检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-GW25-M53R-QH88 | SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f) | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-09-03 22:56 | 2026-09-03 22:56 |
| GHSA-99RQ-75J6-5J9F | SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Gogithub.com/siyuan-note/siyuan/kernel |
| 已审查 |
| 2026-09-03 22:53 |
| 2026-09-03 22:53 |
| GHSA-78X9-FHHX-V2G6 CVE-2026-73846 | CKAN MCP Server: Cache-key canonicalization collision enables cache confusion / poisoning | 中危 | npm@aborruso/ckan-mcp-server | 已审查 | 2026-09-03 22:49 | 2026-09-03 22:49 |
| GHSA-6F9W-9HF2-5RG3 CVE-2026-73844 | CKAN MCP Server: Information disclosure via verbose error reflection | 低危 | npm@aborruso/ckan-mcp-server | 已审查 | 2026-09-03 22:49 | 2026-09-03 22:49 |
| GHSA-2MW5-23GM-PCCQ CVE-2026-73667 | OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged pods | 高危 | Gogithub.com/openchoreo/openchoreo | 已审查 | 2026-09-03 07:45 | 2026-09-03 07:45 |
| GHSA-C5F6-2RM9-2W8G CVE-2026-73840 | OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass) | 中危 | Gogithub.com/openchoreo/openchoreo | 已审查 | 2026-09-03 07:45 | 2026-09-03 07:45 |
| GHSA-52GF-6RPQ-FGMX CVE-2026-73841 | OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints | 高危 | Gogithub.com/openchoreo/openchoreo | 已审查 | 2026-09-03 07:44 | 2026-09-03 07:44 |
| GHSA-QH9R-J7RP-4X2M CVE-2026-73843 | OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs | 严重 | Gogithub.com/openchoreo/openchoreo | 已审查 | 2026-09-03 07:43 | 2026-09-03 07:43 |
| GHSA-W878-PJ84-3J5V CVE-2026-67445 | Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection | 高危 | Gogithub.com/axllent/mailpit | 已审查 | 2026-09-03 07:42 | 2026-09-03 07:42 |
| GHSA-GV5W-HFX8-8CWQ CVE-2026-72921 | SeaweedFS: Filer JWT allowed_prefixes literal prefix match allows cross-tenant access to sibling paths | 高危 | Gogithub.com/seaweedfs/seaweedfs | 已审查 | 2026-09-03 07:42 | 2026-09-03 07:42 |
| GHSA-9468-V6MJ-FPPW CVE-2026-71485 | Centrifugo: Client-forgeable headers emulation lets any client spoof headers forwarded to proxy backends | 严重 | Gogithub.com/centrifugal/centrifugo | 已审查 | 2026-09-03 07:41 | 2026-09-03 07:41 |
| GHSA-75MR-QW9X-3R39 CVE-2026-67446 | Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling | 高危 | Gogithub.com/axllent/mailpit | 已审查 | 2026-09-03 07:39 | 2026-09-03 07:39 |
| GHSA-76G3-C3X4-CRVX CVE-2026-84366 | Scrapy: S3DownloadHandler sends signed S3 requests over plaintext HTTP by default | 高危 | PyPIscrapy | 已审查 | 2026-09-03 06:50 | 2026-09-03 06:50 |
| GHSA-GCR2-9V8M-GQ45 CVE-2026-68921 | DiceBear: SVG injection via the unescaped rotate option in @dicebear/core (and fontSize/fontWeight in @dicebear/initials) | 中危 | npm@dicebear/core+1 | 已审查 | 2026-09-03 06:44 | 2026-09-03 06:44 |
| GHSA-7MQG-CX4G-X2RF CVE-2026-62676 | Omnigent Guardrail policy bypass: shell-command parser fails open in policies/builtins/_shell.py | 高危 | PyPIomnigent | 已审查 | 2026-09-03 06:40 | 2026-09-03 06:40 |
| GHSA-4Q39-2JHR-7QX8 CVE-2026-65842 | Plate: SSRF with response disclosure in DOCX image embedding | 高危 | npm@platejs/docx-io | 已审查 | 2026-09-03 06:14 | 2026-09-03 06:14 |
| GHSA-G29J-RWFV-H99W CVE-2026-63490 | Handlebars.java: Arbitrary file read in `SpringTemplateLoader` via URL-fragment suffix bypass | 高危 | Mavencom.github.jknack:handlebars-springmvc | 已审查 | 2026-09-03 06:12 | 2026-09-03 06:12 |
| GHSA-7W2G-9MF9-324M CVE-2026-63481 | Hurl: Cookies in Cookies section leak when redirecting to a different host | 中危 | crates.iohurl | 已审查 | 2026-09-03 06:11 | 2026-09-03 06:11 |
| GHSA-MVXR-6M87-MV2Q CVE-2026-63435 | Mail: Email address spoofing via malformed RFC 2047 encoded-words | 中危 | RubyGemsmail | 已审查 | 2026-09-03 06:02 | 2026-09-03 06:02 |
| GHSA-7MGC-C7PQ-3RR3 CVE-2026-62669 | Grav: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challenge | 高危 | Packagistgetgrav/grav | 已审查 | 2026-09-03 06:01 | 2026-09-03 06:01 |
| GHSA-P8RW-8QJ3-HF33 CVE-2026-62677 | Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE | 高危 | PyPIomnigent | 已审查 | 2026-09-03 06:00 | 2026-09-03 06:00 |
| GHSA-JRRM-9HC7-2V3H CVE-2026-62674 | Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE | 严重 | PyPIomnigent | 已审查 | 2026-09-03 05:55 | 2026-09-03 05:55 |
| GHSA-756X-9HF6-Q4H4 CVE-2026-62675 | Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools | 高危 | PyPIomnigent | 已审查 | 2026-09-03 05:54 | 2026-09-03 05:54 |
| GHSA-MC5Q-6HPJ-RP7J CVE-2026-61842 | Grav: Twig sandbox config exfiltration via grav.offsetGet + dump filter (CVE-2026-44738 bypass) | 中危 | Packagistgetgrav/grav | 已审查 | 2026-09-03 05:41 | 2026-09-03 05:41 |
| GHSA-928X-9MPW-8H56 CVE-2026-61690 | Grav: Decompression Bomb via ZipArchiver - Missing Extraction Limits | 中危 | Packagistgetgrav/grav | 已审查 | 2026-09-03 05:35 | 2026-09-03 05:35 |