检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-2944-57XV-2682 | @asymmetric-effort/specifyjs: `data:` URI allowed without size restriction | 中危 | npm@asymmetric-effort/specifyjs | 已审查 | 2026-07-03 03:07 | 2026-07-03 03:07 |
| GHSA-XW57-23P8-9WC5 | @asymmetric-effort/specifyjs: Localhost bypass incomplete (IPv6, 0.0.0.0, 127.x range) |
当前筛选结果 35,190 条 · 时间按北京时间显示
npm@asymmetric-effort/specifyjs |
| 已审查 |
| 2026-07-03 03:07 |
| 2026-07-03 03:07 |
| GHSA-QCR8-X557-7CP3 | @asymmetric-effort/specifyjs: Production console warnings may leak internal framework state | 中危 | npm@asymmetric-effort/specifyjs | 已审查 | 2026-07-03 03:03 | 2026-07-03 03:03 |
| GHSA-5C7W-4WM3-85VW | @asymmetric-effort/specifyjs: GraphQL gql tag allows metacharacter injection | 中危 | npm@asymmetric-effort/specifyjs | 已审查 | 2026-07-03 03:00 | 2026-07-03 03:00 |
| GHSA-8882-FRVV-92W4 CVE-2026-50288 | @asymmetric-effort/specifyjs: URL parse failure silently allows request | 高危 | npm@asymmetric-effort/specifyjs | 已审查 | 2026-07-03 02:59 | 2026-07-03 02:59 |
| GHSA-7H62-6V23-V8FM CVE-2026-50284 | Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assets | 高危 | Packagistcraftcms/cms | 已审查 | 2026-07-03 02:49 | 2026-07-03 02:49 |
| GHSA-QH45-9G5P-M2V4 CVE-2026-50283 | Craft CMS: Unauthorized Deletion of Source Assets During File Replacement | 中危 | Packagistcraftcms/cms | 已审查 | 2026-07-03 02:48 | 2026-07-03 02:48 |
| GHSA-43CQ-C2GQ-PFPW CVE-2026-50280 | Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save check | 中危 | Packagistcraftcms/cms | 已审查 | 2026-07-03 02:47 | 2026-07-03 02:47 |
| GHSA-QQ2C-2Q8J-JH27 CVE-2026-50279 | Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gap | 高危 | Packagistcraftcms/cms | 已审查 | 2026-07-03 02:45 | 2026-07-03 02:45 |
| GHSA-M3CR-VC2J-PM27 CVE-2026-44454 | Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent | 高危 | Gogithub.com/coder/coder+1 | 已审查 | 2026-07-03 02:14 | 2026-07-08 06:17 |
| GHSA-4H7G-5542-V3FC CVE-2026-52854 | mediawiki/maps has stored XSS through the overlays parameter in the display_map parser function | 高危 | Packagistmediawiki/maps | 已审查 | 2026-07-03 01:51 | 2026-07-03 01:51 |
| GHSA-GFHV-VQV2-4544 CVE-2026-52726 | Dulwich's submodule path traversal in porcelain.submodule_update / porcelain.clone(recurse_submodules=True) yields RCE via attacker-dropped .git/hooks payload | 高危 | PyPIdulwich | 已审查 | 2026-07-03 01:50 | 2026-07-03 01:50 |
| GHSA-PMCH-G965-GRMR CVE-2026-50180 | Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read | 高危 | PyPIlangroid | 已审查 | 2026-07-03 01:42 | 2026-07-03 01:42 |
| GHSA-FG23-3346-88F5 CVE-2026-50181 | Langroid: Path traversal in the file tools allows read/write outside configured current directory | 高危 | PyPIlangroid | 已审查 | 2026-07-03 01:38 | 2026-07-03 01:38 |
| GHSA-H5GX-45RJ-2H5J CVE-2026-50192 | Kerberos Hub private key (X-Kerberos-Hub-PrivateKey) leaked to cross-host redirect target due to redirect-following HTTP client without CheckRedirect | 中危 | Gogithub.com/kerberos-io/agent/machinery | 已审查 | 2026-07-03 01:33 | 2026-07-03 01:33 |
| GHSA-P73F-W79W-JQR5 | OpenClaw: Native command authorization could skip owner-command enforcement | 高危 | npmopenclaw | 已审查 | 2026-07-03 01:23 | 2026-07-03 01:23 |
| GHSA-J472-GF56-X589 CVE-2026-53836 | OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks | 高危 | npmopenclaw | 已审查 | 2026-07-03 01:22 | 2026-08-26 00:39 |
| GHSA-77Q5-RR5V-X43Q | OpenClaw: Trusted retry endpoint checks could match hostname prefixes | 高危 | npmopenclaw | 已审查 | 2026-07-03 01:22 | 2026-07-03 01:22 |
| GHSA-W5WW-7CHG-MXCQ | OpenClaw: Telegram interactive callbacks could skip commands.allowFrom | 高危 | npmopenclaw | 已审查 | 2026-07-03 01:18 | 2026-07-03 01:18 |
| GHSA-3RJW-M598-PQ24 CVE-2026-50185 | Cmov/CmovEq on aarch64 can produce wrong results if high-bits of registers are set | 中危 | crates.iocmov | 已审查 | 2026-07-03 01:18 | 2026-07-03 01:18 |
| GHSA-G3XR-5W5J-W4Q4 CVE-2026-50149 | Contour has Improper JWT Verification for Non-SNI Requests on Virtual Hosts with Fallback Certificate Enabled | 中危 | Gogithub.com/projectcontour/contour | 已审查 | 2026-07-03 01:15 | 2026-07-03 01:15 |
| GHSA-7HXM-F538-3XP6 CVE-2026-53811 | OpenClaw: Matrix allowFrom could bind to mutable display names | 高危 | npmopenclaw | 已审查 | 2026-07-03 01:13 | 2026-07-03 01:13 |
| GHSA-4M3V-Q747-PC6H | OpenClaw: Mattermost slash token revocation could lag until monitor refresh | 中危 | npmopenclaw | 已审查 | 2026-07-03 01:13 | 2026-07-03 01:13 |
| GHSA-3C6J-HQ33-3JV4 CVE-2026-53816 | OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance | 高危 | npmopenclaw | 已审查 | 2026-07-03 01:12 | 2026-07-03 01:12 |
| GHSA-VXX3-6HC9-7CC3 CVE-2026-53806 | OpenClaw: Combined POSIX shell options could confuse exec revalidation | 高危 | npmopenclaw | 已审查 | 2026-07-03 01:11 | 2026-07-03 01:13 |