检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-H7X2-H6G9-P789 CVE-2026-71211 | MLflow AI Gateway permits SSRF through an unvalidated api_base | 高危 | PyPImlflow | 已审查 | 2026-08-05 17:31 | 2026-09-01 03:48 |
| GHSA-XM43-3M56-W3WF CVE-2026-59817 | Ghost: Paid gift memberships obtainable at minimal cost via the donations feature |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
npmghost |
| 已审查 |
| 2026-08-05 05:57 |
| 2026-08-05 05:57 |
| GHSA-CHGM-3698-JM42 CVE-2026-53947 | Ghost: Member existence leak via magic link sign-in response | 中危 | npmghost | 已审查 | 2026-08-05 05:56 | 2026-08-05 05:56 |
| GHSA-XPP7-93X6-V29M CVE-2026-53950 | XSS in Ghost's ActivityPub client | 高危 | npm@tryghost/activitypub | 已审查 | 2026-08-05 05:54 | 2026-08-05 05:54 |
| GHSA-7MPP-R37J-X5WH CVE-2026-70594 | Ghost: Session Fixation in Ghost Admin | 中危 | npmghost | 已审查 | 2026-08-05 05:53 | 2026-08-05 05:53 |
| GHSA-CJC9-Q5GF-327P CVE-2026-70593 | Ghost: Theme Upload Path Traversal | 中危 | npmghost | 已审查 | 2026-08-05 05:49 | 2026-08-05 05:49 |
| GHSA-CJ62-HVV2-2Q5H CVE-2026-70592 | Ghost: Database Backup Path Traversal | 中危 | npmghost | 已审查 | 2026-08-05 05:41 | 2026-08-05 05:41 |
| GHSA-GCVV-72Q8-9V76 CVE-2026-70591 | Ghost: Server-Side Request Forgery in Image Fetching | 中危 | npmghost | 已审查 | 2026-08-05 05:38 | 2026-08-05 05:38 |
| GHSA-JM22-3W23-5Q7W CVE-2026-70590 | Ghost: Blind Password Hash Disclosure in Ghost Admin API | 中危 | npmghost | 已审查 | 2026-08-05 05:28 | 2026-08-05 05:28 |
| GHSA-G366-23FW-GGP6 CVE-2026-53946 | Ghost: Mobiledoc image-size fetch SSRF | 中危 | npmghost | 已审查 | 2026-08-05 05:25 | 2026-08-05 05:25 |
| GHSA-CH52-PX8Q-F22J CVE-2026-53945 | Ghost: Server-side request forgery via DNS rebinding in external request handling | 中危 | npmghost | 已审查 | 2026-08-05 05:24 | 2026-08-05 05:24 |
| GHSA-WVP2-4QQP-4H3R CVE-2026-53944 | Ghost: Private IP filtering bypass to make server-side requests to internal services | 中危 | npmghost | 已审查 | 2026-08-05 05:13 | 2026-08-05 05:13 |
| GHSA-4WX2-7GVJ-QFQ3 CVE-2026-70589 | Ghost: Archived Offers can be Redeemed | 中危 | npmghost | 已审查 | 2026-08-05 05:11 | 2026-08-05 05:11 |
| GHSA-944X-PM95-3JPR CVE-2026-53948 | Ghost: File Upload Content-Type Spoofing | 中危 | npmghost | 已审查 | 2026-08-05 05:05 | 2026-08-05 05:05 |
| GHSA-2GX6-7GX2-WWCF CVE-2026-70588 | Ghost: Cross-Site Scripting in Universal Import | 中危 | npmghost | 已审查 | 2026-08-05 05:03 | 2026-08-05 05:03 |
| GHSA-3CG5-48J3-V4GV CVE-2026-70494 | Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder | 高危 | PyPIopen-webui | 已审查 | 2026-08-05 04:58 | 2026-08-05 04:58 |
| GHSA-2F54-P244-32Q6 CVE-2026-70493 | Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that backtracks catastrophically | 中危 | PyPIopen-webui | 已审查 | 2026-08-05 04:56 | 2026-08-05 04:56 |
| GHSA-PWXH-7358-JQ2X CVE-2026-70492 | Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages | 高危 | PyPIopen-webui | 已审查 | 2026-08-05 04:54 | 2026-08-05 04:54 |
| GHSA-3R7G-Q6CG-Q2VX CVE-2026-70491 | Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpoints | 中危 | PyPIopen-webui | 已审查 | 2026-08-05 04:51 | 2026-08-05 04:51 |
| GHSA-5GPJ-VJ23-VHHV CVE-2026-70490 | Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check | 中危 | PyPIopen-webui | 已审查 | 2026-08-05 04:45 | 2026-08-05 04:45 |
| GHSA-73CQ-MCGH-379C CVE-2026-70489 | Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second parsing | 中危 | PyPIopen-webui | 已审查 | 2026-08-05 04:42 | 2026-08-05 04:42 |
| GHSA-H6X2-583H-X99R CVE-2026-54020 | Open WebUI: DNS Rebinding SSRF Bypass | 中危 | PyPIopen-webui | 已审查 | 2026-08-05 04:38 | 2026-08-05 05:07 |
| GHSA-6XHV-RXHV-PWM4 CVE-2026-70487 | Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata | 中危 | PyPIopen-webui | 已审查 | 2026-08-05 04:35 | 2026-08-05 04:35 |
| GHSA-JXC9-XMC4-GR23 CVE-2026-70488 | Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup | 中危 | PyPIopen-webui | 已审查 | 2026-08-05 04:35 | 2026-08-05 04:35 |
| GHSA-3XPF-XQ7R-V8C5 CVE-2026-70486 | Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin | 高危 | PyPIopen-webui | 已审查 | 2026-08-05 04:02 | 2026-08-05 04:02 |