检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-2XHG-73J7-RRGX CVE-2026-53957 | Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to attacker-controlled endpoint | 高危 | npm@contentful/mcp-server+1 | 已审查 | 2026-08-20 03:17 | 2026-08-20 03:17 |
| GHSA-9GMC-JQMH-3RVM CVE-2026-53951 |
当前筛选结果 35,190 条 · 时间按北京时间显示
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted |
| 高危 |
PyPIcopier |
| 已审查 |
| 2026-08-20 03:16 |
| 2026-08-20 03:16 |
| GHSA-VJHX-2CQW-3Q6Q CVE-2026-53941 | Uprobe gadgets: unprivileged container's ld.so.cache causes high CPU utilization and container startup DoS | 中危 | Gogithub.com/inspektor-gadget/inspektor-gadget | 已审查 | 2026-08-20 03:16 | 2026-08-20 03:16 |
| GHSA-QWGH-2VCV-G2F7 | block_buffer: panic corrupts inline buffer position | 中危 | crates.ioblock_buffer | 已审查 | 2026-08-20 03:15 | 2026-08-20 03:15 |
| GHSA-RR55-JP92-8WP2 | claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools | 高危 | npmclaude-faf-mcp | 已审查 | 2026-08-20 03:15 | 2026-08-20 03:15 |
| GHSA-J4R7-8PH4-43G3 | faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools | 高危 | npmfaf-mcp | 已审查 | 2026-08-20 03:15 | 2026-08-20 03:15 |
| GHSA-CC2G-GQ8C-R332 | grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools | 高危 | npmgrok-faf-mcp | 已审查 | 2026-08-20 03:15 | 2026-08-20 03:15 |
| GHSA-JFJ5-WRJ9-63X4 CVE-2026-55236 | langgraph-api: Incomplete assistant authorization in LangGraph Server run creation | 中危 | PyPIlanggraph-api | 已审查 | 2026-08-20 02:56 | 2026-08-20 02:56 |
| GHSA-2C9Q-C2Q9-QGQV CVE-2026-55235 | langgraph-api: Relative webhook targets in LangGraph Server can reach in-process routes without authentication | 中危 | PyPIlanggraph-api | 已审查 | 2026-08-20 02:55 | 2026-08-20 02:55 |
| GHSA-RH9C-RQVG-F7PR CVE-2026-73974 | linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE) | 中危 | PyPIlinuxfabrik-lib | 已审查 | 2026-08-19 05:18 | 2026-08-19 05:18 |
| GHSA-HFG8-HC9C-6C3H CVE-2026-17106 | moby/go-archive: Crafted tar archive can write outside the extraction directory | 高危 | Gogithub.com/moby/go-archive | 已审查 | 2026-08-19 05:17 | 2026-08-19 05:17 |
| GHSA-7GWW-X7FH-JF9J | LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page | 高危 | Packagistlibrenms/librenms | 已审查 | 2026-08-19 05:17 | 2026-08-19 05:17 |
| GHSA-7CJ5-V4PP-V632 | LibreNMS: Stored XSS via graph_descr admin config settings echoed without escaping to all authenticated users | 中危 | Packagistlibrenms/librenms | 已审查 | 2026-08-19 05:17 | 2026-08-19 05:17 |
| GHSA-JF24-8G2H-2WG7 | LibreNMS Vulnerable to Remote Code Execution via AboutController | 中危 | Packagistlibrenms/librenms | 已审查 | 2026-08-19 05:17 | 2026-08-19 05:17 |
| GHSA-PXMC-2FFP-8J67 CVE-2026-71417 | Lemur: Any user can revoke arbitrary certificates at the CA by uploading a duplicate record and revoking it | 高危 | PyPIlemur | 已审查 | 2026-08-19 04:51 | 2026-08-19 04:51 |
| GHSA-4H97-P9WQ-CHQJ CVE-2026-71322 | Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False | 中危 | PyPIlemur | 已审查 | 2026-08-19 04:51 | 2026-08-19 04:51 |
| GHSA-G7P5-89MH-248H CVE-2026-71317 | Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority | 中危 | PyPIlemur | 已审查 | 2026-08-19 04:51 | 2026-08-19 04:51 |
| GHSA-CFH6-PV5C-38JV CVE-2026-71308 | Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates | 高危 | PyPIlemur | 已审查 | 2026-08-19 04:51 | 2026-08-19 04:51 |
| GHSA-6C8M-Q6G9-VRW3 CVE-2026-71307 | Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API | 高危 | PyPIlemur | 已审查 | 2026-08-19 04:51 | 2026-08-19 04:51 |
| GHSA-V5RC-CPWC-CFPR CVE-2026-71303 | Lemur: Incomplete fix for GHSA-v2wp-frmc-5q3v -- ACME authority update endpoint allows non-admin to replace `acme_url` with internal IP, bypassing allowlist | 高危 | PyPIlemur | 已审查 | 2026-08-19 04:51 | 2026-08-19 04:51 |
| GHSA-F3QQ-49M6-RW8F CVE-2026-70667 | Lemur: SSRF protection in certificate revocation checking bypassable via HTTP redirects and DNS rebinding (incomplete fix for GHSA-54vg-pfh7-jq95) | 中危 | PyPIlemur | 已审查 | 2026-08-19 04:51 | 2026-08-19 04:51 |
| GHSA-XPMJ-WJCP-6PWW CVE-2026-70666 | Lemur: Server-Side Request Forgery via the ACME client following server-controlled URLs | 高危 | PyPIlemur | 已审查 | 2026-08-19 04:51 | 2026-08-19 04:51 |
| GHSA-MHC4-G3WH-CW7M CVE-2026-65959 | Vitess: Missing authorization on vttablet /debug/vrlog exposes live VReplication SQL data | 中危 | Govitess.io/vitess | 已审查 | 2026-08-19 04:50 | 2026-09-02 23:26 |
| GHSA-7788-GHFQ-C6MH CVE-2026-62988 | Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints | 严重 | Packagistfroxlor/froxlor | 已审查 | 2026-08-19 04:48 | 2026-08-19 04:48 |
| GHSA-XPR4-8VP6-C87J CVE-2026-55593 | Froxlor has CSRF Vulnerability in AJAX Endpoint — Missing Cross-Site Request Forgery Protection | 中危 | Packagistfroxlor/froxlor | 已审查 | 2026-08-19 04:48 | 2026-08-19 04:48 |