VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3534 CVEsRSS

CVE-2026-61687High· 7.1
today

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ValidateOAuthState clears the oauth_state_ session value to an empty string after a successful OAuth callback and later…

Twilighthatchet · hatchetvia NVD
CVE-2026-55074High· 8.2
today

Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin for FreeBSD Jails via jexec

Ansible FreeBSD Jail Connection Plugin is an Ansible connection plugin for FreeBSD Jails via jexec. Through version 1.3.0, the jailexec connection plugin's put_file resolved a transfer's destination to a path on the jail host ( + ) and r…

Twilightchofstede · ansible_jailexecvia NVD
CVE-2026-55071High· 8.4PoC
today

MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design

MCP-for-Stata is a MCP server for integrating Stata into agent loops with a safety-first design. Prior to version 1.19.0, the ado_package_install MCP tool in stata-mcp concatenates user-controlled input directly into a Stata command stri…

MidnightSepineTam · mcp-for-statavia NVD
GHSA-xwmw-prc4-v3crHigh· 8.8
3d ago

Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion

Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion

Twilightobot-platform · github.com/obot-platform/obotvia OSV
GHSA-pr6h-vr44-xq8jMedium· 5.3
3d ago

Obot: MCP Registry API readable without authentication

Obot: MCP Registry API readable without authentication

Sunlitobot-platform · github.com/obot-platform/obotvia OSV
GHSA-jgh3-fggc-mcpmHigh· 7.6
3d ago

Obot: Server-Side Request Forgery via remote MCP server URL

Obot: Server-Side Request Forgery via remote MCP server URL

Twilightobot-platform · github.com/obot-platform/obotvia OSV
CVE-2026-59163Critical· 9.1PoC
3d ago

Mnemosyne is a memory layer for artificial intelligence agents

Mnemosyne is a memory layer for artificial intelligence agents. Prior to v3.10.1, the auth check in mnemosyne/core/sync_server.py parsed the JWT's header and payload using base64 decoding, then passed the token to a jwt library call with…

Abyssalmnemosyne-memory · mnemosyne-memoryEPSS 0.25%via NVD
CVE-2026-85058High· 7.5
3d ago

Moquette is a lightweight Java MQTT broker

Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last Will message through publish2Subscribers without invoking the authorizator.canWrite check used by normal PUBLISH paths…

Twilightmoquette · io.moquette:moquette-brokerEPSS 0.27%via NVD
CVE-2026-71537Medium· 6.5
3d ago

Paymenter is a free and open-source webshop solution for management of hosting services

Paymenter is a free and open-source webshop solution for management of hosting services. Prior to 1.5.7, app/Livewire/Services/Upgrade.php::doUpgrade() relies on Service::upgradable to check for a pending service upgrade and later execut…

Sunlitpaymenter · paymenter/paymenterEPSS 0.23%via NVD
GHSA-jr78-w6w5-m8f8High· 7.3
3d ago

Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasks

Semantic MediaWiki'a missing authorization in the smwtask API module allows unauthenticated access to admin-only maintenance tasks

Twilightmediawiki · mediawiki/semantic-media-wikivia GHSA
GHSA-9rcc-pmj8-ffhrMedium· 6.1
3d ago

Semantic MediaWiki's Special:FacetedSearch cstate hidden inputs enable reflected XSS (residual of CVE-2025-10354)

Semantic MediaWiki's Special:FacetedSearch cstate hidden inputs enable reflected XSS (residual of CVE-2025-10354)

Sunlitmediawiki · mediawiki/semantic-media-wikivia GHSA
CVE-2025-66455Critical· 9.8
3d ago

LMDeploy is a toolkit for compressing, deploying, and serving large language models

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior to version 0.16.0, LMDeploy's PyTorch DistServe/PD-disaggregation control plane used `recv_pyobj()` to deserialize m…

MidnightInternLM · lmdeployEPSS 0.70%via NVD
GHSA-39wr-7q6h-cf68High· 7.5
3d ago

LMDeploy has an SSRF bypass

LMDeploy has an SSRF bypass

Twilightlmdeploy · lmdeployvia OSV
CVE-2026-33625High· 8.8
3d ago

LMDeploy is a toolkit for compressing, deploying, and serving large language models

LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions 012.1 through 0.12.2 contain a code injection vulnerability in `lmdeploy/pytorch/config.py` line 620 that allows an attacker to execute arbitra…

TwilightInternLM · lmdeployEPSS 0.24%via NVD
CVE-2026-64847Medium· 6.8
3d ago

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Prior to 4.14.2, AnyIO starts process-pool workers with standard error connected to a pipe that the parent never drains,…

Sunlitagronholm · anyioEPSS 0.12%via NVD
CVE-2026-63374Critical
3d ago

AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing

AnyIO: TLSStream IDNA 2003 host name encoding enables potential TLS certificate spoofing

Midnightanyio · anyiovia OSV
CVE-2026-91127High· 8.2
3d ago

File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applications

File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applications. Prior to @file-viewer/doc 2.3.1 and msdoc-viewer 0.2.2, the legacy DOC renderer emitted document-controlled h…

Twilightfile-viewer · @file-viewer/docEPSS 0.24%via NVD
CVE-2026-84992Medium· 6.1PoC
3d ago

md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript

md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript. Prior to 6.5.4, MdPreview's useMarkdownIt() highlight callback in packages/MdEditor/layouts/Content/composition/useMarkdownIt.ts inserts a fenced-code language …

Twilightimzbf · md-editor-v3EPSS 0.23%via NVD
CVE-2026-63458High· 7.1
3d ago

Perses is an open-source dashboard and visualization project for observability data

Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-beta.3, an authenticated user with viewer access to one project can supply another project through the project query parameter on projec…

Twilightperses · persesEPSS 0.30%via NVD
CVE-2026-63445High· 7.1
3d ago

Perses is an open-source dashboard and visualization project for observability data

Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-rc.0, list endpoints used with the file-system database bind the request-controlled project query parameter into the resource Query stru…

Twilightperses · github.com/perses/persesEPSS 0.56%via NVD
CVE-2026-63199High· 8.3
3d ago

Perses is an open-source dashboard and visualization project for observability data

Perses is an open-source dashboard and visualization project for observability data. From 0.43.0 until 0.54.0-rc.0, the datasource creation and unsaved datasource proxy paths authorize the caller on a Datasource or GlobalDatasource scope…

Twilightperses · github.com/perses/persesEPSS 0.27%via NVD
CVE-2026-77616Medium· 6.1
3d ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. In versions 7.0.0 through 7.1.0, `Special:Ask` accepts a `cursor` query parameter for keyset pagination (added…

Sunlitmediawiki · mediawiki/semantic-media-wikiEPSS 0.20%via NVD
CVE-2026-77610Medium· 6.1
3d ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, query debug output (`format=debug`, or the `debug` request parameter on `Special:Ask`)…

Sunlitmediawiki · mediawiki/semantic-media-wikiEPSS 0.15%via NVD
CVE-2026-77609Medium· 6.1
3d ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, `Special:URIResolver` resolves its user-controlled subpage to a MediaWiki title and is…

Sunlitmediawiki · mediawiki/semantic-media-wikiEPSS 0.15%via NVD
CVE-2026-77607Medium· 6.1
3d ago

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages

Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's pages. Prior to version 7.2.0, `sep` was inserted verbatim into HTML cell joins. This made it possible to inject HTML…

SunlitSemanticMediaWiki · SemanticMediaWikiEPSS 0.15%via NVD
CVE-2026-63406Medium· 5.9PoC
3d ago

AnyCable is a realtime server for reliable two-way communication that supports any backend

AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the telemetry subsystem in telemetry/config.go enables tracking with a hardcoded public authToken, while clusterFingerprint in t…

Twilightanycable · github.com/anycable/anycableEPSS 0.24%via NVD
CVE-2026-63405Medium· 5.9PoC
3d ago

AnyCable is a realtime server for reliable two-way communication that supports any backend

AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the Pusher-compatible REST API in pusher/http.go includes the caller-supplied body_md5 value in the HMAC input but does not calc…

Twilightanycable · github.com/anycable/anycableEPSS 0.17%via NVD
CVE-2026-63349High· 7.0
3d ago

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio

AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In 4.14.0, AnyIO accepts the POSIX extra_groups argument in anyio.run_process() and anyio.open_process(), but open_proce…

Twilightanyio · anyioEPSS 0.11%via NVD
CVE-2026-61833High· 8.1
3d ago

zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification

zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification. Prior to 2.1.18, the bearer authentication handler in pkg/api/authn.go maps every HTTP method other than GET and HEAD to th…

Twilightzot · zotregistry.dev/zot/v2EPSS 0.43%via NVD
CVE-2026-81505High· 7.1PoC
3d ago

Convoy is a cloud native webhooks gateway

Convoy is a cloud native webhooks gateway. Prior to 26.6.8, Convoy's GET /api/v1/projects/{projectID}/sources/{sourceID} endpoint authorizes access to the project in the URL, but Handler.GetSource calls sources.Service.FindSourceByID() a…

Midnightfrain-dev · github.com/frain-dev/convoyEPSS 0.34%via NVD
CVEs tagged “ghsa” · VulnSea