VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3886 CVEsRSS

CVE-2026-53849High· 8.1
3mo ago

OpenClaw: Discord allowFrom could bind to mutable display names

OpenClaw: Discord allowFrom could bind to mutable display names

▾ Twilightopenclaw · openclawEPSS 0.37%via GHSA
CVE-2026-53865High· 7.1
3mo ago

OpenClaw: Workspace-derived service PATH could influence trash command selection

OpenClaw: Workspace-derived service PATH could influence trash command selection

▾ Twilightopenclaw · openclawEPSS 0.18%via GHSA
CVE-2026-53852Low· 5.4
3mo ago

OpenClaw: Empty-scope device re-pairing could confuse caller scope containment

OpenClaw: Empty-scope device re-pairing could confuse caller scope containment

▾ Sunlitopenclaw · openclawEPSS 0.28%via GHSA
CVE-2026-53854Medium
3mo ago

OpenClaw: Internal/webchat command auth could inherit ownerAllowFrom wildcard state

OpenClaw: Internal/webchat command auth could inherit ownerAllowFrom wildcard state

▾ Sunlitopenclaw · openclawEPSS 0.41%via GHSA
CVE-2026-0755Critical· 9.80day
3mo ago

gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)

gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)

▾ Hadalgemini-mcp-tool · gemini-mcp-toolEPSS 3.5%via GHSA
GHSA-g7m4-839x-ch6vHigh
3mo ago

spomky-labs/otphp: Unbounded digits parameter in a provisioning URI triggers an uncaught DivisionByZeroError in OTP generation

spomky-labs/otphp: Unbounded digits parameter in a provisioning URI triggers an uncaught DivisionByZeroError in OTP generation

▾ Twilightspomky-labs · spomky-labs/otphpvia GHSA
GHSA-2jx3-65f3-xr8rMedium
3mo ago

spomky-labs/otphp: Mass-assignment in Factory::loadFromProvisioningUri lets a hostile provisioning URI corrupt OTP state or leak an uncaught TypeError

spomky-labs/otphp: Mass-assignment in Factory::loadFromProvisioningUri lets a hostile provisioning URI corrupt OTP state or leak an uncaught TypeError

▾ Sunlitspomky-labs · spomky-labs/otphpvia GHSA
GHSA-6vvh-pxr4-25r7Medium
3mo ago

PHP JWT Framework: Chacha20Poly1305 key-encryption algorithm discards the Poly1305 authentication tag, performing no authentication on decryption

PHP JWT Framework: Chacha20Poly1305 key-encryption algorithm discards the Poly1305 authentication tag, performing no authentication on decryption

▾ Sunlitweb-token · web-token/jwt-experimentalvia GHSA
GHSA-3prj-6hqw-cm82High
3mo ago

PHP JWT Library: PBES2-HS*+A*KW unwrap accepts an unbounded p2c iteration count, enabling CPU-amplification denial of service

PHP JWT Library: PBES2-HS*+A*KW unwrap accepts an unbounded p2c iteration count, enabling CPU-amplification denial of service

▾ Twilightweb-token · web-token/jwt-libraryvia GHSA
GHSA-jc38-x7x8-2xc8High
3mo ago

PHP JWT Framework: JWSVerifier uses algorithm from unprotected header, enabling algorithm confusion attacks

PHP JWT Framework: JWSVerifier uses algorithm from unprotected header, enabling algorithm confusion attacks

▾ Twilightweb-token · web-token/jwt-frameworkvia GHSA
GHSA-5739-39v2-5754Medium
3mo ago

PHP JWT Library: RSA1_5 (RSAES-PKCS1-v1_5) decryption lacks implicit rejection, exposing a Bleichenbacher/Marvin padding oracle

PHP JWT Library: RSA1_5 (RSAES-PKCS1-v1_5) decryption lacks implicit rejection, exposing a Bleichenbacher/Marvin padding oracle

▾ Sunlitweb-token · web-token/jwt-libraryvia GHSA
GHSA-5vg9-5847-vvmqHigh· 8.9
3mo ago

Laravel Framework: CRLF injection in default email rule

Laravel Framework: CRLF injection in default email rule

▾ Twilightlaravel · laravel/frameworkvia GHSA
GHSA-crmm-hgp2-wgrpMedium· 4.2
3mo ago

Laravel Framework: Temporary Signed URL Path Confusion

Laravel Framework: Temporary Signed URL Path Confusion

▾ Sunlitlaravel · laravel/frameworkvia GHSA
CVE-2026-54327Low· 2.2
3mo ago

Pi Agent: Race condition in Pi auth.json writes could expose stored credentials

Pi Agent: Race condition in Pi auth.json writes could expose stored credentials

▾ Sunlitmariozechner · @mariozechner/pi-coding-agentEPSS 0.09%via GHSA
CVE-2026-54328High· 7.3
3mo ago

Pi Agent: Predictable temporary extension install paths allow local privilege escalation on shared Linux hosts

Pi Agent: Predictable temporary extension install paths allow local privilege escalation on shared Linux hosts

▾ Twilightearendil-works · @earendil-works/pi-coding-agentEPSS 0.16%via GHSA
CVE-2026-54325Medium· 4.4
3mo ago

Pi Agent: Pi loads project-local extensions without approval

Pi Agent: Pi loads project-local extensions without approval

▾ Sunlitearendil-works · @earendil-works/pi-coding-agentEPSS 0.17%via GHSA
GHSA-664h-gpgq-h6xxMedium· 5.4
3mo ago

n8n: Wrong OAuth Scope on Evaluation Test Runs Endpoints

n8n: Wrong OAuth Scope on Evaluation Test Runs Endpoints

▾ Sunlitn8n · n8nvia GHSA
CVE-2026-53765Medium· 6.1
3mo ago

Chrome DevTools for agents: daemon.pid write follows symlinks in /tmp fallback runtime directory

Chrome DevTools for agents: daemon.pid write follows symlinks in /tmp fallback runtime directory

▾ Sunlitchrome-devtools-mcp · chrome-devtools-mcpEPSS 0.10%via GHSA
CVE-2026-54761High· 7.1PoC
3mo ago

Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services

Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services

▾ Midnighttraefik · github.com/traefik/traefik/v3EPSS 0.37%via OSV
CVE-2026-54235Medium· 6.5
3mo ago

vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels

vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels

▾ Sunlitvllm · vllmEPSS 0.45%via OSV
CVE-2026-12491Medium· 4.8
3mo ago

vLLM: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations

vLLM: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations

▾ Sunlitvllm · vllmEPSS 0.24%via OSV
CVE-2026-53923High· 7.5
3mo ago

vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving

vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving

▾ Twilightvllm · vllmEPSS 0.48%via OSV
CVE-2026-54236Medium· 5.3PoC
3mo ago

vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router

vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router

▾ Twilightvllm · vllmEPSS 0.93%via OSV
CVE-2026-54233Medium· 6.5
3mo ago

vLLM: OOM Denial of Service via Audio Decompression Bomb

vLLM: OOM Denial of Service via Audio Decompression Bomb

▾ Sunlitvllm · vllmEPSS 0.42%via OSV
CVE-2026-53927Medium
3mo ago

NocoDB: Server-Side Request Forgery via Spreadsheet Fetch URL

NocoDB: Server-Side Request Forgery via Spreadsheet Fetch URL

▾ Sunlitnocodb · nocodbEPSS 0.39%via GHSA
CVE-2026-53928Medium
3mo ago

NocoDB: Refresh Tokens Persist Through Password Recovery

NocoDB: Refresh Tokens Persist Through Password Recovery

▾ Sunlitnocodb · nocodbEPSS 0.31%via GHSA
CVE-2026-53929Medium
3mo ago

NocoDB: Stored Cross-Site Scripting via Secure Attachment

NocoDB: Stored Cross-Site Scripting via Secure Attachment

▾ Sunlitnocodb · nocodbEPSS 0.40%via GHSA
CVE-2026-53930Medium
3mo ago

NocoDB: Server-Side Request Forgery via Base Migration URL

NocoDB: Server-Side Request Forgery via Base Migration URL

▾ Sunlitnocodb · nocodbEPSS 0.39%via GHSA
CVE-2026-53931Medium
3mo ago

NocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint

NocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint

▾ Sunlitnocodb · nocodbEPSS 0.41%via GHSA
CVE-2026-54006Medium· 4.3
3mo ago

Open WebUI IDOR: Calendar event re-parenting allows writing events into another user's calendar

Open WebUI IDOR: Calendar event re-parenting allows writing events into another user's calendar

▾ Sunlitopen-webui · open-webuiEPSS 0.30%via GHSA
CVEs tagged “ghsa” — page 114 · VulnSea