检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-VQFP-P66C-XRP9 CVE-2026-55088 | ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token | 中危 | npmep_etherpad-lite | 已审查 | 2026-08-13 22:12 | 2026-08-13 22:12 |
| GHSA-2JWF-F4XQ-F24H CVE-2026-55086 | ep_etherpad-lite: Import/export uses Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwrite |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
npmep_etherpad-lite |
| 已审查 |
| 2026-08-13 22:11 |
| 2026-08-13 22:11 |
| GHSA-FJGC-3MJ7-8RG8 CVE-2026-55087 | ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header | 中危 | npmep_etherpad-lite | 已审查 | 2026-08-13 21:46 | 2026-08-13 21:46 |
| GHSA-2MHJ-FHVG-V428 CVE-2026-55072 | Pimcore: ClassDefinition UID regex missing end anchor allows SQL injection via Block.php unquoted table name | 高危 | Packagistpimcore/pimcore | 已审查 | 2026-08-13 21:44 | 2026-08-13 21:44 |
| GHSA-CXGV-HP74-JJ7R CVE-2026-55074 | Ansible FreeBSD Jail Connection Plugin: Jail escape via symlink following in put_file (host-side root mv) | 高危 | PyPIansible-jailexec | 已审查 | 2026-08-13 07:21 | 2026-08-13 23:58 |
| GHSA-V598-7627-G9FX | Duplicate Advisory: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents 已撤回 | 严重 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-13 05:31 | 2026-09-04 06:52 |
| GHSA-MHCC-G592-267J | Duplicate Advisory: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode) 已撤回 | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-13 05:31 | 2026-09-04 06:48 |
| GHSA-J26H-R8JX-887C | Duplicate Advisory: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode) 已撤回 | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-13 05:31 | 2026-09-04 06:50 |
| GHSA-H4W7-MGQ4-WG6X | Duplicate Advisory: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents 已撤回 | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-13 05:31 | 2026-09-04 06:58 |
| GHSA-8WX9-J7J5-H9VP | Duplicate Advisory: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port prox 已撤回 | 高危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-13 05:31 | 2026-09-04 06:32 |
| GHSA-89HF-XCX5-R9R6 | Duplicate Advisory: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents 已撤回 | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-13 05:31 | 2026-09-04 06:51 |
| GHSA-72XP-24P9-7VPF | Duplicate Advisory: Absolute filesystem path and OS username disclosure via resolveAssetPath 已撤回 | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-13 05:31 | 2026-09-04 07:00 |
| GHSA-2JMX-Q9JF-WP3W | Duplicate Advisory: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel 已撤回 | 高危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-13 05:31 | 2026-09-04 06:49 |
| GHSA-HR3F-QFRH-H7W5 | Duplicate Advisory: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking 已撤回 | 高危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-13 05:31 | 2026-09-04 07:01 |
| GHSA-FXMW-RV85-5HWH | Duplicate Advisory: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode) 已撤回 | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-13 05:31 | 2026-09-04 07:03 |
| GHSA-PFVM-W89X-94JW | SIPSorcery: Malformed UDP datagram crashes TurnServer receive loop with no restart, disabling TURN UDP relay for all clients (DoS) | 高危 | NuGetSIPSorcery | 已审查 | 2026-08-13 03:31 | 2026-08-13 03:31 |
| GHSA-JWJP-4649-V8JP | SIPSorcery vulnerable to Denial of Service via out-of-bounds read in SCTP SACK chunk parsing | 高危 | NuGetSIPSorcery | 已审查 | 2026-08-13 03:30 | 2026-08-13 03:30 |
| GHSA-49M4-VP58-WGC9 CVE-2026-55071 | MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install` | 高危 | PyPIstata-mcp | 已审查 | 2026-08-13 03:23 | 2026-08-13 03:23 |
| GHSA-W62W-66V9-VVGV CVE-2026-54917 | SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access | 高危 | Gogithub.com/seaweedfs/seaweedfs | 已审查 | 2026-08-13 03:19 | 2026-08-13 03:19 |
| GHSA-H47F-GMJP-M7RR CVE-2026-52776 | compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0 | 高危 | PyPIcompliance-trestle | 已审查 | 2026-08-12 23:21 | 2026-08-12 23:21 |
| GHSA-Q939-RPR3-3284 CVE-2026-48798 | SSH.NET: ScpClient Recursive Download Allows Arbitrary File Write via Server-Controlled SCP Filenames | 高危 | NuGetSSH.NET | 已审查 | 2026-08-12 23:19 | 2026-08-19 02:05 |
| GHSA-88P2-JJ8W-J8QG CVE-2026-48786 | Fleet: Observer-class users can view team enroll secrets and credential-bearing configuration via target search endpoint | 中危 | Gogithub.com/fleetdm/fleet/v4 | 已审查 | 2026-08-12 23:18 | 2026-08-12 23:18 |
| GHSA-6PVM-2VJJ-RX4W CVE-2026-47132 | phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumeration | 中危 | Packagistthorsten/phpmyfaq | 已审查 | 2026-08-12 23:17 | 2026-08-12 23:17 |
| GHSA-3763-QP59-59VF CVE-2026-46369 | nimiq-blockchain: Validity store off by one error | 高危 | crates.ionimiq-blockchain | 已审查 | 2026-08-12 23:16 | 2026-08-12 23:16 |
| GHSA-JMQM-F8Q4-V7WX CVE-2026-45694 | LibreNMS: Reflected XSS via Proxmox instance/vmid GET parameters injected into document.title JavaScript assignment | 中危 | Packagistlibrenms/librenms | 已审查 | 2026-08-12 23:16 | 2026-08-12 23:16 |