Tagged “ghsa”
CVEs tagged ghsa, newest first.
3886 CVEsRSS
GHSA-wvrh-2f4m-924vMedium· 5.5ChatterBot: Symlink-Following Arbitrary Write via UbuntuCorpusTrainer
ChatterBot: Symlink-Following Arbitrary Write via UbuntuCorpusTrainer
GHSA-cw6h-ffmh-x6vhMedium· 6.5Anki: User scripts in iframes have access to the internal Anki API
Anki: User scripts in iframes have access to the internal Anki API
GHSA-4cc2-g9w2-fhf6Medium· 5.9Zeep: Server-Side Request Forgery (SSRF)
Zeep: Server-Side Request Forgery (SSRF)
CVE-2026-11941Medium· 5.6Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
Cloudflare Quiche: Use-after-free in connection ID iterator FFI functions
GHSA-c3xh-98xp-6qhfHighgithubtoplanguages: Command Injection via Issue Title in Discord Notification Workflow
githubtoplanguages: Command Injection via Issue Title in Discord Notification Workflow
GHSA-f4xh-w4cj-qxq8High· 7.7LangSmith SDK TracingMiddleware: Arbitrary server-side file read
LangSmith SDK TracingMiddleware: Arbitrary server-side file read
GHSA-h5x8-xp6m-x6q4High· 7.1@jhb.software/payload-cloudinary-plugin: Arbitrary Cloudinary API Parameter Signing
@jhb.software/payload-cloudinary-plugin: Arbitrary Cloudinary API Parameter Signing
GHSA-g2gw-q38m-vjfcHighLokka: Azure Resource Manager URL path validation issue
Lokka: Azure Resource Manager URL path validation issue
GHSA-4xgf-cpjx-pc3jMedium· 5.3pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size
pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size
GHSA-h5rg-8p7f-47g2Medium· 4.1SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
SurrealDB: SSRF via JWKS URL — Redirect Following in JWT Key Fetch
GHSA-cc8f-fcx3-gpjrHigh· 7.7SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter
GHSA-h4h3-3rfj-x6fqMedium· 4.3SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field
SurrealDB: Indexed ORDER BY leaks the value ordering of a SELECT-restricted field
GHSA-hv6h-hc26-q48pMedium· 4.3SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals
SurrealDB: Field-level SELECT permissions bypassed via graph and reference traversals
GHSA-jv2j-mqmw-xvv5Medium· 6.5SurrealDB: Denial of Service via deep operator chains
SurrealDB: Denial of Service via deep operator chains
GHSA-869j-r97x-hx2gHighAnki's local HTTP server does not sufficiently validate requests
Anki's local HTTP server does not sufficiently validate requests
CVE-2026-58399Critical@acastellon/auth: Authentication bypass via spoofable headers in validateToken()
@acastellon/auth: Authentication bypass via spoofable headers in validateToken()
CVE-2026-54386Medium· 6.1marimo contains a reflected cross-site scripting vulnerability in the notebook page
marimo contains a reflected cross-site scripting vulnerability in the notebook page
CVE-2026-55744High· 8.1Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module
Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module
CVE-2026-55742Critical· 9.6Cotonti: Cross-Site Request Forgery in the administration rights handler
Cotonti: Cross-Site Request Forgery in the administration rights handler
CVE-2026-55745Medium· 5.4Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module
Cotonti: Cross-Site Request Forgery in the Personal File Storage (PFS) module
CVE-2026-55746High· 7.6Cotonti: Stored Cross-Site Scripting in the Personal File Storage (PFS) module
Cotonti: Stored Cross-Site Scripting in the Personal File Storage (PFS) module
CVE-2026-55671LowZITADEL: Server-Side Request Forgery (SSRF) and Denylist Bypass in Outgoing HTTP Components
ZITADEL: Server-Side Request Forgery (SSRF) and Denylist Bypass in Outgoing HTTP Components
CVE-2026-53864High· 8.1OpenClaw: Host environment sanitizer missed two Node.js control variables
OpenClaw: Host environment sanitizer missed two Node.js control variables
CVE-2026-53843High· 8.8OpenClaw: Pairing-scoped device session could restore revoked node token authority
OpenClaw: Pairing-scoped device session could restore revoked node token authority
CVE-2026-53866High· 8.1OpenClaw: Shell inline-command parsing could miss an allowlist check
OpenClaw: Shell inline-command parsing could miss an allowlist check
CVE-2026-53842High· 7.1OpenClaw: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution
OpenClaw: Workspace .env CLOUDSDK_PYTHON could influence Gmail setup gcloud execution
CVE-2026-53863MediumOpenClaw: Tool group policy callers could accept unvalidated group IDs
OpenClaw: Tool group policy callers could accept unvalidated group IDs
CVE-2026-55229High· 7.5PoCGotenberg: SSRF via LibreOffice document processing
Gotenberg: SSRF via LibreOffice document processing
CVE-2026-55886Mediumjodit: Prototype pollution in Jodit via Jodit.modules.Helpers.set()
jodit: Prototype pollution in Jodit via Jodit.modules.Helpers.set()
CVE-2026-55388High· 8.1piscina: Prototype Pollution Gadget → RCE via inherited options.filename
piscina: Prototype Pollution Gadget → RCE via inherited options.filename