检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-QXVM-R42F-5P8J | AVideo's Meet plugin: `uploadRecordedVideo.json.php` derives `users_id` from the uploaded filename and calls passwordless `User->login()`, allowing any caller with the Meet shared secret to obtain a session as arbitrary users including admin | 高危 | PackagistWWBN/AVideo | 已审查 | 2026-05-16 02:17 | 2026-05-16 02:17 |
| GHSA-RC6V-5RMX-W5MV | arnika is affected by medium-severity issues in UDP rotation, PQC handling, and KMS TLS |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Gogithub.com/arnika-project/arnika |
| 已审查 |
| 2026-05-16 02:13 |
| 2026-06-09 18:34 |
| GHSA-VFVV-C25P-M7MM | rkyv: Panic safety bugs in `InlineVec::clear` and `SerVec::clear` enable arbitrary code execution | 中危 | crates.iorkyv | 已审查 | 2026-05-16 02:09 | 2026-05-16 02:09 |
| GHSA-JRRG-99XH-5J2Q CVE-2026-46491 | SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditional deletion | 高危 | Packagistsimplesamlphp/simplesamlphp-module-casserver | 已审查 | 2026-05-16 02:07 | 2026-06-10 21:41 |
| GHSA-748W-HM6R-QC7V CVE-2026-44692 | Authenticated Sharp users can download unrelated Laravel Storage objects through the generic download endpoint | 高危 | Packagistcode16/sharp | 已审查 | 2026-05-16 02:01 | 2026-06-11 21:30 |
| GHSA-44M2-CRH7-F4Q2 CVE-2026-45717 | Budibase: `PUT /api/datasources/:datasourceId` is protected only by `TABLE/READ` permission instead of builder access, allowing any authenticated app user to overwrite datasource connection parameters including host, port, and URL | 高危 | npm@budibase/server | 已审查 | 2026-05-16 01:59 | 2026-06-09 07:51 |
| GHSA-FGQV-JH4G-PVG2 CVE-2026-45715 | Budibase: SSRF Bypass via HTTP Redirect in REST Datasource Integration | 高危 | npm@budibase/server | 已审查 | 2026-05-16 01:53 | 2026-06-09 07:50 |
| GHSA-RPJ4-7X2V-WJRF CVE-2026-45548 | Budibase: SSRF in AI Extract File Automation Step via Missing IP Blacklist Validation | 高危 | npm@budibase/server | 已审查 | 2026-05-16 01:47 | 2026-06-09 07:50 |
| GHSA-P6V2-XCPG-H6XW CVE-2026-45364 | Better Auth: Rate limiter keys IPv6 addresses individually and is bypassable via prefix rotation | 高危 | npmbetter-auth | 已审查 | 2026-05-16 01:41 | 2026-06-09 18:26 |
| GHSA-WXW3-Q3M9-C3JR | Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCE | 中危 | npmbetter-auth | 已审查 | 2026-05-16 01:33 | 2026-05-16 01:33 |
| GHSA-MXG3-432P-MR72 | goshs: SSH host key verification disabled, allowing transparent MITM of every tunnelled HTTP request | 高危 | Gogoshs.de/goshs/v2 | 已审查 | 2026-05-16 01:17 | 2026-05-16 01:17 |
| GHSA-6WXC-8MGQ-W26M CVE-2026-45106 | Weblate: Stored HTML injection in editor search preview | 中危 | PyPIweblate | 已审查 | 2026-05-16 01:14 | 2026-06-11 21:30 |
| GHSA-3G8V-8R37-CGJM CVE-2026-45062 | FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files | 高危 | Gogithub.com/dunglas/frankenphp | 已审查 | 2026-05-16 01:09 | 2026-06-11 02:41 |
| GHSA-3363-2PH6-35WH CVE-2026-44716 | Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File Read via `%2F`-Encoded Separator | 高危 | PyPIpipecat-ai | 已审查 | 2026-05-16 00:55 | 2026-06-10 21:41 |
| GHSA-64RR-PP78-62WW CVE-2026-41147 | NukeViet CMS: Stored Cross-Site Scripting (XSS) via insufficient server-side input sanitization in Request class | 高危 | Packagistnukeviet/nukeviet | 已审查 | 2026-05-16 00:45 | 2026-06-09 07:20 |
| GHSA-27W2-87XV-37C6 CVE-2026-40092 | nimiq-keys: Unchecked Ed25519 signature length in TaggedPublicKey::verify causes remote node panic via DHT | 高危 | crates.ionimiq-keys | 已审查 | 2026-05-16 00:31 | 2026-06-09 04:14 |
| GHSA-GCMJ-C9GG-9VH6 CVE-2026-22810 | @joplin/onenote-converter: Path traversal in OneNote importer allows overwriting arbitrary files | 高危 | npm@joplin/onenote-converter | 已审查 | 2026-05-16 00:27 | 2026-05-20 00:08 |
| GHSA-CVRM-5HP6-H523 CVE-2025-65954 | SimpleSAMLphp casserver: Open Redirect in logout | 中危 | Packagistsimplesamlphp/simplesamlphp-module-casserver | 已审查 | 2026-05-16 00:21 | 2026-05-20 00:08 |
| GHSA-FV2F-RW9F-V9CM CVE-2026-38728 | smtp-server's command parser memory exhaustion denial-of-service | 高危 | npmsmtp-server | 已审查 | 2026-05-15 23:30 | 2026-06-30 06:57 |
| GHSA-75CM-X2W3-8MGF CVE-2026-2652 | MLflow: unauthenticated access to certain FastAPI routes | 高危 | PyPImlflow | 已审查 | 2026-05-15 11:30 | 2026-05-22 03:35 |
| GHSA-FM77-94QM-4894 CVE-2026-8634 | Crabbox: environment variable exposure vulnerability | 严重 | Gogithub.com/openclaw/crabbox | 已审查 | 2026-05-15 05:30 | 2026-07-21 22:40 |
| GHSA-4G9M-RFFV-H6WQ CVE-2026-8621 | Crabbox: authentication bypass vulnerability that allows impersonation of others by spoofing identity headers | 高危 | Gogithub.com/openclaw/crabbox | 已审查 | 2026-05-15 05:30 | 2026-05-22 03:29 |
| GHSA-248R-7H7Q-CR24 CVE-2026-45411 | vm2 Has a Sandbox Breakout Using Async Generator | 严重 | npmvm2 | 已审查 | 2026-05-15 05:14 | 2026-05-15 05:14 |
| GHSA-5V57-8RXJ-3P2R CVE-2026-45370 | python-utcp: Full Process Environment Exposed to CLI Subprocess - Secrets Leakage via Command Injection | 高危 | PyPIutcp-cli | 已审查 | 2026-05-15 04:56 | 2026-05-16 07:47 |
| GHSA-33P6-5JXP-P3X4 CVE-2026-45369 | utcp-cli Vulnerable to Command Injection via Unsanitized Argument Substitution in CLI Communication Protocol | 严重 | PyPIutcp-cli | 已审查 | 2026-05-15 04:56 | 2026-05-16 07:46 |