VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3812 CVEsRSS

CVE-2026-49464High· 8.1
2w ago

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations

NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:taak` package from version 1.5.0 through 3.0.0 fails to …

▾ Twilightnl-portal · nl-portal-backend-librariesEPSS 0.35%via NVD
CVE-2026-49439Medium· 4.3
2w ago

OpenRemote is an open-source internet-of-things platform

OpenRemote is an open-source internet-of-things platform. Prior to version 1.24.1, the predicted datapoint write endpoint allows users with only `read:assets` privileges to write predicted datapoints. Version 1.24.1 fixes the issue.

▾ Sunlitopenremote · openremoteEPSS 0.26%via NVD
CVE-2026-48496Medium· 6.2
2w ago

OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages

OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages. Starting in version 0.0.202527 and prior to version 0.0.202622, an unprivileged process can cause the profiler to o…

▾ Sunlitopen-telemetry · opentelemetry-ebpf-profilerEPSS 0.18%via NVD
GHSA-w47m-jpv2-qfw5Critical· 9.8
2w ago

Duplicate Advisory: Knowns Sandbox Escape: Unauthenticated Header Injection Grants AI Agent Unrestricted Access to Host Filesystem

Duplicate Advisory: Knowns Sandbox Escape: Unauthenticated Header Injection Grants AI Agent Unrestricted Access to Host Filesystem

▾ Midnightknowns · knownsvia GHSA
CVE-2026-84939Critical· 9.1
2w ago

Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by default …

Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by default …

▾ Midnightapache · freemarkerEPSS 0.85%via NVD
GHSA-wfgq-w7cq-qj7jHigh· 7.2
2w ago

mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url

mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url

▾ Twilightmistralrs-server-core · mistralrs-server-corevia GHSA
GHSA-m3wp-48jr-vr4gHigh· 7.5
2w ago

mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS

mistral.rs: Unbounded Remote Media Fetch and Video Frame Expansion DoS

▾ Twilightmistralrs-server-core · mistralrs-server-corevia GHSA
GHSA-x7m8-jrm8-hpvxHigh· 8.1
2w ago

@eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name

@eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name

▾ Twilighteigenpal · @eigenpal/docx-editor-corevia GHSA
CVE-2026-49836Medium· 4.6PoC
2w ago

psd-tools: arbitrary file write via smart-object filename

psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.17.1, `SmartObject.save()` writes an embedded smart object to a path taken verbatim from the PSD file. Because that name is attacker-controlled …

▾ Twilightpsd-tools · psd-toolsEPSS 0.19%via CVEORG
CVE-2026-49837Medium· 5.9
2w ago

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Versions prior to 4.6.0 contain a BGP OPEN capability parsing issue where several concrete capability decoders may parse data from the f…

▾ Sunlitosrg · gobgpEPSS 0.33%via NVD
CVE-2026-49838Medium· 5.9
2w ago

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.7.0, GoBGP accepts a zero-length AS_PATH during UPDATE decoding and later panics while validating that attribute for …

▾ Sunlitosrg · gobgpEPSS 0.41%via NVD
GHSA-hxjg-93wc-h8p8High· 8.8
2w ago

Komari: Management Interface CSRF

Komari: Management Interface CSRF

▾ Twilightkomari-monitor · github.com/komari-monitor/komarivia OSV
CVE-2026-59185High· 8.5
2w ago

Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification

Identrail Cross-tenant IDOR: Client-supplied GitHub App installation_id is bound to the caller's workspace without ownership verification

▾ Twilightidentrail · github.com/identrail/identrailvia OSV
CVE-2026-59179High· 8.3
2w ago

@openhop/server: Path Traversal in Flow ID File Operations

@openhop/server: Path Traversal in Flow ID File Operations

▾ Twilightopenhop · @openhop/servervia GHSA
CVE-2026-59176High· 7.8
2w ago

functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import

functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import

▾ Twilightfunctype-mcp-server · functype-mcp-servervia GHSA
CVE-2026-59172High· 7.8
2w ago

Joker linter executed project-local .jokerd/linter.* files during linting

Joker linter executed project-local .jokerd/linter.* files during linting

▾ Twilightcandid82 · github.com/candid82/jokervia OSV
CVE-2026-59158High· 7.5
2w ago

Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients

Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients

▾ Twilightnuxt-ollama · nuxt-ollamavia GHSA
CVE-2025-24979Medium· 5.5
2w ago

LF Edge eKuiper: SSRF in External Service

LF Edge eKuiper: SSRF in External Service

▾ Sunlitlf-edge · github.com/lf-edge/ekuiper/v2via OSV
CVE-2025-24978Low· 3.7
2w ago

LF Edge eKuiper: Self-XSS in External Service Creation

LF Edge eKuiper: Self-XSS in External Service Creation

▾ Sunlitlf-edge · github.com/lf-edge/ekuiper/v2via OSV
CVE-2025-58363Medium· 5.5
2w ago

LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint

LF Edge eKuiper: Arbitrary File and Directory Deletion via Path Traversal in Plugin Installation Endpoint

▾ Sunlitlf-edge · github.com/lf-edge/ekuiper/v2via OSV
CVE-2026-47156Critical· 9.3
2w ago

MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator

MantisBT is an open source bug tracker. Versions 2.28.3 and earlier contain a critical authentication bypass in the SOAP API's mci_check_login() function. Any user knowing any valid cookie_string can authenticate as any other user (knowi…

▾ Midnightmantisbt · mantisbtEPSS 0.69%via CVEORG
CVE-2026-53956Medium· 5.4
2w ago

Rattler vulnerable to package cache path traversal via conda package build string

Rattler is a library that provides common functionality used within the conda ecosystem. `rattler_cache` prior to version 0.9.0 and `py-rattler` prior to version 0.24.0 were vulnerable to package-cache path traversal when handling packag…

▾ Sunlitconda · rattler_cacheEPSS 0.33%via CVEORG
GHSA-qjrq-cvv4-3g9wHigh· 8.8
2w ago

Duplicate Advisory: Knowns Unrestricted Path Traversal leading to out-of-bounds arbitrary .md file read, write, and deletion in MCP Docs + Memory Tools

Duplicate Advisory: Knowns Unrestricted Path Traversal leading to out-of-bounds arbitrary .md file read, write, and deletion in MCP Docs + Memory Tools

▾ Twilightknowns · knownsvia GHSA
GHSA-mqvm-gmc4-6rv2High· 8.8
2w ago

Duplicate Advisory: Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability

Duplicate Advisory: Microsoft Security Advisory CVE-2026-69439 – .NET and Visual Studio Elevation of Privilege Vulnerability

▾ TwilightMicrosoft · Microsoft.DiaSymReader.Nativevia GHSA
GHSA-4qhr-qf46-fcrxHigh· 8.8
2w ago

Duplicate Advisory: Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability

Duplicate Advisory: Microsoft Security Advisory CVE-2026-71328 – .NET and Visual Studio Remote Code Execution Vulnerability

▾ TwilightMicrosoft · Microsoft.DiaSymReader.Nativevia GHSA
CVE-2026-86994Medium· 4.3
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the /rest/active-workflows endpoint returned every active workflow ID on the instance to any member regardless of sharing. Workflow activation, de…

▾ Sunlitn8n · n8nEPSS 0.34%via NVD
CVE-2026-86085Medium· 4.9
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /rest/roles/:slug/assignments and /rest/roles/:slug/assignments/:projectId/members endpoints checked only whether the caller could manage the role type. …

▾ Sunlitn8n · n8nEPSS 0.44%via NVD
CVE-2026-86084Medium· 5.5
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the public OIDC login and callback endpoints completed authentication even when OIDC was not the enabled active authentication method. An Enterpri…

▾ Sunlitn8n · n8nEPSS 0.46%via NVD
CVE-2026-86083High· 8.8
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the legacy expression engine generated source text by calling the mutable global JSON.stringify while printing synthetic string literals and inter…

▾ Twilightn8n · n8nEPSS 0.66%via NVD
CVE-2026-86082Medium· 6.5
2w ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the OpenAI Chat Model node enforced credential allowed-domain restrictions for normal calls but not for the model-search dropdown. A workflow edit…

▾ Sunlitn8n · n8nEPSS 0.41%via NVD
CVEs tagged “ghsa” — page 19 · VulnSea