检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-87F9-HVMW-GH4P CVE-2026-41159 | Mermaid: Improper sanitization of configuration leads to CSS injection | 中危 | npmmermaid | 已审查 | 2026-05-12 03:37 | 2026-07-02 03:21 |
| GHSA-6M6C-36F7-FHXH CVE-2026-41150 | Mermaid Gantt Charts are vulnerable to an Infinite Loop DoS |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
npmmermaid |
| 已审查 |
| 2026-05-12 03:36 |
| 2026-06-09 18:28 |
| GHSA-GHCM-XQFW-Q4VR CVE-2026-41149 | Mermaid: Improper sanitization of `classDef` in state diagrams leads to HTML injection | 中危 | npmmermaid | 已审查 | 2026-05-12 03:36 | 2026-06-09 07:21 |
| GHSA-XCJ9-5M2H-648R CVE-2026-41148 | Mermaid: Improper sanitization of `classDefs` in diagrams leads to CSS injection | 中危 | npmmermaid | 已审查 | 2026-05-12 03:36 | 2026-06-09 07:20 |
| GHSA-F633-865Q-2MHH CVE-2026-40607 | MantisBT is Vulnerable to Stored XSS in Saved-Filter Owner Column | 高危 | Packagistmantisbt/mantisbt | 已审查 | 2026-05-12 03:35 | 2026-06-09 07:20 |
| GHSA-6JH4-47V2-4G37 CVE-2026-40598 | MantisBT has Potential Referer-Based Reflected HTML Injection / XSS in Tag Update Page | 中危 | Packagistmantisbt/mantisbt | 已审查 | 2026-05-12 03:35 | 2026-06-09 07:20 |
| GHSA-9C3J-XM6V-J7J3 CVE-2026-40597 | MantisBT has a Content Security Policy bypass via attachments | 高危 | Packagistmantisbt/mantisbt | 已审查 | 2026-05-12 03:34 | 2026-06-09 07:20 |
| GHSA-J3V9-553H-X28J CVE-2026-40596 | MantisBT is Vulnerable to XSS leading to account takeover via updating a user's font family preference | 高危 | Packagistmantisbt/mantisbt | 已审查 | 2026-05-12 03:34 | 2026-06-09 07:20 |
| GHSA-QJ6W-V29Q-4RGX CVE-2026-39960 | MantisBT is Vulnerable to Stored XSS in Custom Field Textarea Values | 中危 | Packagistmantisbt/mantisbt | 已审查 | 2026-05-12 03:34 | 2026-06-09 04:14 |
| GHSA-5VPG-RJ7Q-QPW2 CVE-2026-39850 | Yii 2: Local file inclusion via view parameter name collision | 高危 | Packagistyiisoft/yii2 | 已审查 | 2026-05-12 03:34 | 2026-06-09 04:14 |
| GHSA-CRMX-4P49-46M2 CVE-2026-34970 | MantisBT: Bugnote Revision Page Leaks Private Issue Metadata After Issue Access Is Revoked | 中危 | Packagistmantisbt/mantisbt | 已审查 | 2026-05-12 03:33 | 2026-06-05 22:12 |
| GHSA-H4X5-GVX6-3RWC CVE-2026-34754 | MantisBT has an Authorization Bypass that Allows Uploading Attachments to Private Issues via REST API | 中危 | Packagistmantisbt/mantisbt | 已审查 | 2026-05-12 03:33 | 2026-06-05 22:12 |
| GHSA-RMP5-5JJ7-GMVF CVE-2026-34744 | MantisBT has an authorization bypass that allows reading attachments after losing access to a private issue | 中危 | Packagistmantisbt/mantisbt | 已审查 | 2026-05-12 03:32 | 2026-06-05 22:12 |
| GHSA-GGW7-9675-6V4V CVE-2026-34579 | MantisBT has an authorization bypass in private issue monitoring | 中危 | Packagistmantisbt/mantisbt | 已审查 | 2026-05-12 03:32 | 2026-06-05 22:12 |
| GHSA-FVJF-68WH-RWP2 CVE-2026-34463 | MantisBT is Vulnerable to Stored HTML Injection/XSS in Clone Issue Form | 高危 | Packagistmantisbt/mantisbt | 已审查 | 2026-05-12 03:32 | 2026-06-05 22:12 |
| GHSA-FRF7-JHP9-JXM6 CVE-2026-34390 | MantisBT Vulnerable to Privilege Escalation from Manager to Administrator | 中危 | Packagistmantisbt/mantisbt | 已审查 | 2026-05-12 03:32 | 2026-06-05 22:12 |
| GHSA-XPR6-2HGM-4WWP | Duplicate Advisory: OpenClaw vulnerable to arbitrary code execution via attacker-controlled setup-api.js loaded from cwd during env-key resolution 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-05-12 02:31 | 2026-05-18 23:31 |
| GHSA-V8J2-5F9P-FMH4 | Duplicate Advisory: OpenClaw's Webhooks SecretRef route secret remains valid after rotation/reload 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-05-12 02:31 | 2026-05-18 23:31 |
| GHSA-9J32-3M66-MC4M | Duplicate Advisory: OpenClaw: Hook mapping templates could bypass hook session-key opt-in 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-05-12 02:31 | 2026-05-18 23:29 |
| GHSA-5JGM-F9WR-9QM7 | Duplicate Advisory: OpenClaw: Workspace dotenv files cannot override connector endpoint hosts 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-05-12 02:31 | 2026-05-18 23:29 |
| GHSA-W626-296M-8F85 | Duplicate Advisory: OpenClaw's ACP child sessions inherit subagent security envelope constraints 已撤回 | 低危 | npmopenclaw | 已审查 | 2026-05-12 02:31 | 2026-05-18 23:29 |
| GHSA-P3PV-C954-9M6F | Duplicate Advisory: OpenClaw: Owner-enforced commands could accept wildcard channel senders as command owners 已撤回 | 低危 | npmopenclaw | 已审查 | 2026-05-12 02:31 | 2026-05-18 23:30 |
| GHSA-P3M6-JR2H-HHXJ | Duplicate Advisory: OpenClaw: MCP stdio server env could load dangerous startup variables from workspace config 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-05-12 02:31 | 2026-05-18 23:30 |
| GHSA-M5J2-R859-R5CV | Duplicate Advisory: OpenClaw: Isolated cron awareness events were recorded as trusted system events 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-05-12 02:31 | 2026-05-18 23:29 |
| GHSA-4MHR-CXR4-2PRM | Duplicate Advisory: OpenClaw: Workspace dotenv MiniMax host override could redirect credentialed requests 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-05-12 02:31 | 2026-05-18 23:30 |