检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-XHF4-832V-7XCR CVE-2026-71310 | rclone: Unbounded HTTP CONNECT Response Headers Can Exhaust rclone Memory | 中危 | Gogithub.com/rclone/rclone | 已审查 | 2026-08-06 04:17 | 2026-08-31 22:53 |
| GHSA-CF44-9PGV-M4XC CVE-2026-54572 | rclone: Unvalidated symlink target in local `--links` — arbitrary file write from an untrusted remote |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
Gogithub.com/rclone/rclone |
| 已审查 |
| 2026-08-06 04:15 |
| 2026-08-06 04:15 |
| GHSA-45PQ-889G-FCGH CVE-2026-71309 | rclone: Incomplete path validation allows backend root escape in serve restic | 高危 | Gogithub.com/rclone/rclone | 已审查 | 2026-08-06 04:13 | 2026-08-06 04:13 |
| GHSA-945V-V9P3-V5XW | rclone local `--metadata` applies attacker-controlled mode/uid - setuid binary planted from an untrusted remote | 低危 | Gogithub.com/rclone/rclone | 已审查 | 2026-08-06 04:03 | 2026-08-06 04:03 |
| GHSA-GWFQ-86J8-7QHV | rclone: Verbose Stack Trace Disclosure in RC API Error Responses | 低危 | Gogithub.com/rclone/rclone | 已审查 | 2026-08-06 03:59 | 2026-08-06 03:59 |
| GHSA-P2RR-RVMM-C5FP CVE-2026-70612 | Electron: Sandboxed iframes can launch external protocol handlers | 中危 | npmelectron | 已审查 | 2026-08-06 01:56 | 2026-08-06 01:56 |
| GHSA-F2R8-JV7C-XQMP CVE-2026-70611 | Electron: DevTools embedder handler executes arbitrary files via shell open | 中危 | npmelectron | 已审查 | 2026-08-06 01:49 | 2026-08-06 01:49 |
| GHSA-FF2P-HMQR-HXM4 CVE-2026-70610 | Electron: contextBridge object copy honors prototype setters | 中危 | npmelectron | 已审查 | 2026-08-06 01:41 | 2026-08-06 01:41 |
| GHSA-4F78-QHMW-8J8M CVE-2026-70609 | Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter | 中危 | npmelectron | 已审查 | 2026-08-06 01:32 | 2026-08-06 01:32 |
| GHSA-9F4C-93C8-JC8G CVE-2026-70608 | Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path | 高危 | npmelectron | 已审查 | 2026-08-06 01:27 | 2026-08-06 01:27 |
| GHSA-V93F-FGJR-HJRJ CVE-2026-70607 | Electron: window.open features string controls some window options considered privileged | 中危 | npmelectron | 已审查 | 2026-08-06 00:24 | 2026-08-06 00:24 |
| GHSA-R4W5-6PFG-JXP5 CVE-2026-70606 | Electron: ProtocolResponse.url reuses the default session cache instead of the registering session | 中危 | npmelectron | 已审查 | 2026-08-06 00:07 | 2026-08-06 00:07 |
| GHSA-V64R-4M7R-3MVQ CVE-2026-70605 | Electron: HTTP redirect followed into local file loader | 中危 | npmelectron | 已审查 | 2026-08-06 00:04 | 2026-08-06 00:04 |
| GHSA-V3J7-R9GQ-3GJW CVE-2026-70604 | Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads | 高危 | npmelectron | 已审查 | 2026-08-05 23:59 | 2026-08-05 23:59 |
| GHSA-M55F-7GQJ-FR98 CVE-2026-70602 | Electron: Extension tab APIs operate across session boundaries | 中危 | npmelectron | 已审查 | 2026-08-05 23:57 | 2026-08-05 23:57 |
| GHSA-5C9J-MHMV-5XGX CVE-2026-70603 | Electron: shell.openPath path validation bypass via embedded null byte | 中危 | npmelectron | 已审查 | 2026-08-05 23:57 | 2026-08-05 23:57 |
| GHSA-H7RP-CF8H-J98X CVE-2026-70601 | Electron: Context isolation bypass via Function.prototype.bind hijack | 高危 | npmelectron | 已审查 | 2026-08-05 23:46 | 2026-08-05 23:46 |
| GHSA-X8RC-WPG4-GRPF CVE-2026-70600 | Electron: Cross-origin iframe can position native autofill popup | 低危 | npmelectron | 已审查 | 2026-08-05 23:40 | 2026-08-05 23:40 |
| GHSA-9PF5-HG6P-4PWP CVE-2026-70599 | Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin | 中危 | npmelectron | 已审查 | 2026-08-05 23:36 | 2026-08-05 23:36 |
| GHSA-JPPW-R5J3-XF7X CVE-2026-71293 | Statamic CMS exposes two-factor recovery codes through dynamic Antlers rendering | 中危 | Packagiststatamic/cms | 已审查 | 2026-08-05 23:32 | 2026-09-02 03:56 |
| GHSA-PFMC-3MGC-P6FP CVE-2026-70598 | Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size | 低危 | npmelectron | 已审查 | 2026-08-05 23:27 | 2026-08-05 23:27 |
| GHSA-JM7P-CC5G-QWXX CVE-2026-70597 | Electron: Parent process code-sign check is spoofable | 中危 | npmelectron | 已审查 | 2026-08-05 23:21 | 2026-08-05 23:22 |
| GHSA-JX35-X7FJ-VGPR CVE-2026-53949 | Ghost Content API filter bypass reveals private fields | 中危 | npmghost | 已审查 | 2026-08-05 22:42 | 2026-08-05 22:42 |
| GHSA-PR22-P9RP-2CQV CVE-2026-70596 | Ghost: Cross-Site Scripting in Feature Image Captions | 中危 | npmghost | 已审查 | 2026-08-05 22:40 | 2026-08-05 22:40 |
| GHSA-X5MM-WM4G-J5XV CVE-2026-70595 | Ghost: Server-Side Request Forgery Mitigation Issue | 中危 | npmghost | 已审查 | 2026-08-05 22:37 | 2026-08-05 22:37 |