 23:09 |
| GHSA-PVXX-R596-F5QJ CVE-2026-55541 | PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced | 高危 | PyPIPraisonAI | 已审查 | 2026-08-25 23:06 | 2026-08-25 23:06 |
| GHSA-HMFX-4V44-9QW9 CVE-2026-55535 | PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation | 中危 | PyPIPraisonAI | 已审查 | 2026-08-25 23:02 | 2026-08-25 23:02 |
| GHSA-RG5Q-PP8P-F7JM CVE-2026-55537 | PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114 | 高危 | PyPIPraisonAI | 已审查 | 2026-08-25 22:59 | 2026-08-25 22:59 |
| GHSA-R7V3-X45F-G7HP CVE-2026-55538 | PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated | 高危 | PyPIPraisonAI | 已审查 | 2026-08-25 22:56 | 2026-08-25 22:56 |
| GHSA-CH89-H4R2-C8F8 CVE-2026-55540 | PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks | 高危 | PyPIPraisonAI | 已审查 | 2026-08-25 22:54 | 2026-08-25 22:54 |
| GHSA-CFXV-8FW8-RWPV CVE-2026-55530 | praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool | 中危 | PyPIpraisonaiagents | 已审查 | 2026-08-25 22:46 | 2026-08-25 22:46 |
| GHSA-VG6P-V9VM-6FGJ CVE-2026-55524 | praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap) | 高危 | PyPIpraisonaiagents | 已审查 | 2026-08-25 22:43 | 2026-08-25 22:43 |