Tagged “ghsa”
CVEs tagged ghsa, newest first.
3812 CVEsRSS
CVE-2026-49464High· 8.1NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations
NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:taak` package from version 1.5.0 through 3.0.0 fails to …
CVE-2026-49439Medium· 4.3OpenRemote is an open-source internet-of-things platform
OpenRemote is an open-source internet-of-things platform. Prior to version 1.24.1, the predicted datapoint write endpoint allows users with only `read:assets` privileges to write predicted datapoints. Version 1.24.1 fixes the issue.
CVE-2026-48496Medium· 6.2OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages
OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages. Starting in version 0.0.202527 and prior to version 0.0.202622, an unprivileged process can cause the profiler to o…
GHSA-w47m-jpv2-qfw5Critical· 9.8Duplicate Advisory: Knowns Sandbox Escape: Unauthenticated Header Injection Grants AI Agent Unrestricted Access to Host Filesystem
Duplicate Advisory: Knowns Sandbox Escape: Unauthenticated Header Injection Grants AI Agent Unrestricted Access to Host Filesystem
CVE-2026-84939Critical· 9.1Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by default …
Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by default …
GHSA-wfgq-w7cq-qj7jHigh· 7.2mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url
mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url
GHSA-m3wp-48jr-vr4gHigh· 7.5mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS
mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS
GHSA-x7m8-jrm8-hpvxHigh· 8.1@eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name
@eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name
CVE-2026-49836Medium· 4.6PoCpsd-tools: arbitrary file write via smart-object filename
psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.17.1, `SmartObject.save()` writes an embedded smart object to a path taken verbatim from the PSD file. Because that name is attacker-controlled …
CVE-2026-49837Medium· 5.9GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Versions prior to 4.6.0 contain a BGP OPEN capability parsing issue where several concrete capability decoders may parse data from the f…
CVE-2026-49838Medium· 5.9GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language
GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.7.0, GoBGP accepts a zero-length AS_PATH during UPDATE decoding and later panics while validating that attribute for …
GHSA-hxjg-93wc-h8p8High· 8.8Komari: Management Interface CSRF
Komari: Management Interface CSRF
CVE-2026-59185High· 8.5Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification
Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification
CVE-2026-59179High· 8.3@openhop/server: Path Traversal in Flow ID File Operations
@openhop/server: Path Traversal in Flow ID File Operations
CVE-2026-59176High· 7.8functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import
functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import
CVE-2026-59172High· 7.8Joker linter executed project-local .jokerd/linter.* files during linting
Joker linter executed project-local .jokerd/linter.* files during linting
CVE-2026-59158High· 7.5Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients
Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients
CVE-2025-24979Medium· 5.5LF Edge eKuiper: SSRF in External Service
LF Edge eKuiper: SSRF in External Service
CVE-2025-24978Low· 3.7LF Edge eKuiper: Self-XSS in External Service Creation
LF Edge eKuiper: Self-XSS in External Service Creation
CVE-2025-58363Medium· 5.5LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint
CVE-2026-47156Critical· 9.3MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator
MantisBT is an open source bug tracker. Versions 2.28.3 and earlier contain a critical authentication bypass in the SOAP API's mci_check_login() function. Any user knowing any valid cookie_string can authenticate as any other user (knowi…
CVE-2026-53956Medium· 5.4Rattler vulnerable to package cache path traversal via conda package build string
Rattler is a library that provides common functionality used within the conda ecosystem. `rattler_cache` prior to version 0.9.0 and `py-rattler` prior to version 0.24.0 were vulnerable to package-cache path traversal when handling packag…
GHSA-qjrq-cvv4-3g9wHigh· 8.8Duplicate Advisory: Knowns Unrestricted Path Traversal leading to out-of-bounds arbitrary .md file read, write, and deletion in MCP Docs + Memory Tools
Duplicate Advisory: Knowns Unrestricted Path Traversal leading to out-of-bounds arbitrary .md file read, write, and deletion in MCP Docs + Memory Tools
GHSA-mqvm-gmc4-6rv2High· 8.8Duplicate Advisory: Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability
Duplicate Advisory: Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability
GHSA-4qhr-qf46-fcrxHigh· 8.8Duplicate Advisory: Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability
Duplicate Advisory: Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability
CVE-2026-86994Medium· 4.3n8n is an open source workflow automation platform
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the /rest/active-workflows endpoint returned every active workflow ID on the instance to any member regardless of sharing. Workflow activation, de…
CVE-2026-86085Medium· 4.9n8n is an open source workflow automation platform
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /rest/roles/:slug/assignments and /rest/roles/:slug/assignments/:projectId/members endpoints checked only whether the caller could manage the role type. …
CVE-2026-86084Medium· 5.5n8n is an open source workflow automation platform
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the public OIDC login and callback endpoints completed authentication even when OIDC was not the enabled active authentication method. An Enterpri…
CVE-2026-86083High· 8.8n8n is an open source workflow automation platform
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the legacy expression engine generated source text by calling the mutable global JSON.stringify while printing synthetic string literals and inter…
CVE-2026-86082Medium· 6.5n8n is an open source workflow automation platform
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the OpenAI Chat Model node enforced credential allowed-domain restrictions for normal calls but not for the model-search dropdown. A workflow edit…