检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-9R8R-X3VG-6XH4 | Duplicate Advisory: phpMyFAQ: Ordinary Authenticated User Can Access Admin-Only API Endpoints Due to Insufficient Authorization Check 已撤回 | 中危 | PackagistphpMyFAQ/phpMyFAQ+1 | 已审查 | 2026-05-16 05:31 | 2026-06-09 08:01 |
当前筛选结果 998 条 · 时间按北京时间显示
| GHSA-6626-79JH-5CCR |
Duplicate Advisory: phpMyFAQ enables unauthenticated 2FA brute-force attack via /admin/check acceptance of arbitrary user-id 已撤回 |
| 严重 |
Packagistphpmyfaq/phpmyfaq+1 |
| 已审查 |
| 2026-05-16 05:31 |
| 2026-06-09 08:00 |
| GHSA-5H62-F8FG-4W7Q | Duplicate Advisory: phpMyFAQ: Missing Authorization on Tag Deletion Allows Any Authenticated User to Delete Tags 已撤回 | 中危 | PackagistphpMyFAQ/phpMyFAQ+1 | 已审查 | 2026-05-16 05:31 | 2026-06-09 08:05 |
| GHSA-478M-MRW4-QF2W | Duplicate Advisory: phpMyFAQ has stored XSS via | raw Filter in search.twig — html_entity_decode(strip_tags()) Bypass in Search Result Rendering 已撤回 | 高危 | Packagistphpmyfaq/phpmyfaq+1 | 已审查 | 2026-05-16 05:31 | 2026-06-09 08:02 |
| GHSA-XPR6-2HGM-4WWP | Duplicate Advisory: OpenClaw vulnerable to arbitrary code execution via attacker-controlled setup-api.js loaded from cwd during env-key resolution 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-05-12 02:31 | 2026-05-18 23:31 |
| GHSA-V8J2-5F9P-FMH4 | Duplicate Advisory: OpenClaw's Webhooks SecretRef route secret remains valid after rotation/reload 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-05-12 02:31 | 2026-05-18 23:31 |
| GHSA-9J32-3M66-MC4M | Duplicate Advisory: OpenClaw: Hook mapping templates could bypass hook session-key opt-in 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-05-12 02:31 | 2026-05-18 23:29 |
| GHSA-5JGM-F9WR-9QM7 | Duplicate Advisory: OpenClaw: Workspace dotenv files cannot override connector endpoint hosts 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-05-12 02:31 | 2026-05-18 23:29 |
| GHSA-W626-296M-8F85 | Duplicate Advisory: OpenClaw's ACP child sessions inherit subagent security envelope constraints 已撤回 | 低危 | npmopenclaw | 已审查 | 2026-05-12 02:31 | 2026-05-18 23:29 |
| GHSA-P3PV-C954-9M6F | Duplicate Advisory: OpenClaw: Owner-enforced commands could accept wildcard channel senders as command owners 已撤回 | 低危 | npmopenclaw | 已审查 | 2026-05-12 02:31 | 2026-05-18 23:30 |
| GHSA-P3M6-JR2H-HHXJ | Duplicate Advisory: OpenClaw: MCP stdio server env could load dangerous startup variables from workspace config 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-05-12 02:31 | 2026-05-18 23:30 |
| GHSA-M5J2-R859-R5CV | Duplicate Advisory: OpenClaw: Isolated cron awareness events were recorded as trusted system events 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-05-12 02:31 | 2026-05-18 23:29 |
| GHSA-4MHR-CXR4-2PRM | Duplicate Advisory: OpenClaw: Workspace dotenv MiniMax host override could redirect credentialed requests 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-05-12 02:31 | 2026-05-18 23:30 |
| GHSA-J7W6-VPVQ-J3GM CVE-2026-44827 | Diffusers has a `trust_remote_code` bypass via `custom_pipeline` and local custom components 已撤回 | 高危 | PyPIdiffusers | 已审查 | 2026-05-07 10:24 | 2026-06-06 01:53 |
| GHSA-XRGF-R9GR-JJJF | Duplicate Advisory: OpenClaw: Exec environment denylist missed high-risk interpreter startup variables 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-05-07 05:31 | 2026-05-12 00:14 |
| GHSA-WWWC-F646-VJ2J | Duplicate Advisory: OpenClaw: Browser press/type interaction routes missed complete navigation guard coverage 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-05-07 05:31 | 2026-05-12 00:12 |
| GHSA-W7RC-VVGX-PJ45 | Duplicate Advisory: OpenClaw: Browser SSRF hostname validation could be bypassed by DNS rebinding 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-05-07 05:31 | 2026-05-12 00:14 |
| GHSA-R747-33R4-RMJW | Duplicate Advisory: OpenClaw: QQBot direct media upload skipped URL SSRF validation 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-05-07 05:31 | 2026-05-12 00:12 |
| GHSA-QVMW-H675-H7QG | Duplicate Advisory: OpenClaw validates Zalo outbound photo URLs through the SSRF guard 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-05-07 05:31 | 2026-05-12 00:13 |
| GHSA-M8WM-R5VQ-QJPG | Duplicate Advisory: OpenClaw: Gateway HTTP endpoints re-resolve bearer auth after SecretRef rotation 已撤回 | 严重 | npmopenclaw | 已审查 | 2026-05-07 05:31 | 2026-05-12 00:14 |
| GHSA-FRR5-J3MH-H9CH | Duplicate Advisory: OpenClaw: OpenShell FS bridge reads pin and verify the opened file before returning bytes 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-05-07 05:31 | 2026-05-12 00:13 |
| GHSA-CJG8-85GJ-V9Q2 | Duplicate Advisory: OpenClaw: Feishu webhook and card-action validation now fail closed 已撤回 | 严重 | npmopenclaw | 已审查 | 2026-05-07 05:31 | 2026-05-12 00:14 |
| GHSA-9R9J-3R2W-FG3V | Duplicate Advisory: OpenClaw: Workspace dotenv could override runtime-control environment variables 已撤回 | 高危 | npmopenclaw | 已审查 | 2026-05-07 05:31 | 2026-05-12 00:13 |
| GHSA-82RM-QCFX-2V78 | Duplicate Advisory: OpenClaw: Delivery queue recovery could lose group tool-policy context for media replay 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-05-07 05:31 | 2026-05-13 00:18 |
| GHSA-6F72-9GXX-98MJ | Duplicate Advisory: OpenClaw: OpenShell FS bridge writes stay pinned to the sandbox mount root 已撤回 | 中危 | npmopenclaw | 已审查 | 2026-05-07 05:31 | 2026-05-12 00:13 |