检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-GJGQ-W2M6-WR5Q CVE-2026-54771 | Langroid: handle_message() executes user-supplied tool JSON without sender verification | 高危 | PyPIlangroid | 已审查 | 2026-07-07 04:42 | 2026-07-07 04:42 |
| GHSA-Q9P7-WQXG-MRHC CVE-2026-54769 | Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 严重 |
PyPIlangroid |
| 已审查 |
| 2026-07-07 04:42 |
| 2026-07-07 04:42 |
| GHSA-6XC5-4R68-67FC CVE-2026-54760 | Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls | 严重 | PyPIlangroid | 已审查 | 2026-07-07 04:39 | 2026-07-07 04:39 |
| GHSA-CHWM-M7G7-685G CVE-2026-54637 | Dragonfly scheduler v1 and v2 gRPC unauthenticated SSRF via attacker-controlled PeerHost in DownloadTinyFile | 中危 | God7y.io/dragonfly/v2 | 已审查 | 2026-07-07 04:32 | 2026-07-07 04:57 |
| GHSA-R35R-FPX2-JGR4 CVE-2026-53759 | Linuxfabrik Monitoring Plugins allow insecure creation of SQLite databases | 低危 | PyPIlinuxfabrik-lib | 已审查 | 2026-07-07 04:31 | 2026-07-07 04:31 |
| GHSA-X76W-8C62-48MG CVE-2026-56384 | Craft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission | 中危 | Packagistcraftcms/cms | 已审查 | 2026-07-07 04:28 | 2026-08-07 05:06 |
| GHSA-MP2F-45PM-3CG9 CVE-2026-53486 | Decompress: Archive extraction can create files and links outside of the target directory | 严重 | npm@xhmikosr/decompress+1 | 已审查 | 2026-07-07 04:27 | 2026-07-07 04:27 |
| GHSA-P7H3-7Q52-72W8 CVE-2026-35366 | printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection) | 中危 | crates.iouu_printenv | 已审查 | 2026-07-07 04:25 | 2026-07-07 04:25 |
| GHSA-W6XC-G9QJ-VP32 CVE-2026-35362 | uucore: safe_traversal TOCTOU protection only enabled on Linux | 低危 | crates.iouucore | 已审查 | 2026-07-07 04:25 | 2026-07-07 04:25 |
| GHSA-H444-6J9X-P8VH CVE-2026-35365 | mv: symlinks expanded during cross-device move (resource exhaustion / data duplication) | 中危 | crates.iouu_mv | 已审查 | 2026-07-07 04:24 | 2026-07-07 04:24 |
| GHSA-8VRF-R662-2W2V CVE-2026-35358 | cp: -R reads device nodes as streams, destroying device semantics | 中危 | crates.iouu_cp | 已审查 | 2026-07-07 04:21 | 2026-07-07 04:21 |
| GHSA-89P7-7CQ3-HHR2 CVE-2026-35363 | rm: 'rm -rf ./' (and ./// variants) silently deletes current directory contents, bypassing dot protection | 中危 | crates.iouu_rm | 已审查 | 2026-07-07 04:20 | 2026-07-07 04:20 |
| GHSA-3WFC-MGPM-9RQ6 CVE-2026-35347 | comm: FIFO/pipe inputs are drained before comparison (data loss / hang) | 中危 | crates.iouu_comm | 已审查 | 2026-07-07 04:17 | 2026-07-07 04:17 |
| GHSA-47C7-QRM7-MQW7 CVE-2026-35370 | id: groups= computed from real GID instead of effective GID | 中危 | crates.iouu_id | 已审查 | 2026-07-07 04:16 | 2026-07-07 04:16 |
| GHSA-MJ6P-44CH-CQ69 CVE-2026-35353 | mkdir: -m exposes directory with umask perms before chmod (race window) | 低危 | crates.iouu_mkdir | 已审查 | 2026-07-07 04:16 | 2026-07-07 04:16 |
| GHSA-7CR3-H577-G38J CVE-2026-35349 | rm: --preserve-root bypassed via a symlink to / (string check instead of dev/inode) | 中危 | crates.iouu_rm | 已审查 | 2026-07-07 04:15 | 2026-07-07 04:15 |
| GHSA-XV5W-CW7X-72GJ CVE-2026-35371 | id: pretty-print uses effective GID instead of effective UID for name lookup | 低危 | crates.iouu_id | 已审查 | 2026-07-07 03:55 | 2026-07-07 03:55 |
| GHSA-P6RV-2QPM-FWVG CVE-2026-35369 | kill: 'kill -1' parsed as PID -1, sending SIGTERM to all processes (system crash / DoS) | 中危 | crates.iouu_kill | 已审查 | 2026-07-07 03:55 | 2026-07-07 03:55 |
| GHSA-GWM6-Q8CH-HCFR CVE-2026-35356 | install -D: symlink race in directory creation allows arbitrary file overwrite | 中危 | crates.iouu_install | 已审查 | 2026-07-07 03:54 | 2026-07-07 03:54 |
| GHSA-WV33-5PXH-R7J7 CVE-2026-35343 | cut: -s (only-delimited) ignored when delimiter is a newline | 低危 | crates.iouu_cut | 已审查 | 2026-07-07 03:54 | 2026-07-07 03:54 |
| GHSA-239G-2685-54X3 CVE-2026-35355 | install: TOCTOU symlink race (unlink-then-create without O_EXCL) allows arbitrary file overwrite | 中危 | crates.iouu_install | 已审查 | 2026-07-07 03:54 | 2026-07-07 03:54 |
| GHSA-JCJR-RH8Q-7XQF CVE-2026-35373 | ln: rejects non-UTF-8 source filenames in target-directory mode | 低危 | crates.iouu_ln | 已审查 | 2026-07-07 03:53 | 2026-07-07 03:53 |
| GHSA-6GCW-W7CP-94G9 CVE-2026-35346 | comm: lossy UTF-8 conversion silently corrupts non-UTF-8 output | 低危 | crates.iouu_comm | 已审查 | 2026-07-07 03:51 | 2026-07-07 03:51 |
| GHSA-2W8R-9XJ7-69J5 CVE-2026-35342 | mktemp: empty TMPDIR creates temp files in CWD instead of /tmp | 低危 | crates.iouu_mktemp | 已审查 | 2026-07-07 03:50 | 2026-07-07 03:50 |
| GHSA-4X34-CHG5-MWJJ CVE-2026-35339 | chmod: recursive mode returns exit code 0 even when some files fail (last-file-wins) | 中危 | crates.iouu_chmod | 已审查 | 2026-07-07 03:27 | 2026-07-07 03:27 |