VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3812 CVEsRSS

CVE-2026-46369High· 7.5
1mo ago

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm

Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Through 1.5.0, the validity store uses a strict lower-bound comparison that expires a stored transaction too early relative t…

▾ Twilightnimiq-blockchain · nimiq-blockchainEPSS 0.55%via NVD
CVE-2026-48786Medium· 6.5
1mo ago

Fleet is an open-source device management platform built on osquery

Fleet is an open-source device management platform built on osquery. In versions prior to 4.87.0, the target search endpoint (POST /api/latest/fleet/targets) returned unmasked team enroll secrets and full team configuration, including cr…

▾ Sunlitfleetdm · github.com/fleetdm/fleet/v4EPSS 0.44%via NVD
CVE-2026-52776High
1mo ago

Compliance-trestle (Trestle) is a tooling platform for managing compliance as code

Compliance-trestle (Trestle) is a tooling platform for managing compliance as code. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the URLSecurityValidator that guards trestle's remote-fetch paths against server-side request…

▾ Twilightcompliance-trestle · compliance-trestleEPSS 0.44%via NVD
CVE-2026-32257High· 8.1
1mo ago

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings Styles field by a backend user with the backend.manage_branding permission …

▾ Twilightwinter · winter/wn-backend-moduleEPSS 0.38%via NVD
CVE-2026-32258High· 8.1
1mo ago

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom Markup Styles that are c…

▾ Twilightwinter · winter/wn-backend-moduleEPSS 0.38%via NVD
CVE-2026-32593Medium· 5.9
1mo ago

Winter CMS is a content management system built on the Laravel PHP framework

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, the backend Filter widget is vulnerable to SQL injection through the numberrange scope type when that scope is configur…

▾ Sunlitwinter · winter/wn-backend-moduleEPSS 0.27%via NVD
CVE-2026-46370Medium· 6.5
1mo ago

Fleet is an open-source device management platform built on osquery

Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels host-listing endpoint (GET /api/v1/fleet/labels/{id}/hosts) allowed an authenticated user with the lowest-privilege O…

▾ Sunlitfleetdm · github.com/fleetdm/fleet/v4EPSS 0.37%via NVD
CVE-2026-46371Medium· 6.5
1mo ago

Fleet is an open-source device management platform built on osquery

Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple MDM commands listing endpoint (GET /api/v1/fleet/mdm/apple/commands) allowed an authenticated user with the lowest-pri…

▾ Sunlitfleetdm · github.com/fleetdm/fleet/v4EPSS 0.37%via NVD
CVE-2026-41262Medium· 4.3
1mo ago

Fleet is an open-source device management platform built on osquery

Fleet is an open-source device management platform built on osquery. In versions prior to 4.85.0, the global policy read endpoint (GET /api/latest/fleet/policies/{policy_id}) fails to verify team ownership of the requested policy, allowi…

▾ Sunlitfleetdm · github.com/fleetdm/fleet/v4EPSS 0.30%via NVD
GHSA-896w-cw95-xq7wHigh· 8.1
1mo ago

Duplicate Advisory: Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion

Duplicate Advisory: Grav: Path Traversal in MediaUploadTrait::deleteFile() Allows Arbitrary File Deletion

▾ Twilightgetgrav · getgrav/gravvia GHSA
GHSA-qh7h-6c7g-x8m6Critical· 5.4
1mo ago

Duplicate Advisory: Grav: Origin validation bypass in Uri::referrer() and Pages::referrerRoute() via unanchored prefix match

Duplicate Advisory: Grav: Origin validation bypass in Uri::referrer() and Pages::referrerRoute() via unanchored prefix match

▾ Midnightgetgrav · getgrav/gravvia GHSA
GHSA-px9v-979x-qmh9Medium· 3.7
1mo ago

Duplicate Advisory: Grav: Non constant time nonce comparison in Utils::verifyNonce() used for CSRF protection

Duplicate Advisory: Grav: Non constant time nonce comparison in Utils::verifyNonce() used for CSRF protection

▾ Sunlitgetgrav · getgrav/gravvia GHSA
GHSA-rj4c-4q9x-543xHigh· 6.5
1mo ago

Duplicate Advisory: Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page content

Duplicate Advisory: Grav: media_directory() Twig function allows filesystem path traversal and file content disclosure from sandboxed page content

▾ Twilightgetgrav · getgrav/gravvia GHSA
GHSA-mw85-cjh9-8hp7High· 6.5
1mo ago

Duplicate Advisory: Grav: The system, site, and theme Twig variables bypass the content sandbox entirely and are never covered by config_denied_paths

Duplicate Advisory: Grav: The system, site, and theme Twig variables bypass the content sandbox entirely and are never covered by config_denied_paths

▾ Twilightgetgrav · getgrav/gravvia GHSA
GHSA-crrc-vpp2-f5x7High· 7.5
1mo ago

Duplicate Advisory: Grav: config_denied_paths default list omits `system`, exposing real secrets (e.g. system.cache.redis.password) via the Twig sandbox when config_access is enabled

Duplicate Advisory: Grav: config_denied_paths default list omits `system`, exposing real secrets (e.g. system.cache.redis.password) via the Twig sandbox when config_access is enabled

▾ Twilightgetgrav · getgrav/gravvia GHSA
GHSA-8vp7-8q4w-vv7mHigh· 6.5
1mo ago

Duplicate Advisory: Grav: UserInterface offsetget/offsetexists allow-listed in Twig sandbox let editor-authored content leak hashed_password and 2FA secrets via offsetGet()

Duplicate Advisory: Grav: UserInterface offsetget/offsetexists allow-listed in Twig sandbox let editor-authored content leak hashed_password and 2FA secrets via offsetGet()

▾ Twilightgetgrav · getgrav/gravvia GHSA
GHSA-6rj2-96f5-chj9High· 6.5
1mo ago

Duplicate Advisory: GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)

Duplicate Advisory: GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)

▾ TwilightGitPython · GitPythonvia GHSA
CVE-2026-78679Medium· 6.5
1mo ago

GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard

GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional reference parameter bypasses the unsafe option guard. Attackers can supply a reference value like --file=<path> to read arb…

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.26%via NVD
GHSA-crmc-f4m7-33fjHigh· 8.4
1mo ago

Duplicate Advisory: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)

Duplicate Advisory: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)

▾ Twilightgitpython · gitpythonvia GHSA
GHSA-9557-234j-7rv9Critical· 9.8
1mo ago

Duplicate Advisory: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE

Duplicate Advisory: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE

▾ MidnightGitPython · GitPythonvia GHSA
GHSA-89ff-m8wv-p99rHigh· 6.5
1mo ago

Duplicate Advisory: GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()

Duplicate Advisory: GitPython: Incomplete unsafe_git_revision_options denylist omits --contents/-S, enabling arbitrary file read via Repo.blame()

▾ Twilightgitpython · gitpythonvia GHSA
GHSA-7r39-6q8m-qw68High· 7.5
1mo ago

Duplicate Advisory: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination

Duplicate Advisory: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination

▾ Twilightgitpython · gitpythonvia GHSA
CVE-2026-78678Medium· 6.5
1mo ago

gitpython: GitPython: Arbitrary file read via Repo.blame() (CVE-2026-78678)

A flaw was found in GitPython. An incomplete denylist in the `unsafe_git_revision_options` guard omits `--contents` and `-S` options. This allows an attacker to read arbitrary files by passing these options to the `Repo.blame()` function. …

▾ SunlitRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.41%via CSAF
CVE-2026-78677High· 7.5
1mo ago

GitPython: GitPython: Arbitrary Code Execution via Path Traversal (CVE-2026-78677)

A flaw was found in GitPython. This vulnerability allows a remote attacker to create arbitrary Git directories outside the intended clone destination. By manipulating the `separate_git_dir` parameter during repository cloning, an attacker …

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.65%via CSAF
CVE-2026-78676Critical· 9.8
1mo ago

gitpython: GitPython before 3.1.59 Remote Code Execution via Config Injection (CVE-2026-78676)

GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives like core.hooksPath. Attackers can craft config files with embedded newlin…

▾ MidnightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.78%via CSAF
CVE-2026-79674High· 7.5
1mo ago

nltk: NLTK: Information disclosure via path traversal in corpus-reader constructors (CVE-2026-79674)

A flaw was found in NLTK. A path traversal vulnerability in corpus-reader constructors allows a remote attacker to bypass the intended data root sandbox. By supplying arbitrary corpus root paths to LinThesaurusCorpusReader and PanLexLiteCo…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.39%via CSAF
CVE-2026-78682High· 7.5
1mo ago

nltk: NLTK: Server-Side Request Forgery via HTTP Proxy Configuration (CVE-2026-78682)

A flaw was found in NLTK. When an HTTP proxy is configured, a server-side request forgery (SSRF) vulnerability exists in the `nltk.pathsec.urlopen` function. An attacker can exploit this by providing a seemingly valid public URL, which the…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.43%via CSAF
CVE-2026-79675High· 8.1
1mo ago

nltk: NLTK before 3.10.3 JVM Argument Injection via Per-Call Options (CVE-2026-79675)

A flaw was found in NLTK. When processing untrusted input for its `per-call options` parameter in the `java()` function, NLTK fails to validate Java Virtual Machine (JVM) options. A remote attacker could exploit this by injecting dangerous…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.78%via CSAF
CVE-2026-78680High· 7.8
1mo ago

NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot binary in dependencygraph.dot2img and AlignedSent._repr_svg_, allowing attackers to execute arbitrary code by placing a malicious dot binary …

NLTK versions before 3.10.3 fail to use validated absolute paths when invoking the Graphviz dot binary in dependencygraph.dot2img and AlignedSent._repr_svg_, allowing attackers to execute arbitrary code by placing a malicious dot binary …

▾ Twilightnltk · nltkEPSS 0.18%via NVD
CVE-2026-55588Medium· 6.5⚖ disputed
1mo ago

ORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in OCI registries

ORAS (OCI Registry As Storage) is a CLI and library for managing artifacts in OCI registries. In ORAS CLI versions up to and including 1.3.2, the recursive referrer traversal does not track visited descriptors, so a malicious OCI registr…

▾ Sunlitoras · oras.land/orasEPSS 0.54%via NVD
CVEs tagged “ghsa” — page 31 · VulnSea