检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-WVH6-F5JH-8GW4 CVE-2026-55554 | Dompdf: Chroot Validation Bypass | 低危 | Packagistdompdf/dompdf | 已审查 | 2026-07-23 05:06 | 2026-07-23 05:06 |
| GHSA-9R8P-H6CC-6QHM CVE-2026-65599 | n8n: Google Service Account Private Key Exposed in JWT Header |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
npmn8n |
| 已审查 |
| 2026-07-23 02:00 |
| 2026-07-23 02:00 |
| GHSA-9WCP-9R3J-383Q CVE-2026-65592 | n8n: Stored DOM XSS via Resource Locator `cachedResultUrl` | 高危 | npmn8n | 已审查 | 2026-07-23 01:59 | 2026-07-23 01:59 |
| GHSA-P3RG-HRF9-W9GJ CVE-2026-65597 | n8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview | 高危 | npmn8n | 已审查 | 2026-07-23 01:57 | 2026-07-23 01:57 |
| GHSA-G3R5-9H93-4J2C CVE-2026-65598 | n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution | 高危 | npmn8n | 已审查 | 2026-07-23 01:56 | 2026-07-23 01:56 |
| GHSA-X5VX-C2C8-M3W9 CVE-2026-65015 | n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool | 高危 | npmn8n | 已审查 | 2026-07-23 01:55 | 2026-07-23 01:55 |
| GHSA-VHCW-F978-XJJG | Duplicate Advisory: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview 已撤回 | 高危 | npmn8n | 已审查 | 2026-07-22 20:32 | 2026-07-23 01:55 |
| GHSA-RHG6-2VJH-J5QC | Duplicate Advisory: Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware 已撤回 | 高危 | Gogithub.com/traefik/traefik/v2 | 已审查 | 2026-07-22 20:32 | 2026-08-07 00:50 |
| GHSA-MHVH-GWHR-76PW | Duplicate Advisory: Google Service Account Private Key Exposed in JWT Header 已撤回 | 中危 | npmn8n | 已审查 | 2026-07-22 20:32 | 2026-07-23 01:59 |
| GHSA-7M3P-WC52-RMC6 | Duplicate Advisory: Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass 已撤回 | 中危 | Gogithub.com/traefik/traefik | 已审查 | 2026-07-22 20:32 | 2026-08-06 05:51 |
| GHSA-725Q-C4VP-Q4CG | Duplicate Advisory: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution 已撤回 | 高危 | npmn8n | 已审查 | 2026-07-22 20:32 | 2026-07-23 01:54 |
| GHSA-6MXQ-JR92-3H2R | Duplicate Advisory: Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion 已撤回 | 中危 | Gogithub.com/traefik/traefik | 已审查 | 2026-07-22 20:32 | 2026-08-06 05:49 |
| GHSA-WQ64-HCRF-8M56 | Duplicate Advisory: n8n: Privilege Escalation and Code Execution via Full Public API Key Scope Assignment to Token Exchange JWTs 已撤回 | 高危 | npmn8n | 已审查 | 2026-07-22 20:32 | 2026-07-23 05:59 |
| GHSA-W46P-W7W2-FR9G | Duplicate Advisory: AI Agents Project Viewer Privilege Escalation via run_node_tool 已撤回 | 高危 | npmn8n | 已审查 | 2026-07-22 20:32 | 2026-07-23 01:54 |
| GHSA-MWQ7-VCMC-CM4Q | Duplicate Advisory: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner 已撤回 | 高危 | npmn8n | 已审查 | 2026-07-22 20:32 | 2026-07-23 06:02 |
| GHSA-M7JC-P4HF-XHWQ | Duplicate Advisory: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution 已撤回 | 高危 | npmn8n | 已审查 | 2026-07-22 20:32 | 2026-07-23 06:01 |
| GHSA-H9FM-XCV2-QFW3 | Duplicate Advisory: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook 已撤回 | 中危 | npmn8n | 已审查 | 2026-07-22 20:32 | 2026-07-23 06:32 |
| GHSA-H5XR-FQVJ-253P | Duplicate Advisory: Stored DOM XSS via Resource Locator `cachedResultUrl` 已撤回 | 高危 | npmn8n | 已审查 | 2026-07-22 20:32 | 2026-07-23 01:58 |
| GHSA-FMVG-VHQQ-R2MJ | Duplicate Advisory: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data 已撤回 | 中危 | npmn8n | 已审查 | 2026-07-22 20:32 | 2026-07-23 06:53 |
| GHSA-88C4-PCQM-3R9P | Duplicate Advisory: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction 已撤回 | 中危 | npmn8n | 已审查 | 2026-07-22 20:32 | 2026-07-23 06:31 |
| GHSA-5VFW-JC4P-FJ39 | Duplicate Advisory: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check 已撤回 | 中危 | npmn8n | 已审查 | 2026-07-22 20:32 | 2026-07-23 06:30 |
| GHSA-4V35-78JC-648R | Duplicate Advisory: computer-use Shell Sandbox Not Enforced on Linux and Windows 已撤回 | 中危 | npm@n8n/computer-use | 已审查 | 2026-07-22 20:32 | 2026-07-23 06:26 |
| GHSA-38FJ-36M5-783C | Duplicate Advisory: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access 已撤回 | 中危 | npmn8n | 已审查 | 2026-07-22 20:32 | 2026-07-23 06:00 |
| GHSA-PX8P-9VWX-VF98 CVE-2026-45820 | fflate unzipSync can enter an infinite loop when parsing malformed ZIP64 archives | 中危 | npmfflate | 已审查 | 2026-07-22 17:32 | 2026-09-03 22:58 |
| GHSA-V2HH-GCRM-F6HX CVE-2026-16221 | fast-uri vulnerable to host confusion via literal backslash authority delimiter | 高危 | npmfast-uri | 已审查 | 2026-07-22 06:08 | 2026-07-22 06:08 |