VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3812 CVEsRSS

CVE-2026-55629High
1mo ago

Whistle vulnerable to path traversal

Whistle vulnerable to path traversal

▾ Twilightwhistle · whistleEPSS 0.67%via GHSA
CVE-2026-55609High· 7.1
1mo ago

sublinear-time-solver is a Rust and WebAssembly library for solving asymmetric diagonally dominant systems in sublinear time

sublinear-time-solver is a Rust and WebAssembly library for solving asymmetric diagonally dominant systems in sublinear time. Prior to consciousness-explorer 1.1.2 and sublinear-time-solver 1.6.0, the export_state and import_state tools …

▾ Twilightconsciousness-explorer · consciousness-explorerEPSS 0.17%via NVD
CVE-2026-55604High· 8.6
1mo ago

@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key

@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key

▾ Twilightarikusi · @arikusi/deepseek-mcp-serverEPSS 0.37%via GHSA
CVE-2026-55605Medium· 5.3
1mo ago

@arikusi/deepseek-mcp-server: Missing Authentication on Self-Hosted HTTP MCP Endpoint

@arikusi/deepseek-mcp-server: Missing Authentication on Self-Hosted HTTP MCP Endpoint

▾ Sunlitarikusi · @arikusi/deepseek-mcp-serverEPSS 0.60%via GHSA
CVE-2026-45018Critical· 9.8
1mo ago

Chainlit is a Python framework for building production-ready conversational AI applications

Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint wi…

▾ Midnightchainlit · chainlitEPSS 1.1%via NVD
CVE-2026-45019High· 7.2
1mo ago

Chainlit is a Python framework for building production-ready conversational AI applications

Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint wi…

▾ Twilightchainlit · chainlitEPSS 0.43%via NVD
CVE-2026-55099High· 7.5
1mo ago

icalendar has Algorithmic Complexity in Equality

icalendar has Algorithmic Complexity in Equality

▾ Twilighticalendar · icalendarEPSS 0.63%via OSV
CVE-2026-54338Medium· 5.3
1mo ago

JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login

JupyterHub has Unauthenticated Denial of Service via Unbounded Username Logging on Failed Login

▾ Sunlitjupyterhub · jupyterhubEPSS 0.44%via OSV
CVE-2026-12210Medium· 4.7
1mo ago

utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins

utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins

▾ Sunlitutcp-gql · utcp-gqlEPSS 0.23%via OSV
GHSA-88g4-74f3-63x9Medium· 4.9
1mo ago

phpMyFAQ has Potential Authenticated Path Traversal in PDF Export

phpMyFAQ has Potential Authenticated Path Traversal in PDF Export

▾ Sunlitthorsten · thorsten/phpmyfaqvia GHSA
GHSA-mf8r-wm2w-f8c5Medium· 5.3
1mo ago

phpMyFAQ public FAQ APIs expose inactive FAQ content

phpMyFAQ public FAQ APIs expose inactive FAQ content

▾ Sunlitthorsten · thorsten/phpmyfaqvia GHSA
GHSA-pg62-f8g4-4wqhHigh· 8.8
1mo ago

phpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold

phpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold

▾ Twilightphpmyfaq · phpmyfaq/phpmyfaqvia GHSA
CVE-2026-55092High· 7.5
1mo ago

Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts

Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts

▾ Twilightaquasecurity · github.com/aquasecurity/trivyEPSS 0.44%via GHSA
CVE-2026-55419Medium· 5.3
1mo ago

reachy_mini Allows Unrestricted Upload of File with Dangerous Type

reachy_mini Allows Unrestricted Upload of File with Dangerous Type

▾ Sunlitreachy-mini · reachy-miniEPSS 0.48%via OSV
GHSA-vwf3-4xxj-qg6hHigh
1mo ago

mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment

mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment

▾ Twilightmcp-contextforge-gateway · mcp-contextforge-gatewayvia GHSA
CVE-2026-55637High
1mo ago

genieacs-mcp is an MCP server for GenieACS written in Go

genieacs-mcp is an MCP server for GenieACS written in Go. Prior to 0.3.2, the Streamable HTTP transport in cmd/server/main.go creates an unauthenticated /mcp listener on the default MCP_LISTEN_ADDR value 127.0.0.1:8080 when MCP_AUTH_TOKE…

▾ Twilightgeiserx · github.com/geiserx/genieacs-mcpEPSS 0.26%via NVD
CVE-2026-53430High
1mo ago

gRPC Erlang package has unbounded gzip decompression (decompression bomb)

gRPC Erlang package has unbounded gzip decompression (decompression bomb)

▾ Twilightgrpc · grpcEPSS 0.52%via GHSA
CVE-2026-55663Medium· 5.6
1mo ago

mediasoup is a WebRTC video conferencing system

mediasoup is a WebRTC video conferencing system. From version 3.20.0 until 3.20.6 for the npm package and from 0.22.0 until 0.22.5 for the Rust crate, mediasoup's built-in SCTP stack authenticates state cookies using only the hardcoded m…

▾ Sunlitmediasoup · mediasoupEPSS 0.19%via NVD
CVE-2026-49757CriticalPoC
1mo ago

AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching

AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching

▾ Abyssalash_authentication · ash_authenticationEPSS 0.68%via GHSA
CVE-2026-55618Medium· 6.5
1mo ago

eml_parser has a URL extraction bypass via HTML entities in URLs

eml_parser has a URL extraction bypass via HTML entities in URLs

▾ Sunliteml-parser · eml-parserEPSS 0.52%via OSV
CVE-2026-55619Medium· 5.3
1mo ago

eml_parser has parser DoS via deeply nested parentheses in e-mail headers

eml_parser has parser DoS via deeply nested parentheses in e-mail headers

▾ Sunliteml-parser · eml-parserEPSS 0.52%via OSV
CVE-2026-55620High· 7.5
1mo ago

eml_parser vulnerable to DoS via deeply nested parens in Received headers

eml_parser vulnerable to DoS via deeply nested parens in Received headers

▾ Twilighteml-parser · eml-parserEPSS 0.63%via OSV
CVE-2026-55557High
1mo ago

browse-mcp is a Playwright-based headless-browser MCP server for MCP-capable agents

browse-mcp is a Playwright-based headless-browser MCP server for MCP-capable agents. Prior to 0.8.2, browser_download writes a fetched response body to join(save_dir, filename) without validating the caller-controlled save_dir, while bro…

▾ Twilightbrowse-mcp · browse-mcpEPSS 0.24%via NVD
CVE-2026-55596High· 8.7
1mo ago

Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript

Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript

▾ Twilightplatejs · @platejs/mediaEPSS 0.43%via GHSA
CVE-2026-55582High· 8.4
1mo ago

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default security.yaml allows /usr/bin/git, while security.go omits ! from containsShellMetacharacters and containsDangerousShel…

▾ Twilightsonirico · github.com/sonirico/mcp-shellEPSS 0.27%via NVD
CVE-2026-55581High· 8.4
1mo ago

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default Docker security.yaml includes /bin/bash in allowed_executables, while security.go validates only the first token and ch…

▾ Twilightsonirico · github.com/sonirico/mcp-shellEPSS 0.45%via NVD
CVE-2026-55580High
1mo ago

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, config.go initializes Security.Enabled to false, and when MCP_SHELL_SEC_CONFIG_FILE is unset, main.go starts the documented bare-bi…

▾ Twilightsonirico · github.com/sonirico/mcp-shellEPSS 0.20%via NVD
GHSA-9qhg-99ww-9mqcHigh· 8.2
1mo ago

utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target

utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target

▾ Twilightutcp-http · utcp-httpvia GHSA
GHSA-ppx3-28rw-8fpfMedium· 4.7
1mo ago

utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins

utcp-gql SSRF: CVE-2026-44661 fix not applied to the GraphQL and WebSocket plugins

▾ Sunlitutcp-gql · utcp-gqlvia GHSA
GHSA-8cp3-qxj6-px34High· 7.1
1mo ago

utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion

utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion

▾ Twilightutcp-http · utcp-httpvia GHSA
CVEs tagged “ghsa” — page 32 · VulnSea