Tagged “ghsa”
CVEs tagged ghsa, newest first.
3887 CVEsRSS
CVE-2026-11718Criticalgoogleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken)
googleapis/mcp-toolbox: authentication bypass vulnerability in the generic opaque token validation path (validateOpaqueToken)
CVE-2026-11719HighMCP Toolbox for Databases: authenticated authorization bypass
MCP Toolbox for Databases: authenticated authorization bypass
CVE-2026-22551Medium[Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat
[Eclipse Theia] Data Exfiltration via Markdown Image Rendering in AI Chat
CVE-2026-44688High[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat
[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat
CVE-2026-44691High[Eclipse Theia] Arbitrary Command Execution via Untrusted Workspace Task Definitions
[Eclipse Theia] Arbitrary Command Execution via Untrusted Workspace Task Definitions
CVE-2026-46580High[Eclipse Theia] Indirect Prompt Injection via Auto-Loaded Workspace Prompt Template Files in AI Chat
[Eclipse Theia] Indirect Prompt Injection via Auto-Loaded Workspace Prompt Template Files in AI Chat
GHSA-2rcg-mm5h-xchxHigh· 7.5PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal
PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal
GHSA-fq2m-6wqh-x44gCritical· 9.8PraisonAI: Jobs API exposes agent-execution endpoints with no authentication
PraisonAI: Jobs API exposes agent-execution endpoints with no authentication
GHSA-rjvw-7vvw-549vHigh· 7.2PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding
PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding
GHSA-x8cv-xmq7-p8xpCritical· 9.8PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints
PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints
GHSA-892r-p3jq-jp24Critical· 9.8PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation
PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation
GHSA-rh39-9c67-59mhHigh· 8.1PraisonAI: Missing ownership check on DELETE endpoints allows members to delete others' content in Platform API
PraisonAI: Missing ownership check on DELETE endpoints allows members to delete others' content in Platform API
GHSA-x92v-rpx6-p6cwHigh· 8.6PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots)
PraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots)
GHSA-p75f-6fp4-p57wCritical· 9.8PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai
PraisonAI: Missing Authentication for Critical Function and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in praisonai
GHSA-gcq3-mfvh-3x25High· 7.3PraisonAI Code agent tools fail open without a workspace boundary
PraisonAI Code agent tools fail open without a workspace boundary
GHSA-38x9-25wx-7fg2HighHeimdall: IP Spoofing via Unvalidated Forwarding Headers
Heimdall: IP Spoofing via Unvalidated Forwarding Headers
GHSA-4jgr-pg2m-m988HighHeimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode
Heimdall: Forwarded Header Injection via Unsanitized Host Header in Proxy Mode
GHSA-f44v-7qgw-9gh9High· 8.1PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion
PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion
GHSA-c969-5x3p-vq3vHigh· 8.1PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters
PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters
GHSA-4qq2-2j2x-x62cHigh· 8.2npm PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation
npm PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation
GHSA-vmmj-pfw7-fjwpCritical· 9.9npm PraisonAI codeMode sandbox escape via Function constructor
npm PraisonAI codeMode sandbox escape via Function constructor
GHSA-gqmf-56h7-rrpfHigh· 7.6npm PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients
npm PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients
GHSA-vjv9-7m7j-h833High· 8.8npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining
npm PraisonAI SandboxExecutor allowedCommands bypass via shell chaining
GHSA-p69m-4f92-2v84Critical· 9.8PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool
PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool
GHSA-9752-mhqh-h34fCritical· 9.4npm PraisonAI AgentOS exposes unauthenticated agent listing and invocation
npm PraisonAI AgentOS exposes unauthenticated agent listing and invocation
GHSA-j4f3-55x4-r6q2Critical· 9.8npm PraisonAI MCPServer exposes unauthenticated HTTP tools/call
npm PraisonAI MCPServer exposes unauthenticated HTTP tools/call
GHSA-h2w2-v7j6-xqm4High· 8.8npm PraisonAI AgentLoop onToolCall approval runs after tool execution
npm PraisonAI AgentLoop onToolCall approval runs after tool execution
GHSA-5jv7-2mjm-h6qjHigh· 8.8npm PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining
npm PraisonAI utility shell safe-command wrapper allowlist bypass via shell chaining
GHSA-7qw2-w5rc-37x2High· 7.8PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml
PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml
GHSA-jxcw-qp4h-6jfqHigh· 7.5PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default
PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default