VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3816 CVEsRSS

CVE-2026-62682Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, an unescaped backtick in servers[0].url is emitted into request URL template literals generated when output.baseUr…

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-62681Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, an unescaped backtick in an OpenAPI path is emitted into request URL template literals generated for axios, fetch,…

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-71864Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a double quote in a header parameter name is emitted into the generated request-validation zod.object({...}) schem…

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-71865Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a double quote in a query parameter name is emitted into the generated request-validation zod.object({...}) schema…

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-71868Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in an enum default is emitted into a module-level template literal emitted by zod …

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-71867Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a single quote in a schema property name is emitted into single-quoted object keys in generated MSW mock factories…

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-71871Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a header parameter default is emitted into a module-level template literal emit…

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-71869Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in an array item default is emitted into a module-level template literal emitted b…

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-72717Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a schema default is emitted into a module-level template literal emitted by zod…

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-61556High
1mo ago

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. From 10.26.0 until 10.27.1, the strip_html filter in src/filters/html.ts can enter an infinite loop when an input string contains <, includes at least on…

▾ Twilightliquidjs · liquidjsEPSS 0.52%via NVD
CVE-2026-62669High· 7.4
1mo ago

Grav Login Plugin adds login, basic ACL, and session wide messages to Grav

Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Grav Login plugin login.regenerate2FASecret task checks only that the pending-session user exists rather than requiring $user->authorized. A…

▾ Twilightgetgrav · getgrav/gravEPSS 0.50%via NVD
CVE-2026-61690Medium· 6.5
1mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipArchiver::extract() in system/src/Grav/Common/Filesystem/ZipArchiver.php passes archives to ZipArchive::extractTo() without enforcing the system.gpm.archive uncompressed-size, fi…

▾ Sunlitgetgrav · getgrav/gravEPSS 0.53%via NVD
CVE-2026-61842Medium· 6.5
1mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig content sandbox permits grav.offsetGet('config') to return the raw configuration object and permits json_encode, print_r, yaml_encode, and string filters to serialize that …

▾ Sunlitgetgrav · getgrav/gravEPSS 0.44%via NVD
CVE-2026-64850High
1mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 2.0.7, Grav Blueprint::dynamicData() in system/src/Grav/Common/Data/Blueprint.php sends an editor-controlled Class::method provider and arguments to call_user_func_array() without rejecting dan…

▾ Twilightgetgrav · getgrav/gravEPSS 0.47%via NVD
CVE-2026-71866Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. From version 8.19.0 until 8.21.0, a double quote in a schema property name is emitted into the generated zod.object({...}) schema w…

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-72716Critical
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or backtick in a query parameter default is emitted into a module-level template literal emitt…

▾ Midnightorval · orvalEPSS 0.65%via NVD
CVE-2026-62680High· 7.1
1mo ago

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications

Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.22.0, Orval resolves remote and local external $ref values without an allowlist or confinement to the input directory. P…

▾ Twilightorval · orvalEPSS 0.40%via NVD
CVE-2026-76220High· 8.8
1mo ago

gitpython: GitPython: Arbitrary command execution via crafted kwargs (CVE-2026-76220)

A flaw was found in GitPython. A remote attacker can bypass the `check_unsafe_options` guard by combining a single-character keyword argument with `split_single_char_options=False`. This allows the attacker to supply a crafted dictionary o…

▾ TwilightRed Hat · Red Hat Satellite 6.19 for RHEL 9EPSS 0.91%via CSAF
CVE-2026-76222High· 8.2
1mo ago

gitpython: GitPython: Arbitrary file creation via path traversal in .gitmodules submodule names (CVE-2026-76222)

A flaw was found in GitPython where it fails to properly validate submodule names within .gitmodules files. A remote attacker could craft a malicious Git repository containing specially formed submodule names with directory traversal seque…

▾ TwilightRed Hat · Red Hat OpenShift AI (RHOAI)EPSS 0.42%via CSAF
CVE-2026-76218High· 7.5
1mo ago

gitpython: GitPython: Remote Code Execution via malicious Git hooks (CVE-2026-76218)

A flaw was found in GitPython. This vulnerability allows a remote attacker to achieve arbitrary code execution. By supplying a specially crafted template parameter to the `Repo.init` function, an attacker can point to a directory containin…

▾ TwilightRed Hat · Red Hat Satellite 6.19 for RHEL 9EPSS 0.83%via CSAF
CVE-2026-76219High· 8.1
1mo ago

gitpython: GitPython: Arbitrary File Overwrite via `git read-tree` option injection (CVE-2026-76219)

A flaw was found in GitPython. This vulnerability allows an attacker to overwrite arbitrary files on the system. By injecting specific options into the `git read-tree` command through methods like `IndexFile.from_tree`, `IndexFile.reset`, …

▾ TwilightRed Hat · Red Hat Satellite 6.19 for RHEL 9EPSS 0.54%via CSAF
CVE-2026-59992Medium· 5.4
1mo ago

Tina is a headless content management system

Tina is a headless content management system. Prior to next-tinacms-s3 23.0.4, next-tinacms-dos 23.0.4, next-tinacms-azure 14.0.4, and next-tinacms-cloudinary 26.0.4, the first-party production media adapters pass attacker-controlled obj…

▾ Sunlitnext-tinacms-s3 · next-tinacms-s3EPSS 0.38%via NVD
CVE-2026-63123Medium· 6.5
1mo ago

Tina is a headless content management system

Tina is a headless content management system. Prior to 2.5.2, the TinaCMS CLI package's Vite dev server packages/@tinacms/cli/src/next/vite/cors.ts origin callback returns false for a disallowed origin but does not reject the request, an…

▾ Sunlittinacms · @tinacms/cliEPSS 0.26%via NVD
CVE-2026-61711Medium
1mo ago

BuildKit: Custom frontend could bypass Seccomp/AppArmor

BuildKit: Custom frontend could bypass Seccomp/AppArmor

▾ Sunlitmoby · github.com/moby/buildkitEPSS 0.47%via OSV
CVE-2026-61712Low
1mo ago

BuildKit has a possible runtime DoS via unbounded group parsing

BuildKit has a possible runtime DoS via unbounded group parsing

▾ Sunlitmoby · github.com/moby/buildkitEPSS 0.53%via OSV
CVE-2026-63188High
1mo ago

Logto is the modern, open-source auth infrastructure for SaaS and AI apps

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 0.3.9, the Logto Tunnel npm package enabled createStaticFileProxy from packages/tunnel/src/commands/tunnel/index.ts and passed request.url from static as…

▾ Twilightlogto · @logto/tunnelEPSS 0.54%via NVD
GHSA-cc2g-gq8c-r332High· 7.5
1mo ago

grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools

grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools

▾ Twilightgrok-faf-mcp · grok-faf-mcpvia GHSA
GHSA-j4r7-8ph4-43g3High· 7.5
1mo ago

faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools

faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools

▾ Twilightfaf-mcp · faf-mcpvia GHSA
GHSA-rr55-jp92-8wp2High· 7.5
1mo ago

claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools

claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools

▾ Twilightclaude-faf-mcp · claude-faf-mcpvia GHSA
GHSA-qwgh-2vcv-g2f7Medium
1mo ago

block_buffer: panic corrupts inline buffer position

block_buffer: panic corrupts inline buffer position

▾ Sunlitblock_buffer · block_buffervia GHSA
CVEs tagged “ghsa” — page 39 · VulnSea