检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-J7J9-5253-F7VH CVE-2026-42555 | Valtimo has SpEL injection via StandardEvaluationContext that allows Remote Code Execution by admin users | 严重 | Mavencom.ritense.valtimo:case+2 | 已审查 | 2026-05-07 05:41 | 2026-05-15 04:52 |
| GHSA-QRCH-52M5-VV85 |
当前筛选结果 35,190 条 · 时间按北京时间显示
Flight vulnerable to sensitive information disclosure via default error handler |
| 高危 |
Packagistflightphp/core |
| 已审查 |
| 2026-05-07 05:39 |
| 2026-05-15 04:42 |
| GHSA-VXRR-W42W-W76G CVE-2026-42551 | Flight: HTTP method override enabled by default, facilitating CSRF escalation and middleware bypass | 高危 | Packagistflightphp/core | 已审查 | 2026-05-07 05:38 | 2026-05-15 04:40 |
| GHSA-XWQR-RCQG-22MR CVE-2026-42550 | Flight vulnerable to SQL Injection via unvalidated identifiers in SimplePdo::insert / update / delete | 高危 | Packagistflightphp/core | 已审查 | 2026-05-07 05:35 | 2026-05-15 04:40 |
| GHSA-3XJV-PMF2-GF2Q CVE-2026-42549 | Flight has path traversal in `make:controller` CLI that creates arbitrary directories outside project root | 中危 | Packagistflightphp/core | 已审查 | 2026-05-07 05:34 | 2026-05-15 04:39 |
| GHSA-FCX8-PH5R-MXR4 CVE-2026-42548 | Flight has reflected XSS through an unvalidated JSONP callback in Flight::jsonp() | 高危 | Packagistflightphp/core | 已审查 | 2026-05-07 05:34 | 2026-05-15 04:39 |
| GHSA-XRGF-R9GR-JJJF | Duplicate Advisory: OpenClaw: Exec environment denylist missed high-risk interpreter startup variables 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-05-07 05:31 | 2026-05-12 00:14 |
| GHSA-WWWC-F646-VJ2J | Duplicate Advisory: OpenClaw: Browser press/type interaction routes missed complete navigation guard coverage 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-05-07 05:31 | 2026-05-12 00:12 |
| GHSA-W7RC-VVGX-PJ45 | Duplicate Advisory: OpenClaw: Browser SSRF hostname validation could be bypassed by DNS rebinding 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-05-07 05:31 | 2026-05-12 00:14 |
| GHSA-R747-33R4-RMJW | Duplicate Advisory: OpenClaw: QQBot direct media upload skipped URL SSRF validation 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-05-07 05:31 | 2026-05-12 00:12 |
| GHSA-QVMW-H675-H7QG | Duplicate Advisory: OpenClaw validates Zalo outbound photo URLs through the SSRF guard 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-05-07 05:31 | 2026-05-12 00:13 |
| GHSA-M8WM-R5VQ-QJPG | Duplicate Advisory: OpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotation 已撤回 | 严重 | npmopenclaw | 已审查 | 2026-05-07 05:31 | 2026-05-12 00:14 |
| GHSA-FRR5-J3MH-H9CH | Duplicate Advisory: OpenClaw: OpenShell FS bridge reads pin and verify the opened file before returning bytes 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-05-07 05:31 | 2026-05-12 00:13 |
| GHSA-CJG8-85GJ-V9Q2 | Duplicate Advisory: OpenClaw: Feishu webhook and card-action validation now fail closed 已撤回 | 严重 | npmopenclaw | 已审查 | 2026-05-07 05:31 | 2026-05-12 00:14 |
| GHSA-9R9J-3R2W-FG3V | Duplicate Advisory: OpenClaw: Workspace dotenv could override runtime-control environment variables 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-05-07 05:31 | 2026-05-12 00:13 |
| GHSA-82RM-QCFX-2V78 | Duplicate Advisory: OpenClaw: Delivery queue recovery could lose group tool-policy context for media replay 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-05-07 05:31 | 2026-05-13 00:18 |
| GHSA-6F72-9GXX-98MJ | Duplicate Advisory: OpenClaw: OpenShell FS bridge writes stay pinned to the sandbox mount root 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-05-07 05:31 | 2026-05-12 00:13 |
| GHSA-3R56-7HHR-VFG9 | Duplicate Advisory: OpenClaw: CDP /json/version WebSocket URL could pivot to untrusted second-hop targets 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-05-07 05:31 | 2026-05-12 00:12 |
| GHSA-35VF-VW9F-Q3CR | Duplicate Advisory: OpenClaw: MCP loopback owner context is derived from server-issued bearer tokens 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-05-07 05:31 | 2026-05-12 00:12 |
| GHSA-F5P7-9FR5-8JMJ CVE-2026-42545 | Granian vulnerable to DoS via WSGI response header panic | 中危 | PyPIgranian | 已审查 | 2026-05-07 05:24 | 2026-05-14 00:41 |
| GHSA-VRG7-482J-P6F6 CVE-2026-42544 | Granian vulnerable to unauthenticated DoS via WebSocket subprotocol header panic | 高危 | PyPIgranian | 已审查 | 2026-05-07 05:20 | 2026-05-14 00:41 |
| GHSA-6XX2-M8WV-756H CVE-2026-42844 | Low-privileged Grav API users can create super-admin accounts via blueprint-upload | 高危 | Packagistgetgrav/grav | 已审查 | 2026-05-07 05:19 | 2026-05-14 00:41 |
| GHSA-X597-9FR4-5857 CVE-2026-44301 | Hugo's Node tool execution allows file system access outside the project directory | 中危 | Gogithub.com/gohugoio/hugo | 已审查 | 2026-05-07 04:59 | 2026-05-14 00:42 |
| GHSA-X8JV-Q8J2-487C CVE-2026-42458 | Magento LTS: Reflected XSS - Import -> Data Flow (profiles) | 中危 | Packagistopenmage/magento-lts | 已审查 | 2026-05-07 04:57 | 2026-05-16 07:49 |
| GHSA-M24V-F7G5-GQ67 CVE-2026-44306 | Statamic CMS vulnerable to email enumeration via forgot password endpoint | 中危 | Packagiststatamic/cms | 已审查 | 2026-05-07 04:54 | 2026-05-14 00:42 |