检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-8VH5-MGJJ-W6HG | Duplicate Advisory: [CWE-1188] Default ENFORCE=False Disables All pathsec Security Controls 已撤回 | 高危 | PyPInltk | 已审查 | 2026-08-22 23:31 | 2026-09-02 23:40 |
当前筛选结果 998 条 · 时间按北京时间显示
Duplicate Advisory: FileSystemPathPointer.open() sandbox check is dead code — arbitrary file read via file:// protocol 已撤回 |
| 高危 |
PyPInltk |
| 已审查 |
| 2026-08-22 23:31 |
| 2026-09-02 22:47 |
| GHSA-343M-9FQQ-97C7 | Duplicate Advisory: NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely 已撤回 | 中危 | PyPInltk | 已审查 | 2026-08-22 23:31 | 2026-09-02 22:47 |
| GHSA-WW86-C2QF-W8FW | Duplicate Advisory: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode) 已撤回 | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-14 20:31 | 2026-09-04 06:22 |
| GHSA-Q6G5-M978-C6V9 | Duplicate Advisory: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode) 已撤回 | 严重 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-14 20:31 | 2026-09-04 06:30 |
| GHSA-P8CP-78HP-WMQ8 | Duplicate Advisory: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle 已撤回 | 严重 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-14 20:31 | 2026-09-04 06:24 |
| GHSA-V598-7627-G9FX | Duplicate Advisory: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents 已撤回 | 严重 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-13 05:31 | 2026-09-04 06:52 |
| GHSA-MHCC-G592-267J | Duplicate Advisory: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode) 已撤回 | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-13 05:31 | 2026-09-04 06:48 |
| GHSA-J26H-R8JX-887C | Duplicate Advisory: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode) 已撤回 | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-13 05:31 | 2026-09-04 06:50 |
| GHSA-H4W7-MGQ4-WG6X | Duplicate Advisory: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents 已撤回 | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-13 05:31 | 2026-09-04 06:58 |
| GHSA-8WX9-J7J5-H9VP | Duplicate Advisory: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port prox 已撤回 | 高危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-13 05:31 | 2026-09-04 06:32 |
| GHSA-89HF-XCX5-R9R6 | Duplicate Advisory: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents 已撤回 | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-13 05:31 | 2026-09-04 06:51 |
| GHSA-72XP-24P9-7VPF | Duplicate Advisory: Absolute filesystem path and OS username disclosure via resolveAssetPath 已撤回 | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-13 05:31 | 2026-09-04 07:00 |
| GHSA-2JMX-Q9JF-WP3W | Duplicate Advisory: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel 已撤回 | 高危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-13 05:31 | 2026-09-04 06:49 |
| GHSA-HR3F-QFRH-H7W5 | Duplicate Advisory: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking 已撤回 | 高危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-13 05:31 | 2026-09-04 07:01 |
| GHSA-FXMW-RV85-5HWH | Duplicate Advisory: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode) 已撤回 | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-13 05:31 | 2026-09-04 07:03 |
| GHSA-H784-HPJP-2RRM | Duplicate Advisory: Craft CMS: Authenticated RCE through Twig sandbox escape 已撤回 | 高危 | Packagistcraftcms/cms | 已审查 | 2026-08-11 23:32 | 2026-09-02 05:04 |
| GHSA-CC2G-26RW-G997 | Duplicate Advisory: Craft CMS: Authenticated leak of secret environment variables 已撤回 | 高危 | Packagistcraftcms/cms | 已审查 | 2026-08-11 23:32 | 2026-09-02 05:06 |
| GHSA-9W6W-8X3C-HFQP | Duplicate Advisory: Craft CMS: Incorrect path validation could potentially lead to path traversal 已撤回 | 中危 | Packagistcraftcms/cms | 已审查 | 2026-08-11 23:32 | 2026-09-02 05:19 |
| GHSA-4HC4-QJFX-WJF3 | Duplicate Advisory: Craft CMS: Authorization bypass: view-only Categories user can modify category structure via structures/move-element 已撤回 | 严重 | Packagistcraftcms/cms | 已审查 | 2026-08-11 23:32 | 2026-09-02 05:11 |
| GHSA-W36C-QXRQ-V7FW | Duplicate Advisory: Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass 已撤回 | 高危 | Packagistcraftcms/cms | 已审查 | 2026-08-11 23:32 | 2026-09-02 05:07 |
| GHSA-2P2V-3MJG-GFPF | Duplicate Advisory: Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts 已撤回 | 高危 | Packagistcraftcms/cms | 已审查 | 2026-08-11 23:32 | 2026-09-02 05:03 |
| GHSA-4JJW-PWVW-Q6W3 | Duplicate Advisory: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint 已撤回 | 中危 | npmnuxt | 已审查 | 2026-08-11 23:32 | 2026-08-13 22:18 |
| GHSA-4F2F-JR2M-J7P4 | Duplicate Advisory: TYPO3-CORE-SA-2026-021: Broken Access Control in Backend and Install Tool 已撤回 | 高危 | Packagisttypo3/cms-core | 已审查 | 2026-08-11 17:32 | 2026-09-02 05:30 |
| GHSA-6QM2-MCQ7-53QP | Duplicate Advisory: jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition 已撤回 | 中危 | Maventools.jackson.core:jackson-core | 已审查 | 2026-08-04 23:32 | 2026-09-02 02:56 |