Tagged “ghsa”
CVEs tagged ghsa, newest first.
3886 CVEsRSS
CVE-2026-53849High· 8.1OpenClaw: Discord allowFrom could bind to mutable display names
OpenClaw: Discord allowFrom could bind to mutable display names
CVE-2026-53865High· 7.1OpenClaw: Workspace-derived service PATH could influence trash command selection
OpenClaw: Workspace-derived service PATH could influence trash command selection
CVE-2026-53852Low· 5.4OpenClaw: Empty-scope device re-pairing could confuse caller scope containment
OpenClaw: Empty-scope device re-pairing could confuse caller scope containment
CVE-2026-53854MediumOpenClaw: Internal/webchat command auth could inherit ownerAllowFrom wildcard state
OpenClaw: Internal/webchat command auth could inherit ownerAllowFrom wildcard state
CVE-2026-0755Critical· 9.80daygemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)
gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755)
GHSA-g7m4-839x-ch6vHighspomky-labs/otphp: Unbounded digits parameter in a provisioning URI triggers an uncaught DivisionByZeroError in OTP generation
spomky-labs/otphp: Unbounded digits parameter in a provisioning URI triggers an uncaught DivisionByZeroError in OTP generation
GHSA-2jx3-65f3-xr8rMediumspomky-labs/otphp: Mass-assignment in Factory::loadFromProvisioningUri lets a hostile provisioning URI corrupt OTP state or leak an uncaught TypeError
spomky-labs/otphp: Mass-assignment in Factory::loadFromProvisioningUri lets a hostile provisioning URI corrupt OTP state or leak an uncaught TypeError
GHSA-6vvh-pxr4-25r7MediumPHP JWT Framework: Chacha20Poly1305 key-encryption algorithm discards the Poly1305 authentication tag, performing no authentication on decryption
PHP JWT Framework: Chacha20Poly1305 key-encryption algorithm discards the Poly1305 authentication tag, performing no authentication on decryption
GHSA-3prj-6hqw-cm82HighPHP JWT Library: PBES2-HS*+A*KW unwrap accepts an unbounded p2c iteration count, enabling CPU-amplification denial of service
PHP JWT Library: PBES2-HS*+A*KW unwrap accepts an unbounded p2c iteration count, enabling CPU-amplification denial of service
GHSA-jc38-x7x8-2xc8HighPHP JWT Framework: JWSVerifier uses algorithm from unprotected header, enabling algorithm confusion attacks
PHP JWT Framework: JWSVerifier uses algorithm from unprotected header, enabling algorithm confusion attacks
GHSA-5739-39v2-5754MediumPHP JWT Library: RSA1_5 (RSAES-PKCS1-v1_5) decryption lacks implicit rejection, exposing a Bleichenbacher/Marvin padding oracle
PHP JWT Library: RSA1_5 (RSAES-PKCS1-v1_5) decryption lacks implicit rejection, exposing a Bleichenbacher/Marvin padding oracle
GHSA-5vg9-5847-vvmqHigh· 8.9Laravel Framework: CRLF injection in default email rule
Laravel Framework: CRLF injection in default email rule
GHSA-crmm-hgp2-wgrpMedium· 4.2Laravel Framework: Temporary Signed URL Path Confusion
Laravel Framework: Temporary Signed URL Path Confusion
CVE-2026-54327Low· 2.2Pi Agent: Race condition in Pi auth.json writes could expose stored credentials
Pi Agent: Race condition in Pi auth.json writes could expose stored credentials
CVE-2026-54328High· 7.3Pi Agent: Predictable temporary extension install paths allow local privilege escalation on shared Linux hosts
Pi Agent: Predictable temporary extension install paths allow local privilege escalation on shared Linux hosts
CVE-2026-54325Medium· 4.4Pi Agent: Pi loads project-local extensions without approval
Pi Agent: Pi loads project-local extensions without approval
GHSA-664h-gpgq-h6xxMedium· 5.4n8n: Wrong OAuth Scope on Evaluation Test Runs Endpoints
n8n: Wrong OAuth Scope on Evaluation Test Runs Endpoints
CVE-2026-53765Medium· 6.1Chrome DevTools for agents: daemon.pid write follows symlinks in /tmp fallback runtime directory
Chrome DevTools for agents: daemon.pid write follows symlinks in /tmp fallback runtime directory
CVE-2026-54761High· 7.1PoCTraefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services
Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services
CVE-2026-54235Medium· 6.5vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels
vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels
CVE-2026-12491Medium· 4.8vLLM: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations
vLLM: image EXIF Rotation & PNG tRNS Transparency Not Normalized, Causing Mismatch Between Model Input and Expectations
CVE-2026-53923High· 7.5vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving
vLLM: GGUF dequantize kernel int truncation exposes uninitialized GPU memory in multi-tenant serving
CVE-2026-54236Medium· 5.3PoCvLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router
vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router
CVE-2026-54233Medium· 6.5vLLM: OOM Denial of Service via Audio Decompression Bomb
vLLM: OOM Denial of Service via Audio Decompression Bomb
CVE-2026-53927MediumNocoDB: Server-Side Request Forgery via Spreadsheet Fetch URL
NocoDB: Server-Side Request Forgery via Spreadsheet Fetch URL
CVE-2026-53928MediumNocoDB: Refresh Tokens Persist Through Password Recovery
NocoDB: Refresh Tokens Persist Through Password Recovery
CVE-2026-53929MediumNocoDB: Stored Cross-Site Scripting via Secure Attachment
NocoDB: Stored Cross-Site Scripting via Secure Attachment
CVE-2026-53930MediumNocoDB: Server-Side Request Forgery via Base Migration URL
NocoDB: Server-Side Request Forgery via Base Migration URL
CVE-2026-53931MediumNocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint
NocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint
CVE-2026-54006Medium· 4.3Open WebUI IDOR: Calendar event re-parenting allows writing events into another user's calendar
Open WebUI IDOR: Calendar event re-parenting allows writing events into another user's calendar