VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3812 CVEsRSS

CVE-2026-68586High· 8.6
3w ago

SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-f…

SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.41%via OSV
CVE-2026-68585Medium· 5.8
3w ago

SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered

SiYuan: Cross-boundary metadata disclosure via getBlockInfo (publish mode): reader-reachable document title/root info for publish-forbidden docs; sibling getDocInfo is filtered

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.33%via GHSA
GHSA-7j72-f6wg-cxw6High· 8.6
3w ago

SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)

SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelvia GHSA
CVE-2026-69084Critical· 10.0PoC
3w ago

SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write

SiYuan: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write

▾ Abyssalsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 1.6%via GHSA
CVE-2026-71429Medium· 6.2
3w ago

stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint

stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.5.0, the path filters pick, ignore, filter, and replace in src/core/filters/filter-base.js recompute the full p…

▾ Sunlitstream-json · stream-jsonEPSS 0.16%via NVD
CVE-2026-69086High· 7.7
3w ago

SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclo…

SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.53%via OSV
CVE-2026-63376High· 8.2⚖ disputed
3w ago

toml-node is a TOML parser for Node.js and the browser

toml-node is a TOML parser for Node.js and the browser. Prior to 4.1.2, toml.parse() in lib/compiler.js can be tricked by a table path such as a.b.y.__proto__.__proto__, allowing traversal from a scalar value into Number.prototype and Ob…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.68%via NVD
CVE-2026-77465High· 7.5⚖ disputed
3w ago

toml-node is a TOML parser for Node.js and the browser

toml-node is a TOML parser for Node.js and the browser. Prior to 4.2.0, toml.parse() uses a Peggy 5.1.0 generated recursive-descent parser in lib/parser.js whose peg$parsevalue, peg$parsearray, and peg$parseinline_table_entry functions r…

▾ TwilightRed Hat · Red Hat Enterprise Linux 10EPSS 0.61%via NVD
CVE-2026-69083Critical· 10.0PoC
3w ago

SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB

SiYuan: Unauthenticated SQL execution and REGEXP injection via fullTextSearchAssetContent (publish mode): reader-reachable raw SQL (method 2) and unescaped REGEXP (method 3) on read-write asset-content DB

▾ Abyssalsiyuan-note · github.com/siyuan-note/siyuan/kernelEPSS 0.47%via GHSA
CVE-2026-56743Medium· 5.4
3w ago

Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match

Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match

▾ Sunlitcilium · github.com/cilium/ciliumEPSS 0.25%via GHSA
GHSA-2q7j-2vhx-56g8High· 8.1
3w ago

OpenClaw Feishu tools could ignore per-account disablement

OpenClaw Feishu tools could ignore per-account disablement

▾ Twilightopenclaw · @openclaw/feishuvia GHSA
GHSA-w8wf-3qvj-6xqfHigh· 8.1
3w ago

OpenClaw Feishu permission tools could ignore per-account disablement

OpenClaw Feishu permission tools could ignore per-account disablement

▾ Twilightopenclaw · @openclaw/feishuvia GHSA
CVE-2026-75602Medium· 6.5
3w ago

OpenList a file list program that supports multiple storage

OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST /api/fs/add_offline_download with tool: "SimpleHttp" accepts an attacker-supplied URL and saves its bytes under a pe…

▾ SunlitOpenListTeam · github.com/OpenListTeam/OpenListEPSS 0.69%via NVD
GHSA-99rq-75j6-5j9fHigh· 8.7
3w ago

SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass

SiYuan: Stored and reflected XSS in SiYuan through an SVG sanitizer bypass

▾ Twilightsiyuan-note · github.com/siyuan-note/siyuan/kernelvia GHSA
GHSA-gw25-m53r-qh88Medium· 6.5
3w ago

SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)

SiYuan: path traversal via /export/temp/ short-circuit branch (incomplete fix for the export-disclosure hardening, GHSA-6865-qjcf-286f)

▾ Sunlitsiyuan-note · github.com/siyuan-note/siyuan/kernelvia GHSA
CVE-2026-53728High· 7.1PoC
3w ago

Medplum is a developer platform that enables development of healthcare apps

Medplum is a developer platform that enables development of healthcare apps. Prior to version 5.1.6, the external identity provider callback at GET /auth/external accepts attacker-controlled redirect URIs that only need to start with a r…

▾ Midnightmedplum · medplumEPSS 0.20%via NVD
CVE-2026-50554Medium· 5.3
3w ago

Note Mark is an open-source note-taking application

Note Mark is an open-source note-taking application. Prior to version 0.19.5, GET /api/books/{bookID}/notes is an unauthenticated endpoint that accepts a "deleted" query parameter. When the request is ?deleted=true, the service runs the …

▾ Sunlitenchant97 · github.com/enchant97/note-mark/backendEPSS 0.42%via NVD
CVE-2026-53720Medium
3w ago

pymonocypher uses cython to wrap the Monocypher C library

pymonocypher uses cython to wrap the Monocypher C library. Prior to version 4.0.2.8, the argon2i_32 implementation does not check the nb_blocks size. If the caller does not provide a sufficiently large buffer based on the API contract, t…

▾ Sunlitpymonocypher · pymonocypherEPSS 0.18%via NVD
CVE-2026-49455Medium· 6.5
3w ago

Waku is the minimal React framework

Waku is the minimal React framework. Prior to version 1.0.0-beta.1, Waku's RSC request dispatcher invokes server actions without validating the request's Origin (or Sec-Fetch-Site) header. A cross-origin web attacker can therefore cause …

▾ Sunlitwaku · wakuEPSS 0.17%via NVD
CVE-2026-49456Low· 3.1
3w ago

Waku is the minimal React framework

Waku is the minimal React framework. Prior to version 1.0.0-beta.1, the unstable_redirect() helper exported from waku/router/server (packages/waku/src/router/define-router.tsx:156–161) accepts an arbitrary string and reflects it unchange…

▾ Sunlitwaku · wakuEPSS 0.40%via NVD
CVE-2026-84452High
3w ago

Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML

Windows ML CLI is a command line tool for building portable, performant, and high-quality AI models for Windows ML. Prior to 0.4.0, the src/winml/modelkit/serve/cli_api.py component exposes WinML CLI commands through a localhost HTTP API…

▾ Twilightwinml-cli · winml-cliEPSS 1.6%via NVD
CVE-2026-84376Medium
3w ago

Astro is a web framework for content-driven websites

Astro is a web framework for content-driven websites. Prior to 7.2.4, Astro stripped a configured non-root base path from request pathnames using a string-prefix check without verifying a path-segment boundary. With base "/app", a reques…

▾ Sunlitastro · astroEPSS 0.71%via NVD
CVE-2026-84382High· 7.5
3w ago

HTTPX2 is a next generation HTTP client for Python

HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, the HTTPX2 content decoders in src/httpx2/httpx2/_decoders.py fully inflate each gzip, deflate, br, or zstd network chunk before iter_bytes() or aiter_bytes() yields bo…

▾ Twilighthttpx2 · httpx2EPSS 0.63%via NVD
CVE-2026-84380Medium· 5.6
3w ago

HTTPX2 is a next generation HTTP client for Python

HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, Request._prepare() in src/httpx2/httpx2/_models.py can add a body-derived Content-Length header to a request that already contains a caller-supplied Transfer-Encoding h…

▾ Sunlithttpx2 · httpx2EPSS 0.36%via NVD
CVE-2026-84379Medium· 5.3
3w ago

HTTPX2 is a next generation HTTP client for Python

HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, FileField.render_headers() in src/httpx2/httpx2/_multipart.py directly interpolates attacker-controlled content_type values and custom headers from the files= three-ele…

▾ Sunlithttpx2 · httpx2EPSS 0.45%via NVD
CVE-2026-84378Medium· 5.9
3w ago

HTTPX2 is a next generation HTTP client for Python

HTTPX2 is a next generation HTTP client for Python. From 2.5.0 until 2.10.0, the HTTPX2 Server-Sent Events parser in src/httpx2/httpx2/_sse.py repeatedly copies and rescans buffered text in _SSELineDecoder.decode() when an attacker-contr…

▾ Sunlithttpx2 · httpx2EPSS 0.53%via NVD
CVE-2026-84381High· 8.1
3w ago

HTTPX2 is a next generation HTTP client for Python

HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore2/_async/socks_proxy.py when the remote origin uses wss through a…

▾ Twilighthttpcore2 · httpcore2EPSS 0.11%via NVD
CVE-2026-82404High· 8.3
3w ago

TOON is a compact, human-readable serialization of JSON data for LLM prompts

TOON is a compact, human-readable serialization of JSON data for LLM prompts. Prior to 2.3.1, decoding attacker-controlled TOON with a __proto__, constructor, or prototype key wrote through the object prototype chain instead of creating …

▾ Twilighttoon-format · @toon-format/toonEPSS 0.68%via NVD
CVE-2026-71553High
3w ago

ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS

ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS

▾ Twilightapostrophe · apostropheEPSS 0.43%via GHSA
CVE-2026-18504Medium· 5.4PoC
3w ago

fastify vulnerable to schema validation bypass via root primitive coercion mismatch

fastify vulnerable to schema validation bypass via root primitive coercion mismatch

▾ Twilightfastify · fastifyEPSS 0.31%via GHSA
CVEs tagged “ghsa” — page 23 · VulnSea