检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-7WW9-85PG-CV4X CVE-2026-55534 | PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution | 高危 | PyPIPraisonAI | 已审查 | 2026-08-25 22:42 | 2026-08-25 22:42 |
| GHSA-X44H-65QV-CW74 CVE-2026-55526 | praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`) |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
PyPIpraisonaiagents |
| 已审查 |
| 2026-08-25 22:37 |
| 2026-08-25 22:38 |
| GHSA-WV94-5QCP-6M36 CVE-2026-55531 | PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced) | 中危 | PyPIPraisonAI | 已审查 | 2026-08-25 22:34 | 2026-08-25 22:34 |
| GHSA-7G3P-92QQ-8WVH CVE-2026-55528 | praisonaiagents: AgentServer declares auth_token but never enforces it on any route | 高危 | PyPIpraisonaiagents | 已审查 | 2026-08-25 22:31 | 2026-08-25 22:31 |
| GHSA-WJ6G-V78P-6FX3 CVE-2026-55529 | PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server | 中危 | PyPIPraisonAI | 已审查 | 2026-08-25 22:26 | 2026-08-25 22:26 |
| GHSA-8HJW-25CG-G52H CVE-2026-55523 | praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets | 高危 | PyPIpraisonaiagents | 已审查 | 2026-08-25 22:18 | 2026-08-25 22:18 |
| GHSA-HXMV-C4G6-5FQC CVE-2026-55522 | PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code | 高危 | PyPIPraisonAI+1 | 已审查 | 2026-08-25 22:15 | 2026-08-25 22:15 |
| GHSA-5R34-2G38-6569 CVE-2026-55525 | praisonaiagents web_crawl vulnerable to SSRF via redirect-following | 高危 | PyPIpraisonaiagents | 已审查 | 2026-08-25 22:05 | 2026-08-25 22:05 |
| GHSA-VP9C-2PJM-8925 | Duplicate Advisory: Allowlisted pickle loaders still permit code execution in current source 已撤回 | 严重 | PyPInltk | 已审查 | 2026-08-25 20:31 | 2026-09-02 22:41 |
| GHSA-JX89-3QG8-P2MR | Duplicate Advisory: Entity-expansion DoS (billion laughs) via remaining raw ElementTree parses (CWE-776) 已撤回 | 高危 | PyPInltk | 已审查 | 2026-08-25 11:32 | 2026-09-02 22:39 |
| GHSA-GX65-C5HJ-VPV5 | Duplicate Advisory: [CWE-502] Unsafe Pickle Deserialization in TransitionParser Allows Remote Code Execution 已撤回 | 严重 | PyPInltk | 已审查 | 2026-08-25 11:32 | 2026-09-02 22:40 |
| GHSA-CRP9-R7RQ-C8CG | Duplicate Advisory: pathsec SSRF protection can be bypassed when a proxy is configured 已撤回 | 高危 | PyPInltk | 已审查 | 2026-08-25 11:32 | 2026-09-02 22:40 |
| GHSA-54XP-3WW7-6WJG | Duplicate Advisory: Uncontrolled search path when invoking the Graphviz 'dot' binary (CWE-426/CWE-427) 已撤回 | 高危 | PyPInltk | 已审查 | 2026-08-25 11:32 | 2026-09-02 04:25 |
| GHSA-FX4F-MHW4-QM7J | vibeio-http has a DoS vulnerability in HTTP/1.x chunked encoding parser triggered by maliciously crafted chunk lengths | 中危 | crates.iovibeio-http | 已审查 | 2026-08-25 06:05 | 2026-08-25 06:05 |
| GHSA-W8J7-39HP-8X59 | Cloudreve's remote download file paths can escape the selected destination directory | 中危 | Gogithub.com/cloudreve/Cloudreve/v4 | 已审查 | 2026-08-25 06:03 | 2026-08-25 06:03 |
| GHSA-VX2M-JPXR-XV7W | Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint | 中危 | Gogithub.com/cloudreve/Cloudreve/v4 | 已审查 | 2026-08-25 06:01 | 2026-08-25 06:01 |
| GHSA-JM48-M3RR-9HGG CVE-2026-55477 | 3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation | 高危 | Gogithub.com/mhsanaei/3x-ui/v2+1 | 已审查 | 2026-08-25 05:05 | 2026-08-25 05:05 |
| GHSA-W67G-5RQW-F597 | Gorilla WebSocket Uses Cryptographically Weak PRNG for WebSocket Mask Key | 中危 | Gogithub.com/gorilla/websocket | 已审查 | 2026-08-25 05:00 | 2026-08-25 05:00 |
| GHSA-4PH6-MJV7-3FQ6 | netfoil vulnerable to improper handling of untrusted DoH response data | 低危 | Gogithub.com/tinfoil-factory/netfoil | 已审查 | 2026-08-25 04:43 | 2026-08-25 04:43 |
| GHSA-FWJF-M4QW-9F2X CVE-2026-54625 | django CMS: Page cache ignores plugin-declared Vary headers (disclosure & poisoning) | 中危 | PyPIdjango-cms | 已审查 | 2026-08-25 04:09 | 2026-08-25 04:09 |
| GHSA-8JJ7-4V57-FRF5 CVE-2026-54623 | django CMS: Plugin move endpoint allows cyclic reparenting (DoS) | 高危 | PyPIdjango-cms | 已审查 | 2026-08-25 04:09 | 2026-08-25 04:09 |
| GHSA-3GJW-F78C-VVPW | tokio-postgres: Panic on a `DataRow` with fewer fields than columns allows denial of service | 中危 | crates.iotokio-postgres | 已审查 | 2026-08-25 03:49 | 2026-08-25 03:49 |
| GHSA-RGQC-3X5P-6GWG | postgres-protocol: Panic decoding a malformed `hstore` value allows denial of service | 中危 | crates.iopostgres-protocol | 已审查 | 2026-08-25 03:47 | 2026-08-25 03:47 |
| GHSA-5X78-73V4-XG6W | postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service | 高危 | crates.iopostgres-protocol | 已审查 | 2026-08-25 03:43 | 2026-08-25 03:43 |
| GHSA-9284-FJC3-FMMJ CVE-2026-54050 | Sakai Profile Image Deletion has an IDOR | 中危 | Mavenorg.sakaiproject.profile2:profile2-api+1 | 已审查 | 2026-08-25 03:40 | 2026-08-25 03:40 |