检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-X6VM-W76M-8J7G CVE-2026-69256 | Flowise: Remote Code Execution Vulnerability in CSVAgent | 严重 | npmflowise+1 | 已审查 | 2026-08-04 23:46 | 2026-08-05 01:47 |
| GHSA-VMV7-4M6C-3CG5 CVE-2026-69255 |
当前筛选结果 35,190 条 · 时间按北京时间显示
Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified |
| 严重 |
npmflowise+1 |
| 已审查 |
| 2026-08-04 23:40 |
| 2026-08-04 23:41 |
| GHSA-6QM2-MCQ7-53QP | Duplicate Advisory: jackson-core: Number Length Constraint Bypass in Async Parser Leads to Potential DoS Condition 已撤回 | 中危 | Maventools.jackson.core:jackson-core | 已审查 | 2026-08-04 23:32 | 2026-09-02 02:56 |
| GHSA-3769-JGQC-CXM7 CVE-2026-69254 | Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override | 严重 | npmflowise+1 | 已审查 | 2026-08-04 23:29 | 2026-08-04 23:29 |
| GHSA-WG86-R78F-74MP CVE-2026-69253 | Flowise Sandbox Escape to RCE | 严重 | npmflowise+1 | 已审查 | 2026-08-04 23:13 | 2026-08-04 23:13 |
| GHSA-WP74-F5HH-5F3R CVE-2026-69252 | Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization | 高危 | npmflowise | 已审查 | 2026-08-04 22:54 | 2026-08-04 22:54 |
| GHSA-G32J-MMXR-GFQ5 CVE-2026-69251 | Flowise RCE via TypeORM DataSource | 严重 | npmflowise+1 | 已审查 | 2026-08-04 22:28 | 2026-08-04 22:28 |
| GHSA-R745-8HWV-H473 CVE-2026-69250 | Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration | 高危 | npmflowise | 已审查 | 2026-08-04 22:20 | 2026-08-04 22:20 |
| GHSA-2364-JH4Q-M9VM | Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint | 中危 | npmflowise | 已审查 | 2026-08-04 22:16 | 2026-08-04 22:16 |
| GHSA-M2H6-J472-RP4C CVE-2026-69248 | python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees | 中危 | PyPIcryptography | 已审查 | 2026-08-04 05:26 | 2026-09-02 21:26 |
| GHSA-JWV3-5HGF-82WW CVE-2026-69249 | python-cryptography: Duplicate self-signed intermediates can cause exponential path-building | 高危 | PyPIcryptography | 已审查 | 2026-08-04 05:26 | 2026-08-04 05:26 |
| GHSA-G6CJ-PR64-35W5 CVE-2026-69247 | cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing | 高危 | PyPIcryptography | 已审查 | 2026-08-04 05:17 | 2026-08-04 05:17 |
| GHSA-V5MV-P594-2X33 CVE-2026-69246 | Guzzle: Noncanonical host can bypass host-based checks | 高危 | Packagistguzzlehttp/guzzle | 已审查 | 2026-08-04 05:07 | 2026-08-04 05:07 |
| GHSA-F7VP-7XGX-4W4R CVE-2026-69245 | Guzzle: Noncanonical cookie domain keeps subdomain scope | 中危 | Packagistguzzlehttp/guzzle | 已审查 | 2026-08-04 05:05 | 2026-08-04 05:05 |
| GHSA-CQ5V-8Q36-5273 CVE-2026-69244 | AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response) | 高危 | PyPIaiohttp | 已审查 | 2026-08-04 04:51 | 2026-08-04 04:51 |
| GHSA-MFX4-HV73-Q22V CVE-2026-69243 | AIOHTTP: HTTP request smuggling via WebSocket upgrade | 中危 | PyPIaiohttp | 已审查 | 2026-08-04 04:46 | 2026-08-04 04:47 |
| GHSA-MQ44-7P77-Q5H7 CVE-2026-59881 | AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate | 中危 | PyPIaiohttp | 已审查 | 2026-08-04 04:40 | 2026-08-04 04:40 |
| GHSA-V8FG-2RW7-Q452 CVE-2026-69240 | Sequelize: SQL Injection (Oracle DB) | 严重 | npmsequelize | 已审查 | 2026-08-04 04:29 | 2026-08-04 04:29 |
| GHSA-8J4G-W8FX-2239 CVE-2026-69207 | Hono: ReDoS in CORS middleware via Access-Control-Request-Headers | 中危 | npmhono | 已审查 | 2026-08-04 04:23 | 2026-08-04 04:23 |
| GHSA-P538-C434-8V24 | GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count | 中危 | PyPIGitPython | 已审查 | 2026-08-04 04:23 | 2026-08-04 04:23 |
| GHSA-539M-9XH6-Q6RR | GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive() | 中危 | PyPIGitPython | 已审查 | 2026-08-04 04:14 | 2026-08-04 04:14 |
| GHSA-3F7W-8RR8-F37F | GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read | 高危 | PyPIGitPython | 已审查 | 2026-08-04 04:09 | 2026-08-04 04:09 |
| GHSA-MWP4-54F8-5FHR CVE-2026-69192 | ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass | 高危 | npmip-address | 已审查 | 2026-08-04 03:59 | 2026-08-04 03:59 |
| GHSA-4XRF-JV44-H6HH CVE-2026-69198 | ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks | 中危 | npmip-address | 已审查 | 2026-08-04 03:59 | 2026-08-04 03:59 |
| GHSA-22JQ-VG5J-6VGG CVE-2026-54272 | ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks | 中危 | npmip-address | 已审查 | 2026-08-04 03:52 | 2026-08-04 03:52 |