检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-X7JR-GVVR-P9W7 | Duplicate Advisory: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure 已撤回 | 高危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-03 23:32 | 2026-09-04 04:33 |
当前筛选结果 998 条 · 时间按北京时间显示
| GHSA-PQPF-6VQV-6W92 |
Duplicate Advisory: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB 已撤回 |
| 严重 |
Gogithub.com/siyuan-note/siyuan |
| 已审查 |
| 2026-08-03 23:32 |
| 2026-09-04 05:00 |
| GHSA-P2X7-4C4P-8WH6 | Duplicate Advisory: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write 已撤回 | 严重 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-03 23:32 | 2026-09-04 04:19 |
| GHSA-85XQ-27M5-59M9 | Duplicate Advisory: SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check 已撤回 | 严重 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-03 23:32 | 2026-09-04 05:17 |
| GHSA-3RFW-7FXW-6JXM | Duplicate Advisory: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered 已撤回 | 中危 | Gogithub.com/siyuan-note/siyuan/kernel | 已审查 | 2026-08-03 23:32 | 2026-09-04 05:21 |
| GHSA-2MMH-4RF8-7XG6 | Duplicate Advisory: SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered 已撤回 | 严重 | npmsiyuan | 已审查 | 2026-08-03 23:32 | 2026-09-04 05:21 |
| GHSA-PV39-QRFQ-G8GC | Duplicate Advisory: NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection 已撤回 | 中危 | PyPInltk | 已审查 | 2026-08-03 17:32 | 2026-09-02 04:30 |
| GHSA-3Q45-2FH7-66CJ | Duplicate Advisory: better-auth has an external request basePath modification DoS 已撤回 | 严重 | npmbetter-auth | 已审查 | 2026-08-02 23:30 | 2026-09-02 02:56 |
| GHSA-MQQ9-GXG5-M58G | Duplicate Advisory: Guzzle: URI fragments disclosed in redirect Referer headers 已撤回 | 高危 | Packagistguzzlehttp/guzzle | 已审查 | 2026-08-01 23:30 | 2026-08-04 20:53 |
| GHSA-MJRX-74JH-7XGW | Duplicate Advisory: Guzzle: Host-only cookie scope is not preserved 已撤回 | 高危 | Packagistguzzlehttp/guzzle | 已审查 | 2026-08-01 23:30 | 2026-08-04 20:55 |
| GHSA-3FVR-2JW6-CRQ4 | Duplicate Advisory: Guzzle: Unbounded response cookies risk denial of service 已撤回 | 中危 | Packagistguzzlehttp/guzzle | 已审查 | 2026-08-01 23:30 | 2026-08-04 20:58 |
| GHSA-32RQ-JHR7-M3HH | Duplicate Advisory: Guzzle: Proxy-Authorization headers can be sent to origin servers 已撤回 | 中危 | Packagistguzzlehttp/guzzle | 已审查 | 2026-08-01 23:30 | 2026-08-04 20:49 |
| GHSA-9WX3-P993-35VP | Duplicate Advisory: Axios: Nested axios option objects can consume polluted prototype values 已撤回 | 中危 | npmaxios | 已审查 | 2026-08-01 23:30 | 2026-09-02 02:41 |
| GHSA-68JP-44VC-2X5H | Duplicate Advisory: Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning 已撤回 | 高危 | npmaxios | 已审查 | 2026-08-01 23:30 | 2026-09-02 02:42 |
| GHSA-FQJ3-H9PC-443H | Duplicate Advisory: Axios: HTTP/2 streamed uploads bypass `maxBodyLength` 已撤回 | 中危 | npmaxios | 已审查 | 2026-08-01 23:30 | 2026-09-02 02:35 |
| GHSA-FQ2J-3J99-RX65 | Duplicate Advisory: Axios: Excessive recursion in formDataToJSON can cause denial of service 已撤回 | 中危 | npmaxios | 已审查 | 2026-08-01 23:30 | 2026-09-02 02:40 |
| GHSA-F2R5-PQH9-R8F8 | Duplicate Advisory: Axios: Prototype pollution gadgets can alter axios request construction 已撤回 | 中危 | npmaxios | 已审查 | 2026-08-01 23:30 | 2026-09-01 03:51 |
| GHSA-7QF5-7PPR-87V8 | Duplicate Advisory: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass 已撤回 | 高危 | Gogithub.com/traefik/traefik/v3 | 已审查 | 2026-08-01 23:30 | 2026-08-07 00:45 |
| GHSA-6HQM-HM2V-3P2P | Duplicate Advisory: Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios 已撤回 | 中危 | npmaxios | 已审查 | 2026-08-01 23:30 | 2026-09-02 02:38 |
| GHSA-4WW2-RJH2-XPV9 | Duplicate Advisory: Axios: Deep formToJSON Key Recursion Can Cause Denial of Service 已撤回 | 中危 | npmaxios | 已审查 | 2026-08-01 23:30 | 2026-09-01 04:02 |
| GHSA-39J5-W47M-2GMV | Duplicate Advisory: Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength` 已撤回 | 中危 | npmaxios | 已审查 | 2026-08-01 23:30 | 2026-09-02 02:37 |
| GHSA-38GX-CFQF-F652 | Duplicate Advisory: Axios: Prototype pollution auth subfields can inject Basic auth 已撤回 | 中危 | npmaxios | 已审查 | 2026-08-01 23:30 | 2026-08-08 01:51 |
| GHSA-VHCW-F978-XJJG | Duplicate Advisory: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview 已撤回 | 高危 | npmn8n | 已审查 | 2026-07-22 20:32 | 2026-07-23 01:55 |
| GHSA-RHG6-2VJH-J5QC | Duplicate Advisory: Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware 已撤回 | 高危 | Gogithub.com/traefik/traefik/v2 | 已审查 | 2026-07-22 20:32 | 2026-08-07 00:50 |
| GHSA-MHVH-GWHR-76PW | Duplicate Advisory: Google Service Account Private Key Exposed in JWT Header 已撤回 | 中危 | npmn8n | 已审查 | 2026-07-22 20:32 | 2026-07-23 01:59 |