检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-88G4-74F3-63X9 | phpMyFAQ has Potential Authenticated Path Traversal in PDF Export | 中危 | Packagistphpmyfaq/phpmyfaq+1 | 已审查 | 2026-08-26 01:28 | 2026-08-26 01:28 |
| GHSA-QJ6X-XX2H-8HVV CVE-2026-55596 | Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript |
当前筛选结果 366,391 条 · 时间按北京时间显示
| 高危 |
npm@platejs/media |
| 已审查 |
| 2026-08-26 00:29 |
| 2026-08-26 00:29 |
| GHSA-M9MQ-7M7Q-XC6P CVE-2026-55557 | browse-mcp has an arbitrary file write via unconfined download and state paths | 高危 | npmbrowse-mcp | 已审查 | 2026-08-26 00:28 | 2026-08-26 00:28 |
| GHSA-Q27Q-98J4-9PFV CVE-2026-55585 | qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()` | 高危 | PyPIqwed | 已审查 | 2026-08-26 00:25 | 2026-08-26 00:25 |
| GHSA-HQ3H-G68C-HP78 CVE-2026-55553 | urllib's cross-origin redirects preserve credential-bearing request headers, leading to potential credential leakage | 高危 | npmurllib | 已审查 | 2026-08-26 00:19 | 2026-08-26 00:19 |
| GHSA-VFP3-V2GW-7WFQ CVE-2026-55677 | Echo: Encoded slash (%2F) bypasses route-level protection and exposes static files | 高危 | Gogithub.com/labstack/echo+2 | 已审查 | 2026-08-26 00:13 | 2026-08-26 00:13 |
| GHSA-XX4J-W367-7247 CVE-2026-55571 | djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls | 高危 | PyPIdjust | 已审查 | 2026-08-26 00:06 | 2026-08-26 00:06 |
| GHSA-8VH3-G2QG-2H2C CVE-2026-55640 | nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default ) | 严重 | PyPInextcloud-mcp-server | 已审查 | 2026-08-26 00:04 | 2026-08-26 00:04 |
| GHSA-8QX3-8GM5-9CJ2 | pickem vulnerable to terminal escape-sequence injection via unsanitized item text | 高危 | npmpickem | 已审查 | 2026-08-25 23:59 | 2026-08-25 23:59 |
| GHSA-8CP3-QXJ6-PX34 | utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion | 高危 | PyPIutcp-http | 已审查 | 2026-08-25 23:57 | 2026-08-25 23:57 |
| GHSA-PPX3-28RW-8FPF CVE-2026-12210 | utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins | 中危 | PyPIutcp-gql+1 | 已审查 | 2026-08-25 23:52 | 2026-08-26 02:09 |
| GHSA-9QHG-99WW-9MQC | utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target | 高危 | PyPIutcp-http | 已审查 | 2026-08-25 23:48 | 2026-08-25 23:48 |
| GHSA-F5PJ-2738-996M CVE-2026-55580 | mcp-shell — Security Disabled by Default in Bare-Binary Deploy Path + Shell Interpreter in Secure-Mode Allowlist | 高危 | Gogithub.com/sonirico/mcp-shell | 已审查 | 2026-08-25 23:46 | 2026-08-25 23:46 |
| GHSA-3X77-WG38-92R3 CVE-2026-55581 | mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable | 高危 | Gogithub.com/sonirico/mcp-shell | 已审查 | 2026-08-25 23:41 | 2026-08-25 23:41 |
| GHSA-74HP-MGGR-HV58 CVE-2026-55582 | mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias | 高危 | Gogithub.com/sonirico/mcp-shell | 已审查 | 2026-08-25 23:39 | 2026-08-25 23:39 |
| GHSA-XJ79-6HH5-9W6Q CVE-2026-15310 | 无摘要 | 低危 | —— | 未审查 | 2026-08-25 23:33 | 2026-09-04 11:31 |
| GHSA-H587-855F-GGWQ CVE-2026-70551 | 无摘要 | 高危 | —— | 未审查 | 2026-08-25 23:33 | 2026-08-25 23:33 |
| GHSA-86R5-W5C4-H244 CVE-2026-79717 | 无摘要 | 中危 | —— | 未审查 | 2026-08-25 23:33 | 2026-08-25 23:33 |
| GHSA-6VWR-3W8Q-MVJ2 CVE-2026-16286 | 无摘要 | 严重 | —— | 未审查 | 2026-08-25 23:33 | 2026-08-25 23:33 |
| GHSA-48R3-MR49-JP8X CVE-2026-16599 | 无摘要 | 中危 | —— | 未审查 | 2026-08-25 23:33 | 2026-08-25 23:33 |
| GHSA-2M4V-9XF8-F95M CVE-2026-69104 | 无摘要 | 高危 | —— | 未审查 | 2026-08-25 23:33 | 2026-08-25 23:33 |
| GHSA-X2CF-FCHR-RW88 CVE-2026-79622 | 无摘要 | 中危 | —— | 未审查 | 2026-08-25 23:32 | 2026-08-25 23:32 |
| GHSA-W4X2-2PCX-2CPC CVE-2026-79623 | 无摘要 | 低危 | —— | 未审查 | 2026-08-25 23:32 | 2026-08-25 23:32 |
| GHSA-VR27-9W4V-HJW2 CVE-2026-75803 | 无摘要 | 严重 | —— | 未审查 | 2026-08-25 23:32 | 2026-09-02 05:31 |
| GHSA-Q5WR-F3RQ-QFCG CVE-2026-78885 | 无摘要 | 中危 | —— | 未审查 | 2026-08-25 23:32 | 2026-08-25 23:32 |