VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3816 CVEsRSS

GHSA-q9c5-pp7m-fm2gMedium· 5.3
1mo ago

Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs

Fleet: Unauthenticated download of in-house iOS app binaries via predictable URLs

▾ Sunlitfleetdm · github.com/fleetdm/fleet/v4via GHSA
GHSA-rxhg-vcww-2mpwLow· 3.1
1mo ago

Fleet: ORDER BY column injection on activity list endpoints

Fleet: ORDER BY column injection on activity list endpoints

▾ Sunlitfleetdm · github.com/fleetdm/fleet/v4via GHSA
GHSA-7mpf-4465-7fc2Low· 2.0
1mo ago

Winter: Stored XSS through Backend List widget image columns

Winter: Stored XSS through Backend List widget image columns

▾ Sunlitwinter · winter/wn-backend-modulevia GHSA
GHSA-mpmw-f6h6-3g26Medium· 4.3
1mo ago

Winter: My Account preview exposes another backend user's profile by record ID

Winter: My Account preview exposes another backend user's profile by record ID

▾ Sunlitwinter · winter/wn-backend-modulevia GHSA
GHSA-fm29-4mq3-phg6Medium· 5.3
1mo ago

Winter: ImportExportController AJAX handlers bypass granular import/export permission gate

Winter: ImportExportController AJAX handlers bypass granular import/export permission gate

▾ Sunlitwinter · winter/wn-backend-modulevia GHSA
GHSA-5cwr-5jxg-pcf6Medium· 4.5
1mo ago

Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles

Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles

▾ Sunlitwinter · winter/wn-backend-modulevia GHSA
GHSA-p2ch-c2c3-4xm5Medium· 6.1
1mo ago

Winter: CSRF through AJAX handler names reachable as backend page actions

Winter: CSRF through AJAX handler names reachable as backend page actions

▾ Sunlitwinter · winter/wn-backend-modulevia GHSA
GHSA-hq84-x37p-j6q5Medium· 4.5
1mo ago

Winter: Reflected XSS through the search query parameter in the backend Table widget

Winter: Reflected XSS through the search query parameter in the backend Table widget

▾ Sunlitwinter · winter/wn-backend-modulevia GHSA
GHSA-92hv-j533-69wcLow· 3.7
1mo ago

Wagtail: Identification of documents by SHA1 hash

Wagtail: Identification of documents by SHA1 hash

▾ Sunlitwagtail · wagtailvia GHSA
GHSA-c2xx-cjmh-9q8fMedium· 5.3
1mo ago

Wagtail: Improper restriction handling on descendant collections in Documents and Images API

Wagtail: Improper restriction handling on descendant collections in Documents and Images API

▾ Sunlitwagtail · wagtailvia GHSA
GHSA-x5cx-w6p2-mxf2Medium· 6.5
1mo ago

Wagtail: Improper permission handling when copying snippets

Wagtail: Improper permission handling when copying snippets

▾ Sunlitwagtail · wagtailvia GHSA
GHSA-jm5p-837g-rv8gMedium· 6.5
1mo ago

Wagtail: Improper restriction handling on Page translation API endpoint

Wagtail: Improper restriction handling on Page translation API endpoint

▾ Sunlitwagtail · wagtailvia GHSA
GHSA-9w56-46f6-3qhxMedium· 5.5
1mo ago

asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter

asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter

▾ Sunlitasteval · astevalvia OSV
CVE-2026-54061Critical· 9.1
1mo ago

Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import

Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import

▾ Midnightdgraph-io · github.com/dgraph-io/dgraph/v25EPSS 0.58%via GHSA
CVE-2026-40345HighPoC
1mo ago

deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects

deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. Prior to 8.0.0, the deepmerge, deepmergeCustom, deepmergeInto, and deepmergeIntoCustom APIs do not track visited objects or object pairs …

▾ Midnightdeepmerge-ts · deepmerge-tsEPSS 0.52%via NVD
CVE-2026-54449High· 8.8
1mo ago

LangBot is a global IM bot platform designed for LLMs

LangBot is a global IM bot platform designed for LLMs. In version 4.10.7 and earlier, any authenticated user can add or change an STDIO MCP server configuration without an adequate authorization boundary. In src/langbot/pkg/provider/tool…

▾ Twilightlangbot · langbotEPSS 0.72%via NVD
CVE-2026-54136Medium
1mo ago

Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs

Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to 1.715.0, a resource-scoped API token could read script contents outside its allowed path scope through GET /api/w/{worksp…

▾ Sunlitwindmill-api · windmill-apiEPSS 0.47%via NVD
CVE-2026-49825High· 8.2
1mo ago

lxml is a library for processing XML and HTML in the Python language

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing ``xlink:href``, which can be used for URL bypass attacks in embedded SVG/MathML/etc. cont…

▾ TwilightRed Hat · Red Hat OpenStack Platform 16.2EPSS 0.43%via NVD
CVE-2026-49244Medium· 5.9
1mo ago

SFTPGo is an open source, event-driven file transfer solution

SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public web-client partial ZIP download endpoint for a browsable share validates client-supplied files entries with a raw byte-prefix comparison ra…

▾ Sunlitdrakkan · github.com/drakkan/sftpgo/v2EPSS 0.45%via NVD
CVE-2026-49245Low· 3.7
1mo ago

SFTPGo is an open source, event-driven file transfer solution

SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the inline query parameter on browsable-share file downloads and authenticated user-file downloads suppresses Content-Disposition: attachment, allowin…

▾ Sunlitdrakkan · github.com/drakkan/sftpgo/v2EPSS 0.25%via NVD
CVE-2026-50192Medium
1mo ago

Kerberos Agent is an open source video (surveillance) management agent

Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the Kerberos Hub upload path sends the agent's Hub credentials in the custom `X-Kerberos-Hub-PrivateKey` and `X-Kerberos-Hub-PublicKey` requ…

▾ Sunlitkerberos-io · github.com/kerberos-io/agent/machineryEPSS 0.42%via NVD
CVE-2026-62672Medium· 6.0PoC
1mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 2.0.4, Grav allowlists the regex_replace filter and function in system/config/security.yaml, and GravExtension::regexReplace() passes an editor-controlled pattern directly to preg_replace(). Wh…

▾ Twilightgetgrav · gravEPSS 0.38%via NVD
GHSA-w672-239g-c3grHigh· 6.5
1mo ago

Duplicate Advisory: GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

Duplicate Advisory: GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()

▾ Twilightgitpython · gitpythonvia GHSA
GHSA-wv46-xpj8-pw53High· 8.8
1mo ago

Duplicate Advisory: GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution

Duplicate Advisory: GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution

▾ Twilightgitpython · gitpythonvia GHSA
GHSA-7jx3-jqcp-hhgcHigh· 8.1
1mo ago

Duplicate Advisory: GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

Duplicate Advisory: GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite

▾ Twilightgitpython · gitpythonvia GHSA
GHSA-3vrx-526r-64rmHigh· 8.2
1mo ago

Duplicate Advisory: GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython

Duplicate Advisory: GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython

▾ Twilightgitpython · gitpythonvia GHSA
GHSA-298h-jpq4-m665High· 7.5
1mo ago

Duplicate Advisory: GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks

Duplicate Advisory: GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks

▾ TwilightGitPython · GitPythonvia GHSA
CVE-2026-75596High· 7.5
1mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, the default io.netty.handler.ssl.SniHandler constructors use the pre-handshake ClientHello aggregation path in handler/src/mai…

▾ Twilightnetty · nettyEPSS 0.69%via NVD
CVE-2026-75595Critical· 9.1
1mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHandler#decode checks the wrong offset before reading the four-byte TLS handshake header, so…

▾ Midnightnetty · nettyEPSS 0.46%via NVD
CVE-2026-69222High· 7.5
1mo ago

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.27.2, the join filter in src/filters/array.ts computes complexity from array.length and separator length instead of the total string length p…

▾ Twilightliquidjs · liquidjsEPSS 0.63%via NVD
CVEs tagged “ghsa” — page 38 · VulnSea