VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3886 CVEsRSS

CVE-2026-54695High· 7.5
3mo ago

Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID

Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID

▾ Twilightpipecat-ai · pipecat-aiEPSS 0.56%via GHSA
CVE-2026-54711Low
3mo ago

PGHoard: Password written to debug log

PGHoard: Password written to debug log

▾ Sunlitpghoard · pghoardvia GHSA
CVE-2026-55170Low
3mo ago

OpenFGA Improper Policy Enforcement

OpenFGA Improper Policy Enforcement

▾ Sunlitopenfga · github.com/openfga/openfgaEPSS 0.34%via GHSA
CVE-2026-54319Medium· 4.2
3mo ago

Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape

Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape

▾ Sunlitdaytonaio · github.com/daytonaio/daytonaEPSS 0.24%via GHSA
CVE-2026-54683Medium· 6.5
3mo ago

NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463)

NL Portal Backend Libraries: Document contents remained downloadable by any logged-in user (incomplete fix of CVE-2026-49463)

▾ Sunlitnl-portal · nl.nl-portal:documenten-apivia GHSA
GHSA-hjwc-26pj-v3pmHigh
3mo ago

AgenticMail: Cross-agent task authorization bypass in AgenticMail API

AgenticMail: Cross-agent task authorization bypass in AgenticMail API

▾ Twilightagenticmail · @agenticmail/apivia GHSA
GHSA-fq4x-789w-jg5hHigh
3mo ago

AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator's Claude Code session (bridge-wake)

AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator's Claude Code session (bridge-wake)

▾ Twilightagenticmail · @agenticmail/corevia GHSA
GHSA-hxpf-9xvq-wph8Critical· 9.6
3mo ago

netlicensing-mcp: REST Path Traversal Bypasses Token Redaction

netlicensing-mcp: REST Path Traversal Bypasses Token Redaction

▾ Midnightnetlicensing-mcp · netlicensing-mcpvia GHSA
CVE-2026-11752Medium
3mo ago

Armeria: External Control of File Name or Path in xDS SDS DataSource

Armeria: External Control of File Name or Path in xDS SDS DataSource

▾ Sunlitlinecorp · com.linecorp.armeria:armeria-xdsEPSS 0.32%via GHSA
GHSA-gfj5-979r-92pwCritical
3mo ago

@acastellon/auth: Authentication bypass via spoofable headers in validateToken()

@acastellon/auth: Authentication bypass via spoofable headers in validateToken()

▾ Midnightacastellon · @acastellon/authvia GHSA
GHSA-qqf5-x7mj-v43pHigh· 8.4
3mo ago

budibase: Database Connector SQL Injections in PostgreSQL, MS SQL, and MySQL

budibase: Database Connector SQL Injections in PostgreSQL, MS SQL, and MySQL

▾ Twilightbudibase · budibasevia GHSA
GHSA-2jq4-q6vv-4cp3Critical· 9.6
3mo ago

Crawl4AI: Arbitrary file write (path traversal) in crawler downloads can lead to RCE

Crawl4AI: Arbitrary file write (path traversal) in crawler downloads can lead to RCE

▾ Midnightcrawl4ai · crawl4aivia GHSA
GHSA-r253-r9jw-qg44Critical· 10.0
3mo ago

Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args

Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args

▾ Midnightcrawl4ai · crawl4aivia GHSA
GHSA-wm69-2pc3-rmmfHigh· 8.6
3mo ago

Crawl4AI: Unauthenticated SSRF on the Docker server streaming crawl path (/crawl/stream)

Crawl4AI: Unauthenticated SSRF on the Docker server streaming crawl path (/crawl/stream)

▾ Twilightcrawl4ai · crawl4aivia GHSA
CVE-2026-53848Low· 4.3
3mo ago

OpenClaw: Exec allowlist could miss side effects from transparent command wrappers

OpenClaw: Exec allowlist could miss side effects from transparent command wrappers

▾ Sunlitopenclaw · openclawEPSS 0.31%via GHSA
CVE-2026-53859Medium· 6.5
3mo ago

OpenClaw: Hostname checks could treat trailing-dot hosts inconsistently

OpenClaw: Hostname checks could treat trailing-dot hosts inconsistently

▾ Sunlitopenclaw · openclawEPSS 0.36%via GHSA
CVE-2026-53855High· 8.1
3mo ago

OpenClaw: Shell positional parameters could weaken strict inline-eval checks

OpenClaw: Shell positional parameters could weaken strict inline-eval checks

▾ Twilightopenclaw · openclawEPSS 0.45%via GHSA
CVE-2026-53862Low· 4.2
3mo ago

OpenClaw: Bootstrap token replay could widen pending pairing scopes

OpenClaw: Bootstrap token replay could widen pending pairing scopes

▾ Sunlitopenclaw · openclawEPSS 0.13%via GHSA
CVE-2026-53851Medium· 5.3
3mo ago

OpenClaw: Slack reaction events could ignore reaction notification settings

OpenClaw: Slack reaction events could ignore reaction notification settings

▾ Sunlitopenclaw · openclawEPSS 0.32%via GHSA
CVE-2026-53841Medium· 6.1
3mo ago

OpenClaw: Exported session HTML could keep unsafe markdown links

OpenClaw: Exported session HTML could keep unsafe markdown links

▾ Sunlitopenclaw · openclawEPSS 0.27%via GHSA
CVE-2026-53847Medium
3mo ago

OpenClaw: Active Memory write scope could mutate global config

OpenClaw: Active Memory write scope could mutate global config

▾ Sunlitopenclaw · openclawEPSS 0.30%via GHSA
CVE-2026-53845Low· 4.3
3mo ago

OpenClaw: Skill-command dispatch could skip before-tool-call hooks

OpenClaw: Skill-command dispatch could skip before-tool-call hooks

▾ Sunlitopenclaw · openclawEPSS 0.31%via GHSA
CVE-2026-53857High· 8.1
3mo ago

OpenClaw: Zalo allowFrom could bind to mutable display names

OpenClaw: Zalo allowFrom could bind to mutable display names

▾ Twilightopenclaw · openclawEPSS 0.37%via GHSA
CVE-2026-53856Medium· 5.5
3mo ago

OpenClaw: Config recovery could restore openclaw.json with broad file permissions

OpenClaw: Config recovery could restore openclaw.json with broad file permissions

▾ Sunlitopenclaw · openclawEPSS 0.14%via GHSA
CVE-2026-53844Medium· 6.5
3mo ago

OpenClaw: memory-wiki shared search could miss session visibility checks

OpenClaw: memory-wiki shared search could miss session visibility checks

▾ Sunlitopenclaw · openclawEPSS 0.36%via GHSA
CVE-2026-53860Low· 4.2
3mo ago

OpenClaw: BlueBubbles sender policy could match mutable conversation identifiers

OpenClaw: BlueBubbles sender policy could match mutable conversation identifiers

▾ Sunlitopenclaw · openclawEPSS 0.23%via GHSA
CVE-2026-53853High· 7.1
3mo ago

OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns

OpenClaw: Linux and macOS exec allowlists skipped configured argument patterns

▾ Twilightopenclaw · openclawEPSS 0.60%via GHSA
CVE-2026-53846High· 7.1
3mo ago

OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency install

OpenClaw: Workspace .env npm_execpath could influence bundled runtime dependency install

▾ Twilightopenclaw · openclawEPSS 0.17%via GHSA
CVE-2026-53850Medium
3mo ago

OpenClaw: Focus command could miss controlScope enforcement

OpenClaw: Focus command could miss controlScope enforcement

▾ Sunlitopenclaw · openclawEPSS 0.14%via GHSA
CVE-2026-53858High· 7.1
3mo ago

OpenClaw: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots

OpenClaw: Workspace .env STATE_DIRECTORY could influence bundled runtime dependency roots

▾ Twilightopenclaw · openclawEPSS 0.18%via GHSA
CVEs tagged “ghsa” — page 113 · VulnSea