检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-Q6MX-QVHP-FQMG | Duplicate Advisory: External Secrets Permission Bypass via Expression Parser Mismatch 已撤回 | 中危 | npmn8n | 已审查 | 2026-07-15 20:32 | 2026-07-23 06:21 |
当前筛选结果 35,190 条 · 时间按北京时间显示
Duplicate Advisory: n8n: External Secrets Accessible via Workflow Expressions Outside Credentials 已撤回 |
| 中危 |
npmn8n |
| 已审查 |
| 2026-07-15 20:32 |
| 2026-07-23 06:23 |
| GHSA-HGJX-R89M-M7V4 | FacturaScripts: Path traversal in UploadedFile::move() via getClientOriginalName() — arbitrary file write outside MyFiles/ leading to RCE | 严重 | Packagistfacturascripts/facturascripts | 已审查 | 2026-07-15 04:52 | 2026-07-15 04:52 |
| GHSA-X9VC-9FFQ-P3GJ CVE-2026-54446 | NetLicensing-MCP: Unauthenticated Use of Server-Side NetLicensing API Key in HTTP Mode | 高危 | PyPInetlicensing-mcp | 已审查 | 2026-07-15 04:47 | 2026-07-15 04:47 |
| GHSA-QF34-295C-26V8 CVE-2026-61549 | Woodpecker: Privilege escalation via unrestricted serviceAccountName in the Kubernetes backend | 高危 | Gogithub.com/woodpecker-ci/woodpecker+2 | 已审查 | 2026-07-15 04:29 | 2026-07-15 04:29 |
| GHSA-7RX3-5WX3-5V76 | Nebula-mesh allows non-admin operators to disable webhook SSRF protection via `allow_private` | 高危 | Gogithub.com/forgekeep/nebula-mesh | 已审查 | 2026-07-15 04:28 | 2026-07-15 04:28 |
| GHSA-CM26-5974-52H8 CVE-2026-61699 | nebula-mesh: Certificate revocation is never enforced at the mesh | 高危 | Gogithub.com/forgekeep/nebula-mesh | 已审查 | 2026-07-15 04:28 | 2026-07-15 04:28 |
| GHSA-2CF7-HPWF-47H9 CVE-2026-55608 | n8n-MCP: Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP mode | 中危 | npmn8n-mcp | 已审查 | 2026-07-15 04:26 | 2026-07-15 04:26 |
| GHSA-G4X6-JCVR-9M3G CVE-2026-55513 | nebula-mesh: Web UI host creation ignores configured enrollment token TTL and mints 24-hour bearer enrollment tokens | 中危 | Gogithub.com/forgekeep/nebula-mesh | 已审查 | 2026-07-15 04:26 | 2026-07-15 04:26 |
| GHSA-M3CX-MWPG-32JG CVE-2026-55512 | nebula-mesh: Unauthenticated OIDC login endpoint allocates unbounded in-memory state entries without rate limiting | 中危 | Gogithub.com/forgekeep/nebula-mesh | 已审查 | 2026-07-15 04:19 | 2026-07-15 04:19 |
| GHSA-MF78-3RPF-R784 CVE-2026-54629 | Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode | 高危 | Gogithub.com/julien040/anyquery | 已审查 | 2026-07-15 04:19 | 2026-07-15 04:19 |
| GHSA-Q4VM-PQ3Q-8WGQ CVE-2026-53603 | nebula-mesh: Operator session tokens stored in plaintext in the database | 高危 | Gogithub.com/forgekeep/nebula-mesh | 已审查 | 2026-07-15 04:17 | 2026-07-15 04:17 |
| GHSA-VHCH-2WF3-M8RP CVE-2026-44891 | Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder | 高危 | Mavenio.netty:netty-codec-stomp | 已审查 | 2026-07-15 04:16 | 2026-07-15 04:16 |
| GHSA-2P2F-PX33-4VV5 CVE-2026-53604 | nebula-mesh: CA private key not zeroized on web mobile-bundle error paths | 高危 | Gogithub.com/forgekeep/nebula-mesh | 已审查 | 2026-07-15 04:05 | 2026-07-15 04:05 |
| GHSA-HWRQ-8WXH-Q4XV CVE-2026-54628 | Anyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server Mode | 高危 | Gogithub.com/julien040/anyquery | 已审查 | 2026-07-15 04:02 | 2026-07-15 04:02 |
| GHSA-Q3V2-XJ35-9GRX | Umbraco.AI discloses sensitive application configuration values | 中危 | NuGetUmbraco.AI | 已审查 | 2026-07-15 03:59 | 2026-07-15 03:59 |
| GHSA-MQXV-9RM6-W8QC | Ech0: ParseAcceptLanguage `_` separator bypass enables ~70x CPU amplification via Accept-Language header in i18n.Middleware | 高危 | Gogithub.com/lin-snow/ech0 | 已审查 | 2026-07-15 03:58 | 2026-07-15 03:58 |
| GHSA-9HC2-HJX8-Q6PV | TidGi Desktop Remote Code Execution via Malicious TiddlyWiki Repository Import — Tiddler Startup Module Auto-Execution | 严重 | npmtidgi | 已审查 | 2026-07-15 03:52 | 2026-07-15 03:52 |
| GHSA-Q3FV-X8VG-QQM4 CVE-2026-54448 | Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser | 高危 | Gogithub.com/aquasecurity/trivy | 已审查 | 2026-07-15 03:52 | 2026-07-15 03:52 |
| GHSA-8559-GWJ3-Q37R CVE-2026-54087 | EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField | 高危 | Packagisteasycorp/easyadmin-bundle | 已审查 | 2026-07-15 03:51 | 2026-07-15 03:51 |
| GHSA-PQG7-V6WH-3PFP | TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services | 高危 | Gogithub.com/almeidapaulopt/tsdproxy | 已审查 | 2026-07-15 03:46 | 2026-07-15 03:46 |
| GHSA-28XV-PH75-77WH CVE-2026-54335 | Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__ | 低危 | npm@feathersjs/commons | 已审查 | 2026-07-15 03:40 | 2026-07-15 03:40 |
| GHSA-2C7F-FXWW-6W6C CVE-2026-50158 | yutu: Arbitrary File Write via MCP `caption-download` Tool | 高危 | Gogithub.com/eat-pray-ai/yutu | 已审查 | 2026-07-15 03:34 | 2026-07-15 03:34 |
| GHSA-FFQ7-HH2J-R24P CVE-2026-50157 | Auth0 Symfony SDK Accepted Bearer Tokens via URL Query Parameter | 中危 | Packagistauth0/symfony | 已审查 | 2026-07-15 03:31 | 2026-07-15 03:31 |
| GHSA-J6R7-6FHX-77WX CVE-2026-54052 | n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments | 严重 | npmn8n-mcp | 已审查 | 2026-07-15 03:07 | 2026-07-15 03:07 |