检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-W727-595X-PC3R CVE-2026-45306 | pyLoad Has Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory in pyLoad | 中危 | PyPIpyload-ng | 已审查 | 2026-05-15 04:17 | 2026-06-09 18:19 |
| GHSA-G39V-CVJH-8FPF | Home Assistant MCP Server: YAML config backups written under www/ are served unauthenticated at /local/ |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
PyPIha-mcp |
| 已审查 |
| 2026-05-15 04:17 |
| 2026-05-15 04:17 |
| GHSA-4VRC-M9CH-6M3R CVE-2026-45303 | Open WebUI has stored XSS via the HTML renedering view | 高危 | PyPIopen-webui | 已审查 | 2026-05-15 04:16 | 2026-05-19 23:58 |
| GHSA-R8WH-8M7R-FH33 CVE-2026-45301 | Open WebUI: Missing permission check in files API allows authenticated users to list, access and delete every uploaded file | 高危 | PyPIopen-webui | 已审查 | 2026-05-15 04:15 | 2026-05-19 23:58 |
| GHSA-JGG9-RW32-44PJ CVE-2026-45058 | Electerm: Importing unsafe bookmark data could lead to unsafe operation when clicking local type bookmark | 严重 | npmelecterm | 已审查 | 2026-05-15 04:15 | 2026-06-09 18:19 |
| GHSA-6GH2-Q7CP-9QF6 CVE-2026-45299 | Open WebUI has Stored Cross-Site Scripting In Profile Picture | 中危 | PyPIopen-webui | 已审查 | 2026-05-15 04:15 | 2026-05-19 23:57 |
| GHSA-3VCP-CHFH-F6R2 CVE-2026-45021 | Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin | 中危 | Gogithub.com/kumahq/kuma | 已审查 | 2026-05-15 04:15 | 2026-06-09 18:19 |
| GHSA-5QRQ-9645-G5G2 CVE-2026-44541 | ethyca-fides has a DOM-based XSS vulnerability in fides.js via fides_description override | 高危 | PyPIethyca-fides | 已审查 | 2026-05-15 03:04 | 2026-06-09 21:12 |
| GHSA-5F64-7VFC-RCX6 CVE-2026-45011 | Apostrophe has stored XSS via javascript: URL in Image Widget Link | 高危 | npmapostrophe | 已审查 | 2026-05-15 02:27 | 2026-06-13 06:02 |
| GHSA-GF43-24G3-5HW2 CVE-2026-45013 | Apostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Input Validation | 高危 | npmapostrophe | 已审查 | 2026-05-15 02:27 | 2026-06-13 06:02 |
| GHSA-PR28-MF3Q-QPG6 CVE-2026-45012 | Apostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/validate-widget | 高危 | npmapostrophe | 已审查 | 2026-05-15 02:26 | 2026-06-13 06:02 |
| GHSA-RPR9-RXV7-X643 CVE-2026-44990 | Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html` | 严重 | npmsanitize-html | 已审查 | 2026-05-15 02:26 | 2026-06-13 06:02 |
| GHSA-7RX4-C5VX-G8W3 | Karakeep SDK has SSRF via metascraper-logo-favicon that bypasses validateUrl protections | 高危 | npm@karakeep/sdk | 已审查 | 2026-05-15 02:26 | 2026-05-15 02:26 |
| GHSA-QW64-3X98-G7Q2 CVE-2026-44973 | go-billy has path traversal vulnerabilities | 高危 | Gogithub.com/go-git/go-billy/v5+1 | 已审查 | 2026-05-15 02:25 | 2026-06-09 18:26 |
| GHSA-JJ54-R8GM-2FCF CVE-2026-44970 | dbt MCP Server Transmits All MCP Tool Arguments Including Raw SQL and --vars Credentials to dbt Labs Telemetry by Default Without Redaction | 低危 | PyPIdbt-mcp | 已审查 | 2026-05-15 02:25 | 2026-05-15 02:25 |
| GHSA-7XGW-6QF3-7W59 CVE-2026-44969 | dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Logging Is Enabled | 低危 | PyPIdbt-mcp | 已审查 | 2026-05-15 02:24 | 2026-05-15 02:24 |
| GHSA-XPWW-F6PM-CFHQ CVE-2026-44968 | dbt MCP Server has an Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parameters | 中危 | PyPIdbt-mcp | 已审查 | 2026-05-15 02:24 | 2026-05-15 02:24 |
| GHSA-9M65-766C-R333 | TanStack Start - Server Core: Inbound server-function request deserialization could invoke a sibling client-referenced server function | 中危 | npm@tanstack/start-server-core | 已审查 | 2026-05-15 00:37 | 2026-05-15 00:37 |
| GHSA-CCFX-MFMX-2FX9 CVE-2026-44899 | Mistune Image Directive CSS Injection Vulnerability | 中危 | PyPImistune | 已审查 | 2026-05-15 00:36 | 2026-06-09 07:30 |
| GHSA-6269-CQXG-MHHV CVE-2026-44898 | Mistune TOC Anchor Injection XSS | 中危 | PyPImistune | 已审查 | 2026-05-15 00:36 | 2026-06-09 07:30 |
| GHSA-RCGG-9C38-7XPX CVE-2026-45292 | OpenTelemetry Java SDK has Unbounded Memory Allocation in W3C Baggage Propagation | 中危 | Mavenio.opentelemetry:opentelemetry-api+1 | 已审查 | 2026-05-15 00:36 | 2026-06-09 10:01 |
| GHSA-CQPQ-2FGR-8MVC CVE-2026-44884 | Portainer missing authorization on custom template file endpoint, which exposes template content | 中危 | Gogithub.com/portainer/portainer | 已审查 | 2026-05-15 00:34 | 2026-06-09 18:25 |
| GHSA-JVP4-Q659-95MJ CVE-2026-44883 | Portainer: JWT accepted in URL query leaks tokens to logs and referers | 高危 | Gogithub.com/portainer/portainer | 已审查 | 2026-05-15 00:33 | 2026-06-09 18:25 |
| GHSA-5FXQ-QCF3-244W CVE-2026-44849 | Portainer has an endpoint security bypass via Swarm service create/update | 严重 | Gogithub.com/portainer/portainer | 已审查 | 2026-05-15 00:33 | 2026-06-09 18:25 |
| GHSA-MGQ6-4X29-88R3 CVE-2026-44882 | Portainer's Kubernetes middleware continues after token validation failure, bypassing endpoint authorization | 高危 | Gogithub.com/portainer/portainer | 已审查 | 2026-05-15 00:24 | 2026-06-09 18:25 |