检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-RMJ4-M9CP-MP9V | Duplicate Advisory: Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics 已撤回 | 中危 | Packagistcraftcms/cms | 已审查 | 2026-07-06 14:31 | 2026-09-01 03:42 |
当前筛选结果 998 条 · 时间按北京时间显示
| GHSA-Q5H6-FCF5-49G9 |
Duplicate Advisory: Arbitrary File Read via Path Traversal in nltk.data.load() through Percent-Encoded Sequences 已撤回 |
| 高危 |
PyPInltk |
| 已审查 |
| 2026-06-30 11:37 |
| 2026-08-14 04:44 |
| GHSA-JCMP-JXH2-4JC3 | Duplicate Advisory: Craft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file read 已撤回 | 高危 | Packagistcraftcms/cms | 已审查 | 2026-06-21 23:31 | 2026-08-07 05:58 |
| GHSA-F95G-VM94-46C3 | Duplicate Advisory: Craft CMS Vulnerable to Stored XSS in Settings Names and Field Options 已撤回 | 中危 | Packagistcraftcms/cms | 已审查 | 2026-06-21 23:31 | 2026-08-07 05:39 |
| GHSA-XJ2C-G5XP-4P47 | Duplicate Advisory: Craft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission 已撤回 | 中危 | Packagistcraftcms/cms | 已审查 | 2026-06-21 23:31 | 2026-08-07 05:06 |
| GHSA-PMM4-V8F6-4VPP | Duplicate Advisory: Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview 已撤回 | 高危 | Packagistcraftcms/cms | 已审查 | 2026-06-21 23:31 | 2026-08-07 05:41 |
| GHSA-F4H3-QHG5-J6MQ | Duplicate Advisory: Craft CMS: Authorized asset "preview file" requests bypass allows users without asset access to retrieve private preview metadata 已撤回 | 中危 | Packagistcraftcms/cms | 已审查 | 2026-06-21 23:31 | 2026-08-07 05:56 |
| GHSA-9R7J-7JHG-4F4C | Duplicate Advisory: Craft CMS Vulnerable to Stored XSS via User Group Name in User Permissions Page 已撤回 | 中危 | Packagistcraftcms/cms | 已审查 | 2026-06-21 23:31 | 2026-08-07 05:37 |
| GHSA-5W9J-W5P8-R4P7 | Duplicate Advisory: Craft CMS has Stored XSS in Table Field in its "Row Heading" Column Type 已撤回 | 中危 | Packagistcraftcms/cms | 已审查 | 2026-06-21 23:31 | 2026-08-07 04:47 |
| GHSA-X44P-GG67-52FC | Duplicate Advisory: PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands 已撤回 | 中危 | PyPIpraisonai | 已审查 | 2026-06-19 08:31 | 2026-06-20 05:32 |
| GHSA-FWH2-95JW-G4J6 | Duplicate Advisory: PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling 已撤回 | 高危 | PyPIpraisonai | 已审查 | 2026-06-19 08:31 | 2026-06-20 05:33 |
| GHSA-J6C9-QVP8-699F | Duplicate Advisory: picklescan missing detection by simple obfuscation of a `builtins.eval` call 已撤回 | 严重 | PyPIpicklescan | 已审查 | 2026-06-18 02:35 | 2026-06-18 22:41 |
| GHSA-CC5P-54X3-HCF8 | Duplicate Advisory: Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER 已撤回 | 高危 | PyPIpicklescan | 已审查 | 2026-06-18 02:35 | 2026-06-18 22:43 |
| GHSA-82FG-2R99-H7V6 | Duplicate Advisory: PickleScan's pkgutil.resolve_name has a universal blocklist bypass 已撤回 | 严重 | PyPIpicklescan | 已审查 | 2026-06-18 02:35 | 2026-06-18 22:45 |
| GHSA-5V23-73V4-W2FP | Duplicate Advisory: picklescan has Arbitrary file read using `io.FileIO` 已撤回 | 高危 | PyPIpicklescan | 已审查 | 2026-06-18 02:35 | 2026-06-18 22:46 |
| GHSA-4MPJ-78P6-RJ59 | Duplicate Advisory: PickleScan's profile.run blocklist mismatch allows exec() bypass 已撤回 | 严重 | PyPIpicklescan | 已审查 | 2026-06-18 02:35 | 2026-06-18 22:43 |
| GHSA-RMPP-8WF5-XX5Q | Duplicate Advisory: Picklescan vulnerable to Arbitrary File Writing 已撤回 | 严重 | PyPIpicklescan | 已审查 | 2026-06-18 02:35 | 2026-06-18 22:44 |
| GHSA-7F79-RVX6-VXC4 | Duplicate Advisory: Picklescan does not block ctypes 已撤回 | 严重 | PyPIpicklescan | 已审查 | 2026-06-18 02:35 | 2026-06-18 22:44 |
| GHSA-6V84-V468-3C7F | Duplicate Advisory: Picklescan has Incomplete List of Disallowed Inputs 已撤回 | 严重 | PyPIpicklescan | 已审查 | 2026-06-18 02:35 | 2026-06-18 22:40 |
| GHSA-5RPH-Q42J-36J9 | Duplicate Advisory: Picklescan has pickle parsing logic flaw that leads to malicious pickle file bypass 已撤回 | 严重 | PyPIpicklescan | 已审查 | 2026-06-18 02:35 | 2026-06-18 22:40 |
| GHSA-5GP7-4733-2W2V | Duplicate Advisory: Picklescan Bypasses Unsafe Globals Check using pty.spawn 已撤回 | 高危 | PyPIpicklescan | 已审查 | 2026-06-18 02:35 | 2026-06-18 22:41 |
| GHSA-X8XR-MJ9X-6H7W | Duplicate Advisory: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations 已撤回 | 中危 | PyPIvllm | 已审查 | 2026-06-18 02:35 | 2026-06-18 22:31 |
| GHSA-VR6H-VXQJ-3PJX | Duplicate Advisory: Host environment sanitizer missed two Node.js control variables 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-06-17 05:32 | 2026-06-18 21:02 |
| GHSA-V383-2WGG-V483 | Duplicate Advisory: Shell inline-command parsing could miss an allowlist check 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-06-17 05:32 | 2026-06-18 21:03 |
| GHSA-H9H6-PWQV-J9HV | Duplicate Advisory: Bootstrap token replay could widen pending pairing scopes 已撤回 | 低危 | npmopenclaw | 已审查 | 2026-06-17 05:32 | 2026-06-19 04:12 |