VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3887 CVEsRSS

GHSA-29w3-p9w9-wc47Critical· 9.1
3mo ago

PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation

PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation

▾ Midnightpraisonai · praisonaivia GHSA
GHSA-f38v-77qj-h4jqCritical· 9.8
3mo ago

praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard)

praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard)

▾ Midnightpraisonai-platform · praisonai-platformvia GHSA
GHSA-4pcv-mg8v-vrgfHigh· 8.8
3mo ago

PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter

PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter

▾ Twilightpraisonaiagents · praisonaiagentsvia GHSA
GHSA-8ccj-p46r-jwqqHigh· 8.2
3mo ago

PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication

PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-6jcq-6546-qrrwHigh· 8.8
3mo ago

PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable

PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable

▾ Twilightpraisonai · praisonaivia GHSA
GHSA-cwj8-7gp2-ggcwCritical· 9.8
3mo ago

praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery

praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery

▾ Midnightpraisonai-platform · praisonai-platformvia GHSA
GHSA-cmwh-pvxp-8882Medium
3mo ago

DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)

DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)

▾ Sunlitdompurify · dompurifyvia GHSA
CVE-2026-47103Critical· 9.8PoC
3mo ago

python-statemachine SCXML <data expr> Eval Injection

python-statemachine SCXML <data expr> Eval Injection

▾ Abyssalpython-statemachine · python-statemachineEPSS 1.4%via GHSA
GHSA-p6gq-j5cr-w38fHigh· 7.1
3mo ago

Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message

Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message

▾ Twilightnodemailer · nodemailervia GHSA
CVE-2026-9675High· 7.5
3mo ago

undici WebSocket client vulnerable to denial of service via cumulative fragment bypass

undici WebSocket client vulnerable to denial of service via cumulative fragment bypass

▾ Twilightundici · undiciEPSS 0.49%via GHSA
CVE-2026-9678Medium· 5.9
3mo ago

undici vulnerable to cross-user information disclosure via shared cache whitespace bypass

undici vulnerable to cross-user information disclosure via shared cache whitespace bypass

▾ Sunlitundici · undiciEPSS 0.42%via GHSA
GHSA-jm82-fx9c-mx94Medium
3mo ago

pypdf: Missing stream length values ignore defined limits

pypdf: Missing stream length values ignore defined limits

▾ Sunlitpypdf · pypdfvia GHSA
CVE-2026-55686Medium· 5.3
3mo ago

Podman: WORKDIR symlink traversal vulnerability

Podman: WORKDIR symlink traversal vulnerability

▾ Sunlitcontainers · github.com/containers/podman/v5EPSS 0.40%via GHSA
GHSA-j99q-93c9-h869Medium
3mo ago

MCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalence

MCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalence

▾ Sunlitbitbonsai · @bitbonsai/mcpvaultvia GHSA
CVE-2026-55885Medium· 6.8
3mo ago

Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets

Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets

▾ Sunlitgetgrav · getgrav/gravEPSS 0.27%via GHSA
GHSA-2fjj-qqg8-fg7xMedium· 4.3
3mo ago

praisonai-platform: Authorization Bypass Through User-Controlled Key

praisonai-platform: Authorization Bypass Through User-Controlled Key

▾ Sunlitpraisonai-platform · praisonai-platformvia GHSA
CVE-2026-55890Medium· 4.8
3mo ago

Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style() — incomplete patch of GHSA-r7fx-8g49-7hhr

Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style() — incomplete patch of GHSA-r7fx-8g49-7hhr

▾ Sunlitgetgrav · getgrav/gravEPSS 0.31%via GHSA
CVE-2026-53861Medium· 6.6
3mo ago

OpenClaw: macOS Swift exec allowlist missed combined POSIX inline flags

OpenClaw: macOS Swift exec allowlist missed combined POSIX inline flags

▾ Sunlitopenclaw · openclawEPSS 0.45%via GHSA
CVE-2026-12566Low· 3.1
3mo ago

BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing

BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing

▾ Sunlitbbot · bbotEPSS 0.17%via GHSA
CVE-2026-12565Medium· 5.3
3mo ago

BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284

BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284

▾ Sunlitbbot · bbotEPSS 0.21%via GHSA
CVE-2026-12568Medium· 6.5
3mo ago

BBOT: Arbitrary File Write in postman_download Module

BBOT: Arbitrary File Write in postman_download Module

▾ Sunlitbbot · bbotEPSS 0.25%via GHSA
CVE-2026-12567Low· 2.2
3mo ago

BBOT: Symlink-Following Arbitrary Write via github_workflows Module

BBOT: Symlink-Following Arbitrary Write via github_workflows Module

▾ Sunlitbbot · bbotEPSS 0.09%via GHSA
CVE-2026-44727Medium· 5.4
3mo ago

Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP

Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP

▾ Sunlitjupyter-server · jupyter-serverEPSS 0.44%via OSV
CVE-2026-49274Medium
3mo ago

Kirby: `pages.access` permission is not checked in the pages picker for parent pages

Kirby: `pages.access` permission is not checked in the pages picker for parent pages

▾ Sunlitgetkirby · getkirby/cmsEPSS 0.48%via GHSA
CVE-2026-49276High
3mo ago

Kirby: Self cross-site scripting (self-XSS) in the writer field

Kirby: Self cross-site scripting (self-XSS) in the writer field

▾ Twilightgetkirby · getkirby/cmsEPSS 0.43%via GHSA
CVE-2026-50188Medium
3mo ago

Kirby: Request header injection in `Http\Remote`

Kirby: Request header injection in `Http\Remote`

▾ Sunlitgetkirby · getkirby/cmsEPSS 0.44%via GHSA
CVE-2026-54002High
3mo ago

Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`

Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`

▾ Twilightgetkirby · getkirby/cmsEPSS 0.55%via GHSA
CVE-2026-54004Medium
3mo ago

Kirby: Access to files of top-level drafts is not protected by permissions

Kirby: Access to files of top-level drafts is not protected by permissions

▾ Sunlitgetkirby · getkirby/cmsEPSS 0.50%via GHSA
CVE-2026-54003Critical
3mo ago

Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header

Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header

▾ Midnightgetkirby · getkirby/cmsEPSS 0.74%via GHSA
CVE-2026-54005High
3mo ago

Kirby: `pages.access` permission is not checked in the `site/find` REST API route

Kirby: `pages.access` permission is not checked in the `site/find` REST API route

▾ Twilightgetkirby · getkirby/cmsEPSS 0.43%via GHSA
CVEs tagged “ghsa” — page 112 · VulnSea