Tagged “ghsa”
CVEs tagged ghsa, newest first.
3812 CVEsRSS
CVE-2026-55629HighWhistle vulnerable to path traversal
Whistle vulnerable to path traversal
CVE-2026-55609High· 7.1sublinear-time-solver is a Rust and WebAssembly library for solving asymmetric diagonally dominant systems in sublinear time
sublinear-time-solver is a Rust and WebAssembly library for solving asymmetric diagonally dominant systems in sublinear time. Prior to consciousness-explorer 1.1.2 and sublinear-time-solver 1.6.0, the export_state and import_state tools …
CVE-2026-55604High· 8.6@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key
@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key
CVE-2026-55605Medium· 5.3@arikusi/deepseek-mcp-server: Missing Authentication on Self-Hosted HTTP MCP Endpoint
@arikusi/deepseek-mcp-server: Missing Authentication on Self-Hosted HTTP MCP Endpoint
CVE-2026-45018Critical· 9.8Chainlit is a Python framework for building production-ready conversational AI applications
Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint wi…
CVE-2026-45019High· 7.2Chainlit is a Python framework for building production-ready conversational AI applications
Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint wi…
CVE-2026-55099High· 7.5icalendar has Algorithmic Complexity in Equality
icalendar has Algorithmic Complexity in Equality
CVE-2026-54338Medium· 5.3JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login
CVE-2026-12210Medium· 4.7utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
GHSA-88g4-74f3-63x9Medium· 4.9phpMyFAQ has Potential Authenticated Path Traversal in PDF Export
phpMyFAQ has Potential Authenticated Path Traversal in PDF Export
GHSA-mf8r-wm2w-f8c5Medium· 5.3phpMyFAQ public FAQ APIs expose inactive FAQ content
phpMyFAQ public FAQ APIs expose inactive FAQ content
GHSA-pg62-f8g4-4wqhHigh· 8.8phpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold
phpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold
CVE-2026-55092High· 7.5Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts
Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts
CVE-2026-55419Medium· 5.3reachy_mini Allows Unrestricted Upload of File with Dangerous Type
reachy_mini Allows Unrestricted Upload of File with Dangerous Type
GHSA-vwf3-4xxj-qg6hHighmcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
CVE-2026-55637Highgenieacs-mcp is an MCP server for GenieACS written in Go
genieacs-mcp is an MCP server for GenieACS written in Go. Prior to 0.3.2, the Streamable HTTP transport in cmd/server/main.go creates an unauthenticated /mcp listener on the default MCP_LISTEN_ADDR value 127.0.0.1:8080 when MCP_AUTH_TOKE…
CVE-2026-53430HighgRPC Erlang package has unbounded gzip decompression (decompression bomb)
gRPC Erlang package has unbounded gzip decompression (decompression bomb)
CVE-2026-55663Medium· 5.6mediasoup is a WebRTC video conferencing system
mediasoup is a WebRTC video conferencing system. From version 3.20.0 until 3.20.6 for the npm package and from 0.22.0 until 0.22.5 for the Rust crate, mediasoup's built-in SCTP stack authenticates state cookies using only the hardcoded m…
CVE-2026-49757CriticalPoCAshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching
AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching
CVE-2026-55618Medium· 6.5eml_parser has a URL extraction bypass via HTML entities in URLs
eml_parser has a URL extraction bypass via HTML entities in URLs
CVE-2026-55619Medium· 5.3eml_parser has parser DoS via deeply nested parentheses in e-mail headers
eml_parser has parser DoS via deeply nested parentheses in e-mail headers
CVE-2026-55620High· 7.5eml_parser vulnerable to DoS via deeply nested parens in Received headers
eml_parser vulnerable to DoS via deeply nested parens in Received headers
CVE-2026-55557Highbrowse-mcp is a Playwright-based headless-browser MCP server for MCP-capable agents
browse-mcp is a Playwright-based headless-browser MCP server for MCP-capable agents. Prior to 0.8.2, browser_download writes a fetched response body to join(save_dir, filename) without validating the caller-controlled save_dir, while bro…
CVE-2026-55596High· 8.7Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript
Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript
CVE-2026-55582High· 8.4mcp-shell is an MCP server for running shell commands securely, auditably, and on demand
mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default security.yaml allows /usr/bin/git, while security.go omits ! from containsShellMetacharacters and containsDangerousShel…
CVE-2026-55581High· 8.4mcp-shell is an MCP server for running shell commands securely, auditably, and on demand
mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default Docker security.yaml includes /bin/bash in allowed_executables, while security.go validates only the first token and ch…
CVE-2026-55580Highmcp-shell is an MCP server for running shell commands securely, auditably, and on demand
mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, config.go initializes Security.Enabled to false, and when MCP_SHELL_SEC_CONFIG_FILE is unset, main.go starts the documented bare-bi…
GHSA-9qhg-99ww-9mqcHigh· 8.2utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target
utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target
GHSA-ppx3-28rw-8fpfMedium· 4.7utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins
GHSA-8cp3-qxj6-px34High· 7.1utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion
utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion