VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3812 CVEsRSS

GHSA-8qx3-8gm5-9cj2High
1mo ago

pickem vulnerable to terminal escape-sequence injection via unsanitized item text

pickem vulnerable to terminal escape-sequence injection via unsanitized item text

▾ Twilightpickem · pickemvia GHSA
CVE-2026-55640Critical· 9.1
1mo ago

nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( d…

nextcloud-mcp-server: Unauthenticated `POST /webhooks/nextcloud` allows arbitrary vector data deletion when `WEBHOOK_SECRET` is unset ( default )

▾ Midnightnextcloud-mcp-server · nextcloud-mcp-serverEPSS 0.73%via OSV
CVE-2026-55571High· 8.2
1mo ago

djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticate…

djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls

▾ Twilightdjust · djustEPSS 0.51%via OSV
CVE-2026-55553High· 7.5
1mo ago

urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other request features

urllib is an HTTP client for Node.js that supports authentication, redirects, timeouts, and other request features. Prior to 4.9.1 and 2.44.1, urllib follows redirects through followRedirect but reuses caller-supplied options across orig…

▾ Twilighturllib · urllibEPSS 0.66%via NVD
CVE-2026-55585High· 8.8
1mo ago

qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`

qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`

▾ Twilightqwed · qwedEPSS 0.78%via OSV
CVE-2026-55529Medium· 6.9
1mo ago

PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on loc…

PraisonAI has an origin validation bypass in MCP HTTP Stream transport that allows browser-mediated unauthenticated tool execution on local MCP server

▾ Sunlitpraisonai · praisonaiEPSS 0.18%via OSV
CVE-2026-55528High· 8.2
1mo ago

praisonaiagents: AgentServer declares auth_token but never enforces it on any route

praisonaiagents: AgentServer declares auth_token but never enforces it on any route

▾ Twilightpraisonaiagents · praisonaiagentsEPSS 0.49%via OSV
CVE-2026-55531Medium· 6.5
1mo ago

PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)

PraisonAI MCP HTTP server has unauthenticated unbounded session accumulation (memory exhaustion; session TTL never enforced)

▾ Sunlitpraisonai · praisonaiEPSS 0.45%via OSV
CVE-2026-55526High· 8.5
1mo ago

praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)

praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)

▾ Twilightpraisonaiagents · praisonaiagentsEPSS 0.36%via OSV
CVE-2026-55534High· 8.6
1mo ago

PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution

PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution

▾ Twilightpraisonai · praisonaiEPSS 0.45%via OSV
CVE-2026-55530Medium· 6.1
1mo ago

praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool

praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool

▾ Sunlitpraisonaiagents · praisonaiagentsEPSS 0.17%via OSV
CVE-2026-55540High· 7.1
1mo ago

PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks

PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks

▾ Twilightpraisonai · praisonaiEPSS 0.39%via OSV
CVE-2026-55538High· 7.3
1mo ago

PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/…

PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated

▾ Twilightpraisonai · praisonaiEPSS 0.45%via OSV
CVE-2026-55537High· 7.1
1mo ago

PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114

PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114

▾ Twilightpraisonai · praisonaiEPSS 0.27%via OSV
CVE-2026-55535Medium· 6.8
1mo ago

PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation

PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation

▾ Sunlitpraisonai · praisonaiEPSS 0.34%via OSV
CVE-2026-55541High
1mo ago

PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced

PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced

▾ Twilightpraisonai · praisonaiEPSS 0.48%via OSV
CVE-2026-55527High· 7.1
1mo ago

praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable …

praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location

▾ Twilightpraisonaiagents · praisonaiagentsEPSS 0.48%via OSV
CVE-2026-55539High· 8.6
1mo ago

PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, c…

PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete

▾ Twilightpraisonai · praisonaiEPSS 0.57%via OSV
CVE-2026-55533High· 8.2
1mo ago

PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret

PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret

▾ Twilightpraisonai · praisonaiEPSS 0.49%via OSV
CVE-2026-55532High· 7.6
1mo ago

PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MC…

PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server

▾ Twilightpraisonai · praisonaiEPSS 0.20%via OSV
CVE-2026-55536Critical· 9.1
1mo ago

PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-v…

PraisonAI has a Browser Server WebSocket origin validation bypass via unanchored regex (patch bypass of CVE-2026-40289 / GHSA-8x8f-54wf-vv92)

▾ Midnightpraisonai · praisonaiEPSS 0.52%via OSV
CVE-2026-55546Critical· 9.8
1mo ago

qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input

qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input

▾ Midnightqwed-mcp · qwed-mcpEPSS 0.73%via OSV
CVE-2026-55525High· 7.5
1mo ago

praisonaiagents web_crawl vulnerable to SSRF via redirect-following

praisonaiagents web_crawl vulnerable to SSRF via redirect-following

▾ Twilightpraisonaiagents · praisonaiagentsEPSS 0.51%via OSV
CVE-2026-32637Medium
1mo ago

Velero is an open source tool for backing up, restoring, and migrating Kubernetes cluster resources and persistent volumes

Velero is an open source tool for backing up, restoring, and migrating Kubernetes cluster resources and persistent volumes. Prior to 1.18.1, an attacker who compromises the backup object-storage backend can upload a malicious backup tarb…

▾ Sunlitvmware-tanzu · github.com/vmware-tanzu/veleroEPSS 0.54%via NVD
CVE-2026-53965High
1mo ago

The MCP PHP SDK (Composer package mcp/sdk) is the official Model Context Protocol SDK for PHP

The MCP PHP SDK (Composer package mcp/sdk) is the official Model Context Protocol SDK for PHP. In versions 0.5.0 through 0.7.0, the HTTP client transport reads a Server-Sent Events response stream incrementally and appends each chunk to …

▾ Twilightmcp · mcp/sdkEPSS 0.61%via NVD
CVE-2026-76845Medium· 6.5
1mo ago

adm-zip 0.5.9 through 0.6.0 follows symbolic links at the extraction destination

adm-zip 0.5.9 through 0.6.0 follows symbolic links at the extraction destination. Utils.sanitize in util/utils.js enforces containment by comparing only the string form of an archive entry name against the resolved extraction root, and U…

▾ Sunlitadm-zip · adm-zipEPSS 0.17%via NVD
CVE-2026-77635CriticalPoC
1mo ago

CakePHP is a rapid development framework for PHP

CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective release lines, FunctionsBuilder::jsonValue() with PostgresDriver is vulnerable to SQL injection when user-controlled data i…

▾ Abyssalcakephp · cakephp/cakephpEPSS 0.49%via NVD
CVE-2026-77634High
1mo ago

CakePHP is a rapid development framework for PHP

CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their respective release lines, custom mail headers added with Message::setHeaders() or Message::addHeaders() do not have CRLF…

▾ Twilightcakephp · cakephp/cakephpEPSS 0.54%via NVD
CVE-2026-76098High· 7.5
1mo ago

Mistune is a Python Markdown parser with renderers and plugins

Mistune is a Python Markdown parser with renderers and plugins. Versions 3.3.0 through 3.3.2 are vulnerable to DoS through deeply nested tokens. HTML rendering creates deeply nested emphasis tokens from consecutive asterisk characters, a…

▾ Twilightmistune · mistuneEPSS 0.49%via NVD
CVE-2026-76172High· 7.5
1mo ago

fast-uri: fast-uri: URI parsing flaw enables server-side request forgery and redirects (CVE-2026-76172)

A flaw was found in fast-uri, a software component used for parsing Uniform Resource Identifiers (URIs) in Node.js applications. This vulnerability arises from an issue in how fast-uri processes the scheme part of a URI, specifically when …

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.40%via CSAF
CVEs tagged “ghsa” — page 33 · VulnSea