检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-PVCR-8MVP-W8QR | Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF) | 高危 | npm@budibase/server | 已审查 | 2026-07-25 05:42 | 2026-07-25 05:42 |
| GHSA-2XGG-R2WC-C5R2 | Budibase: MySQL DESCRIBE Backtick Injection via multipleStatements in Database Connector |
当前筛选结果 35,190 条 · 时间按北京时间显示
npm@budibase/server |
| 已审查 |
| 2026-07-25 05:26 |
| 2026-07-25 05:26 |
| GHSA-QW6M-8FW2-2V64 | Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution | 高危 | npm@budibase/server | 已审查 | 2026-07-25 05:25 | 2026-07-25 05:25 |
| GHSA-GH4H-34GR-87R7 CVE-2026-73308 | Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders | 中危 | npm@budibase/server | 已审查 | 2026-07-25 05:25 | 2026-08-13 03:01 |
| GHSA-HR66-5MQR-8MPX CVE-2026-73406 | Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint | 高危 | npm@budibase/server | 已审查 | 2026-07-25 05:25 | 2026-08-13 03:03 |
| GHSA-MQHR-6J6H-74P5 | Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak | 严重 | npm@budibase/server | 已审查 | 2026-07-25 05:22 | 2026-07-25 05:22 |
| GHSA-C3JM-GV5R-9WCP CVE-2026-62323 | Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored | 中危 | Gogithub.com/cloudreve/Cloudreve/v3+1 | 已审查 | 2026-07-25 05:18 | 2026-07-25 05:18 |
| GHSA-HP6V-6JW7-GV2F CVE-2026-73302 | Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified | 严重 | npm@budibase/server | 已审查 | 2026-07-25 05:17 | 2026-08-13 02:57 |
| GHSA-XG5G-26X8-CVF4 | Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution | 高危 | npm@budibase/server | 已审查 | 2026-07-25 05:17 | 2026-07-25 05:17 |
| GHSA-XCX6-4F2G-HHGX | Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs | 高危 | npm@budibase/server | 已审查 | 2026-07-25 05:17 | 2026-07-25 05:17 |
| GHSA-PPR4-5F46-J9C6 CVE-2026-73409 | Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile | 高危 | npm@budibase/server | 已审查 | 2026-07-25 05:16 | 2026-08-13 03:20 |
| GHSA-Q6X4-V3QX-85QW CVE-2026-73300 | Budibase: SQL Injection via `multipleStatements: true` | 严重 | npm@budibase/server | 已审查 | 2026-07-25 05:15 | 2026-08-13 02:56 |
| GHSA-C8VC-7PV3-G98P CVE-2026-73303 | Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session) | 高危 | npm@budibase/server | 已审查 | 2026-07-25 05:14 | 2026-08-13 02:56 |
| GHSA-FCRW-F7GG-6G9F CVE-2026-73304 | Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users | 中危 | npm@budibase/server | 已审查 | 2026-07-25 05:14 | 2026-08-13 02:57 |
| GHSA-4QCJ-M5WP-JMF4 CVE-2026-73301 | Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings | 中危 | npm@budibase/server | 已审查 | 2026-07-25 05:13 | 2026-08-13 02:57 |
| GHSA-J9FC-W3MR-X6MV CVE-2026-73305 | Budibase: Privilege escalation via public role assignment API missing app-level authorization | 高危 | npm@budibase/server | 已审查 | 2026-07-25 05:12 | 2026-08-13 02:57 |
| GHSA-WX67-QW84-CM4G CVE-2026-44907 | react-server-dom: Denial of Service in Server Functions | 高危 | npmreact-server-dom-parcel+2 | 已审查 | 2026-07-25 05:12 | 2026-07-25 05:12 |
| GHSA-WG5R-WC3X-39VC CVE-2026-62379 | OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback | 严重 | Mavenorg.openidentityplatform.openam:openam-core | 已审查 | 2026-07-25 05:11 | 2026-08-04 04:44 |
| GHSA-VQXV-6XRH-49CP CVE-2026-62280 | OpenAM Reflected XSS in the OAuth2/OIDC `wap` consent page | 中危 | Mavenorg.openidentityplatform.openam:openam-oauth2 | 已审查 | 2026-07-25 05:09 | 2026-07-25 05:09 |
| GHSA-GF8H-GQ53-288J CVE-2026-62263 | OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass | 严重 | Mavenorg.openidentityplatform.openam:openam-auth-webauthn | 已审查 | 2026-07-25 05:08 | 2026-07-25 05:08 |
| GHSA-FRVJ-C5QP-XJ4W CVE-2026-59221 | open-webui terminal proxy path traversal guard bypass via 9x encoded traversal | 高危 | PyPIopen-webui | 已审查 | 2026-07-25 05:05 | 2026-07-25 05:05 |
| GHSA-M3QF-58WF-W979 CVE-2026-59225 | Open WebUI: Arena task endpoints can bypass underlying model access controls | 中危 | PyPIopen-webui | 已审查 | 2026-07-25 04:54 | 2026-07-25 04:54 |
| GHSA-2XWM-4H2Q-GGFX CVE-2026-59212 | Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete | 中危 | PyPIopen-webui | 已审查 | 2026-07-25 04:51 | 2026-07-25 04:51 |
| GHSA-J657-M4C4-24JQ CVE-2026-59224 | Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection) | 高危 | PyPIopen-webui | 已审查 | 2026-07-25 04:49 | 2026-07-25 04:49 |
| GHSA-QG3F-8X3J-GGF2 CVE-2026-59223 | Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching | 中危 | PyPIopen-webui | 已审查 | 2026-07-25 04:49 | 2026-07-25 04:49 |