Tagged “ghsa”
CVEs tagged ghsa, newest first.
3887 CVEsRSS
GHSA-29w3-p9w9-wc47Critical· 9.1PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation
PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation
GHSA-f38v-77qj-h4jqCritical· 9.8praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard)
praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard)
GHSA-4pcv-mg8v-vrgfHigh· 8.8PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter
PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter
GHSA-8ccj-p46r-jwqqHigh· 8.2PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication
PraisonAI: PRAISONAI_CALL_AUTH=disabled environment variable unconditionally disables authentication
GHSA-6jcq-6546-qrrwHigh· 8.8PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable
PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable
GHSA-cwj8-7gp2-ggcwCritical· 9.8praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery
praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery
GHSA-cmwh-pvxp-8882MediumDOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)
DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)
CVE-2026-47103Critical· 9.8PoCpython-statemachine SCXML <data expr> Eval Injection
python-statemachine SCXML <data expr> Eval Injection
GHSA-p6gq-j5cr-w38fHigh· 7.1Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message
Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message
CVE-2026-9675High· 7.5undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
undici WebSocket client vulnerable to denial of service via cumulative fragment bypass
CVE-2026-9678Medium· 5.9undici vulnerable to cross-user information disclosure via shared cache whitespace bypass
undici vulnerable to cross-user information disclosure via shared cache whitespace bypass
GHSA-jm82-fx9c-mx94Mediumpypdf: Missing stream length values ignore defined limits
pypdf: Missing stream length values ignore defined limits
CVE-2026-55686Medium· 5.3Podman: WORKDIR symlink traversal vulnerability
Podman: WORKDIR symlink traversal vulnerability
GHSA-j99q-93c9-h869MediumMCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalence
MCPVault: PathFilter restricted-directory deny-list bypass via case and trailing dot/space equivalence
CVE-2026-55885Medium· 6.8Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets
Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets
GHSA-2fjj-qqg8-fg7xMedium· 4.3praisonai-platform: Authorization Bypass Through User-Controlled Key
praisonai-platform: Authorization Bypass Through User-Controlled Key
CVE-2026-55890Medium· 4.8Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style() — incomplete patch of GHSA-r7fx-8g49-7hhr
Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style() — incomplete patch of GHSA-r7fx-8g49-7hhr
CVE-2026-53861Medium· 6.6OpenClaw: macOS Swift exec allowlist missed combined POSIX inline flags
OpenClaw: macOS Swift exec allowlist missed combined POSIX inline flags
CVE-2026-12566Low· 3.1BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing
BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing
CVE-2026-12565Medium· 5.3BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284
BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284
CVE-2026-12568Medium· 6.5BBOT: Arbitrary File Write in postman_download Module
BBOT: Arbitrary File Write in postman_download Module
CVE-2026-12567Low· 2.2BBOT: Symlink-Following Arbitrary Write via github_workflows Module
BBOT: Symlink-Following Arbitrary Write via github_workflows Module
CVE-2026-44727Medium· 5.4Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP
Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP
CVE-2026-49274MediumKirby: `pages.access` permission is not checked in the pages picker for parent pages
Kirby: `pages.access` permission is not checked in the pages picker for parent pages
CVE-2026-49276HighKirby: Self cross-site scripting (self-XSS) in the writer field
Kirby: Self cross-site scripting (self-XSS) in the writer field
CVE-2026-50188MediumKirby: Request header injection in `Http\Remote`
Kirby: Request header injection in `Http\Remote`
CVE-2026-54002HighKirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`
CVE-2026-54004MediumKirby: Access to files of top-level drafts is not protected by permissions
Kirby: Access to files of top-level drafts is not protected by permissions
CVE-2026-54003CriticalKirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header
CVE-2026-54005HighKirby: `pages.access` permission is not checked in the `site/find` REST API route
Kirby: `pages.access` permission is not checked in the `site/find` REST API route