检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-G8RR-7RJ2-F627 CVE-2026-47412 | praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id} | 高危 | PyPIpraisonai-platform | 已审查 | 2026-06-01 22:24 | 2026-06-01 22:24 |
| GHSA-XWQ8-FRCG-77Q8 CVE-2026-47415 | praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, cross-workspace read/update/delete IDOR |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
PyPIpraisonai-platform |
| 已审查 |
| 2026-06-01 22:24 |
| 2026-06-01 22:24 |
| GHSA-8G2P-PQM3-FCFH CVE-2026-47413 | praisonai-platform: Any workspace member can add arbitrary user as owner via POST /workspaces/{id}/members | 严重 | PyPIpraisonai-platform | 已审查 | 2026-06-01 22:23 | 2026-06-01 22:23 |
| GHSA-RCMC-Q9RJ-4WMQ CVE-2026-47411 | praisonai-platform: Any workspace member can rewrite workspace name, description, and settings via PATCH /workspaces/{id} | 中危 | PyPIpraisonai-platform | 已审查 | 2026-06-01 22:23 | 2026-06-01 22:23 |
| GHSA-CP4F-5M9R-5JC2 CVE-2026-47417 | praisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDOR | 高危 | PyPIpraisonai-platform | 已审查 | 2026-06-01 22:19 | 2026-06-01 22:19 |
| GHSA-943M-6WX2-RC2J CVE-2026-47418 | praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR | 高危 | PyPIpraisonai-platform | 已审查 | 2026-06-01 22:17 | 2026-06-01 22:17 |
| GHSA-Q53Q-5R4J-5729 CVE-2026-47425 | rattler has an entry-point path traversal in noarch:python install (arbitrary file write) | 中危 | crates.iopy-rattler+1 | 已审查 | 2026-06-01 22:15 | 2026-06-09 19:52 |
| GHSA-2H32-95RG-CPPP CVE-2026-47428 | Vitest browser mode serves unsanitized otelCarrier query parameter as inline script | 严重 | npm@vitest/browser | 已审查 | 2026-06-01 22:12 | 2026-06-01 22:12 |
| GHSA-5XRQ-8626-4RWP CVE-2026-47429 | When Vitest UI server is listening, arbitrary file can be read and executed | 严重 | npmvitest | 已审查 | 2026-06-01 22:09 | 2026-08-14 02:19 |
| GHSA-87XG-PXX2-7HVX CVE-2026-47423 | DOMPurify XSS via selectedcontent re-clone | 高危 | npmdompurify | 已审查 | 2026-06-01 22:07 | 2026-06-01 22:07 |
| GHSA-4G6J-G789-RGHM CVE-2026-48119 | Nezha's authenticated agents can forge service-monitor results for other users' services | 高危 | Gogithub.com/nezhahq/nezha | 已审查 | 2026-06-01 22:05 | 2026-06-27 05:28 |
| GHSA-63GR-G7JC-V8RG CVE-2026-50287 | @agenticmail/mcp Missing Authentication for Critical Function | 高危 | npm@agenticmail/mcp | 已审查 | 2026-06-01 21:58 | 2026-06-13 06:01 |
| GHSA-VQC2-C9JH-3JJV CVE-2026-49328 | Apache Fesod is vulnerable to Server-Side Request Forgery through its UrlImageConverter component | 中危 | Mavenorg.apache.fesod:fesod-sheet | 已审查 | 2026-06-01 20:30 | 2026-07-09 04:23 |
| GHSA-VR7M-C6V4-8CX8 CVE-2026-48726 | Apache Airflow: Auth manager doesn't invalidate JWT tokens after users click logout | 中危 | PyPIapache-airflow | 已审查 | 2026-06-01 17:31 | 2026-07-09 03:45 |
| GHSA-QPHR-3MVQ-V466 CVE-2026-46764 | Apache Airflow has an Authorization Bypass Through User-Controlled Key | 中危 | PyPIapache-airflow | 已审查 | 2026-06-01 17:31 | 2026-07-10 05:03 |
| GHSA-MW4M-QHPG-J82M CVE-2026-48827 | Apache MINA SSHD bundle sshd-git has a path traversal vulnerability | 高危 | Mavenorg.apache.sshd:sshd-git | 已审查 | 2026-06-01 17:31 | 2026-07-10 05:08 |
| GHSA-HF52-78X8-6W3W CVE-2026-49270 | Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All have an Exposure of Sensitive Information Through Metadata vulnerability | 中危 | Mavenorg.apache.activemq:activemq-all+2 | 已审查 | 2026-06-01 17:31 | 2026-07-10 05:09 |
| GHSA-CPW7-G3P5-QRFQ CVE-2026-46605 | Apache ActiveMQ server has an incomplete authorization workflow | 中危 | Mavenorg.apache.activemq:apache-activemq | 已审查 | 2026-06-01 17:31 | 2026-07-10 05:04 |
| GHSA-99QX-5QQR-4J95 CVE-2026-49157 | Apache ActiveMQ has an Incorrect Default Permissions vulnerability | 高危 | Mavenorg.apache.activemq:apache-activemq | 已审查 | 2026-06-01 17:31 | 2026-07-10 05:08 |
| GHSA-799X-QP47-8QWQ CVE-2026-49267 | Apache Airflow has no certificate validation on SMTP STARTTLS connections | 中危 | PyPIapache-airflow | 已审查 | 2026-06-01 17:31 | 2026-07-10 05:11 |
| GHSA-5J6P-JRRM-6X94 CVE-2026-49298 | Apache Airflow: Execution API JWT leaked via KubernetesExecutor worker command-line args | 高危 | PyPIapache-airflow-core | 已审查 | 2026-06-01 17:31 | 2026-07-09 03:45 |
| GHSA-4C39-FWGJ-4VQ7 CVE-2026-49361 | Apache Fluss: Unauthenticated remote attackers can exhaust JVM heap memory using crafted frame headers via TabletServer/CoordinatorServer | 高危 | Mavenorg.apache.fluss:fluss-common | 已审查 | 2026-06-01 17:31 | 2026-07-09 03:44 |
| GHSA-X5WM-J6WH-2834 CVE-2026-45426 | Apache Airflow has an Incorrect Authorization issue | 低危 | PyPIapache-airflow | 已审查 | 2026-06-01 17:31 | 2026-07-10 05:00 |
| GHSA-WR76-29CR-67W8 CVE-2026-42359 | Apache Airflow has a Deserialization of Untrusted Data vulnerability | 高危 | PyPIapache-airflow | 已审查 | 2026-06-01 17:31 | 2026-07-10 05:03 |
| GHSA-V853-W46P-FV2H CVE-2026-45505 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ have a Code Injection issue | 高危 | Mavenorg.apache.activemq:activemq-all+2 | 已审查 | 2026-06-01 17:31 | 2026-07-10 05:00 |