VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3812 CVEsRSS

CVE-2026-72795High· 8.6
3w ago

SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers

SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.41%via GHSA
CVE-2026-72792Medium· 5.8
3w ago

SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password

SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.33%via GHSA
CVE-2026-63735High· 8.1
3w ago

SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path

SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path

▾ Twilightsurrealdb · surrealdbEPSS 0.37%via GHSA
GHSA-6hxq-p678-4hr2Low
3w ago

SimpleWebAuthn: Registration verification does not sufficiently ensure that attestation certificates chain to a trust anchor

SimpleWebAuthn: Registration verification does not sufficiently ensure that attestation certificates chain to a trust anchor

▾ Sunlitsimplewebauthn · @simplewebauthn/servervia GHSA
CVE-2026-53604High· 7.1
3w ago

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, the web handler renderMobileBundle passes the real *pki.CAResolver directly into mobilebundle.Build. Inside Build, resolver.LoadByID decrypts t…

▾ Twilightforgekeep · nebula-meshEPSS 0.18%via NVD
CVE-2026-53603High· 7.1
3w ago

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.8, Operator session tokens are stored in plaintext in the operator_sessions table (the token column is the PRIMARY KEY). The session token is a 32…

▾ Twilightforgekeep · nebula-meshEPSS 0.35%via NVD
CVE-2026-55512Medium· 5.3PoC
3w ago

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.2.0 to before version 0.5.0, when OIDC is enabled, GET /ui/oidc/login is reachable without authentication and is registered outside the Web UI rate-limi…

▾ Twilightforgekeep · nebula-meshEPSS 0.60%via NVD
CVE-2026-55513Medium· 5.4PoC
3w ago

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.3.0 to before version 0.5.0, the nebula-mgmt Web UI host-creation path ignores both the server-wide enrollment_token_ttl security setting and per-networ…

▾ Twilightforgekeep · nebula-meshEPSS 0.32%via NVD
CVE-2026-61699High· 8.1PoC
3w ago

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.7.1, revocation is the only in-band mechanism that isolates a compromised/offboarded host from a Nebula mesh. Because the blocklist never reaches an…

▾ Midnightforgekeep · nebula-meshEPSS 0.45%via NVD
CVE-2026-53602Medium
3w ago

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.7, two related authorization gaps let a host that should no longer be trusted obtain a fresh, valid Nebula certificate, because nebula-mgmt does n…

▾ Sunlitforgekeep · github.com/forgekeep/nebula-meshEPSS 0.31%via NVD
CVE-2026-53932High· 8.0
3w ago

laravel-backup-restore restores database backups made with spatie/laravel-backup

laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1.9.4, a crafted backup archive can trigger OS command injection during database restore. This issue has been patched in version 1.9.4.

▾ Twilightstefanzweifel · laravel-backup-restoreEPSS 1.7%via NVD
CVE-2026-53769Medium· 6.5PoC
3w ago

Avo is a framework to create admin panels for Ruby on Rails apps

Avo is a framework to create admin panels for Ruby on Rails apps. From version 2.28.0 to before version 3.32.0, Avo's direct attachment upload endpoint lacks server-side upload authorization and bypasses the documented field-level upload…

▾ Twilightavo-hq · avoEPSS 0.42%via NVD
CVE-2026-50553High
3w ago

Note Mark is an open-source note-taking application

Note Mark is an open-source note-taking application. Prior to version 0.19.5, Note Mark validates book and note slug values with the OpenAPI/huma tag pattern:"[a-z0-9-]+". huma compiles this with regexp.MustCompile(s.Pattern) and tests i…

▾ Twilightenchant97 · github.com/enchant97/note-mark/backendEPSS 0.46%via NVD
CVE-2026-53760Medium· 5.2PoC
3w ago

Admidio is an open-source user management solution

Admidio is an open-source user management solution. In versions 5.0.11 and prior, the modules/plugins.php endpoint handles plugin installation, uninstallation, and update operations via GET requests without CSRF token validation. Because…

▾ TwilightAdmidio · admidioEPSS 0.17%via NVD
CVE-2026-85396High· 7.5
3w ago

rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators

rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with nam…

▾ Twilightrubyzip · rubyzipEPSS 0.56%via NVD
CVE-2026-85062Medium· 6.9
3w ago

Colord is a tiny yet powerful tool for high-performance color manipulations and conversions

Colord is a tiny yet powerful tool for high-performance color manipulations and conversions. Prior to 2.9.4, synchronous CSS color string matchers in src/colorModels/rgbString.ts, src/colorModels/hslString.ts, src/colorModels/hwbString.t…

▾ Sunlitomgovich · colordEPSS 0.51%via NVD
CVE-2026-85061Critical· 10.0
3w ago

MapLibre GL JS is an interactive vector tile map library for web browsers

MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap while removeAttributes() removes attributes from the same collec…

▾ Midnightmaplibre-gl · maplibre-glEPSS 0.52%via NVD
CVE-2026-85063Medium· 6.5
3w ago

node-csv is a full-featured CSV parser with a simple API that is tested against large datasets

node-csv is a full-featured CSV parser with a simple API that is tested against large datasets. Prior to 7.0.2, csv-parse with the columns and group_columns_by_name options enabled treats a duplicate __proto__ header as an existing prope…

▾ Sunlitcsv-parse · csv-parseEPSS 0.57%via NVD
CVE-2026-68584High· 8.6
3w ago

SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)

SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.53%via OSV
CVE-2026-72812Medium· 6.5
3w ago

SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode)

SiYuan: Missing authorization on refreshBacklink allows anonymous readers to trigger persistent server-side writes and unauthenticated resource amplification (publish mode)

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.38%via GHSA
CVE-2026-72811Critical· 10.0
3w ago

SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle

SiYuan: SQL injection in backlink/mention search via unescaped stored and client input (publish mode): first-order (client keyword) and second-order (stored document title) breakout on read-write handle

▾ Midnightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.44%via GHSA
CVE-2026-72810High· 8.6
3w ago

SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)

SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.54%via GHSA
CVE-2026-72808Medium· 5.8
3w ago

SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode)

SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode)

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.40%via GHSA
CVE-2026-72807High· 8.0
3w ago

SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel

SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.33%via GHSA
CVE-2026-72806Medium· 5.8
3w ago

SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents with…

SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode)

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.43%via OSV
CVE-2026-72804High· 8.6
3w ago

SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents

SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.43%via GHSA
CVE-2026-72803Medium· 5.8
3w ago

SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents

SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.33%via GHSA
CVE-2026-72802Medium· 5.3
3w ago

SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath

SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.33%via GHSA
CVE-2026-72800Medium· 5.8
3w ago

SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeratio…

SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode)

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.33%via OSV
CVE-2026-68587High· 8.6
3w ago

SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rende…

SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.42%via OSV
CVEs tagged “ghsa” — page 22 · VulnSea