检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-WVGV-4FC3-2RCP CVE-2026-6345 | Mattermost doesn't prevent disclosure of created user password | 中危 | Gogithub.com/mattermost/mattermost-server+1 | 已审查 | 2026-05-18 17:31 | 2026-06-01 23:34 |
| GHSA-WVCV-9XPM-7MQC CVE-2026-28732 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Gogithub.com/mattermost/mattermost-server+1 |
| 已审查 |
| 2026-05-18 17:31 |
| 2026-06-01 23:13 |
| GHSA-VQP5-2MRP-QQXG CVE-2026-6333 | Mattermost doesn't validate the Host header when constructing response URLs for custom slash command | 低危 | Gogithub.com/mattermost/mattermost-server+1 | 已审查 | 2026-05-18 17:31 | 2026-06-01 23:29 |
| GHSA-M79Q-8QF5-V622 CVE-2026-6343 | Mattermost doesn't check public/private permissions | 中危 | Gogithub.com/mattermost/mattermost-plugin-playbooks+1 | 已审查 | 2026-05-18 17:31 | 2026-06-01 23:38 |
| GHSA-GVG4-JHMR-6J23 CVE-2026-4286 | Mattermost doesn't check if {{team_id}} was being changed when updating playbooks | 低危 | Gogithub.com/mattermost/mattermost-plugin-playbooks+1 | 已审查 | 2026-05-18 17:31 | 2026-06-01 23:19 |
| GHSA-9P64-JPC7-M2RP CVE-2026-6346 | Mattermost doesn't sanitize sensitive configuration fields before including them in support packet generation | 高危 | Gogithub.com/mattermost/mattermost-server+1 | 已审查 | 2026-05-18 17:31 | 2026-06-01 23:41 |
| GHSA-8R89-8W26-CQ32 CVE-2026-5163 | Mattermost doesn't verify channel membership when processing AI-assisted message rewrites | 中危 | Gogithub.com/mattermost/mattermost-server+1 | 已审查 | 2026-05-18 17:31 | 2026-06-01 23:27 |
| GHSA-82J6-4FQ7-FX62 CVE-2026-6347 | Mattermost doesn't sanitize sensitive configuration fields in the Mattermost Calls plugin | 高危 | Gogithub.com/mattermost/mattermost-plugin-calls+1 | 已审查 | 2026-05-18 17:31 | 2026-06-01 23:44 |
| GHSA-V549-XX3C-6PC8 CVE-2026-3637 | Mattermost doesn't check the create_post channel permission during post edit operations | 中危 | Gogithub.com/mattermost/mattermost-server+1 | 已审查 | 2026-05-18 17:31 | 2026-06-01 23:01 |
| GHSA-M3P3-8FRQ-Q7QH CVE-2026-2325 | Mattermost doesn't limit the size of the request body on the start meeting API endpoint | 中危 | Gogithub.com/mattermost/mattermost-plugin-msteams-meetings+1 | 已审查 | 2026-05-18 17:31 | 2026-06-01 23:51 |
| GHSA-JX93-PF6X-874R CVE-2026-3495 | Mattermost doesn't escape some variables that could contain malicious content during error page composition | 低危 | Gogithub.com/mattermost/mattermost-server+1 | 已审查 | 2026-05-18 17:31 | 2026-06-01 23:00 |
| GHSA-JP3F-X449-4Q75 CVE-2026-6334 | Mattermost doesn't enforce client identity binding during the OAuth authorization code redemption flow | 低危 | Gogithub.com/mattermost/mattermost-server+1 | 已审查 | 2026-05-18 17:31 | 2026-06-01 23:04 |
| GHSA-HQPJ-F3JH-29VX CVE-2026-4273 | Mattermost doesn't validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation | 低危 | Gogithub.com/mattermost/mattermost-server+1 | 已审查 | 2026-05-18 17:31 | 2026-06-01 23:53 |
| GHSA-CJM8-JXPW-G43M CVE-2026-6340 | Mattermost doesn't validate 7zip archive structure before processing | 中危 | Gogithub.com/mattermost/mattermost-server+1 | 已审查 | 2026-05-18 17:31 | 2026-06-01 23:09 |
| GHSA-8H9W-W78C-VVR3 CVE-2026-28759 | Mattermost does not verify remote cluster channel access when processing shared channel membership removals | 中危 | Gogithub.com/mattermost/mattermost-server+1 | 已审查 | 2026-05-18 17:31 | 2026-06-01 23:48 |
| GHSA-6V92-PH9P-HRPC CVE-2026-8783 | AMF Vulnerable to Improper Resource Shutdown or Release | 低危 | Gogithub.com/omec-project/amf | 已审查 | 2026-05-18 14:31 | 2026-05-29 06:43 |
| GHSA-FXVJ-WQV2-XGCQ CVE-2026-8779 | AMF Improperly Restricts Operations within the Bounds of a Memory Buffer | 低危 | Gogithub.com/omec-project/amf | 已审查 | 2026-05-18 11:31 | 2026-05-29 06:40 |
| GHSA-6H8R-H22R-JJ64 CVE-2026-8782 | AMF Vulnerable to Improper Resource Shutdown or Release | 低危 | Gogithub.com/omec-project/amf | 已审查 | 2026-05-18 11:31 | 2026-05-29 06:43 |
| GHSA-4QF2-P32M-7HMF CVE-2026-8781 | AMF Vulnerable to Improper Resource Shutdown or Release | 低危 | Gogithub.com/omec-project/amf | 已审查 | 2026-05-18 11:31 | 2026-05-29 06:42 |
| GHSA-3X4G-259H-5P7C CVE-2026-8780 | AMF Improperly Restricts Operations within the Bounds of a Memory Buffer | 低危 | Gogithub.com/omec-project/amf | 已审查 | 2026-05-18 11:31 | 2026-05-29 06:41 |
| GHSA-CVWM-VWHP-22JX CVE-2026-8771 | org.linlinjava:litemall-wx-api has an Injection issue | 中危 | Mavenorg.linlinjava:litemall-wx-api | 已审查 | 2026-05-18 08:31 | 2026-05-29 06:34 |
| GHSA-866G-F22W-33X8 CVE-2026-8769 | @ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue | 低危 | npm@ai-sdk/provider-utils | 已审查 | 2026-05-18 08:31 | 2026-05-30 00:18 |
| GHSA-RPC6-9C4P-J5CG CVE-2026-8766 | @kilocode/cli Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor | 低危 | npm@kilocode/cli | 已审查 | 2026-05-18 08:31 | 2026-05-29 04:05 |
| GHSA-FMMW-44RP-JCFP CVE-2026-8759 | Beetl's SpELFunction extension function has an expression injection risk | 中危 | Mavencom.ibeetl:beetl-spring-classic | 已审查 | 2026-05-17 23:31 | 2026-05-23 08:09 |
| GHSA-F63H-WC26-PMVC CVE-2026-8754 | AstrBot: File upload vulnerability in the function post_file of the file astrbot/dashboard/routes/chat.py | 低危 | PyPIAstrBot | 已审查 | 2026-05-17 23:31 | 2026-05-23 08:10 |