VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3819 CVEsRSS

GHSA-cc2g-gq8c-r332High· 7.5
1mo ago

grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools

grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools

▾ Twilightgrok-faf-mcp · grok-faf-mcpvia GHSA
GHSA-j4r7-8ph4-43g3High· 7.5
1mo ago

faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools

faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools

▾ Twilightfaf-mcp · faf-mcpvia GHSA
GHSA-rr55-jp92-8wp2High· 7.5
1mo ago

claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools

claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools

▾ Twilightclaude-faf-mcp · claude-faf-mcpvia GHSA
GHSA-qwgh-2vcv-g2f7Medium
1mo ago

block_buffer: panic corrupts inline buffer position

block_buffer: panic corrupts inline buffer position

▾ Sunlitblock_buffer · block_buffervia GHSA
CVE-2026-53951High
1mo ago

Copier has a trust-prefix bypass via path traversal that runs tasks unprompted

Copier has a trust-prefix bypass via path traversal that runs tasks unprompted

▾ Twilightcopier · copierEPSS 0.26%via OSV
CVE-2026-53964High· 7.2
1mo ago

Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)

Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)

▾ Twilightdocument-merge-service · document-merge-servicevia OSV
GHSA-p77j-g7h5-r2vwHigh
1mo ago

GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

GeoLens's authorization and cache-scope flaws disclose private dataset data and metadata to unauthorized users (fixed in 1.2.4)

▾ Twilightgeolens · geolensvia GHSA
CVE-2024-45747High· 7.2
1mo ago

GeoServer has a Server-Side Template Injection (SSTI) vulnerability in processing FreeMarker templates

GeoServer has a Server-Side Template Injection (SSTI) vulnerability in processing FreeMarker templates

▾ Twilightgeoserver · org.geoserver:gs-mainvia GHSA
CVE-2026-55694High
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.6.3, a restricted user can request /api/v1/users/{target_id}/eulas to obtain another user's randomized EULA filename and then download the signed file through /account/stored-…

▾ Twilightsnipe · snipe/snipe-itEPSS 0.41%via NVD
CVE-2026-55703Medium· 4.3
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.6.3, any activated account can request /maintenances/{id} and read maintenance records for assets in the same company without asset or maintenance permission. app/Http/Control…

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.33%via NVD
CVE-2026-61807Medium
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, a stored manufacturer or supplier name passed as the table component $name becomes data-selected-count-id in resources/views/partials/bootstrap-table.blade.php. Client-si…

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.47%via NVD
CVE-2026-62673High
1mo ago

Grav is a file-based Web platform

Grav is a file-based Web platform. Prior to 2.0.4, the Grav .htaccess and webserver-configs/htaccess.txt security rules omit the Apache [NC] flag and therefore compare sensitive directory and file-extension patterns case-sensitively. On …

▾ Twilightgetgrav · getgrav/gravEPSS 0.54%via NVD
GHSA-hjwh-xvfw-qrwjMedium· 5.5
1mo ago

SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses

SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses

▾ Sunlitmcp-searxng · mcp-searxngvia GHSA
CVE-2026-55090High
1mo ago

Etherpad is a real-time collaborative editor

Etherpad is a real-time collaborative editor. Prior to 3.3.0, getHTMLFromAtext in src/node/utils/ExportHtml.ts interpolates values from the exportHtmlAdditionalTagsWithData plugin hook into span data attributes without HTML attribute esc…

▾ Twilightep_etherpad-lite · ep_etherpad-liteEPSS 0.55%via NVD
CVE-2026-55086Medium· 4.2
1mo ago

Etherpad is a real-time collaborative editor

Etherpad is a real-time collaborative editor. Prior to 3.1.0, src/node/handler/ImportHandler.ts and src/node/handler/ExportHandler.ts derive temporary filenames from Math.random() and place them in os.tmpdir(). On a host with a shared wo…

▾ Sunlitep_etherpad-lite · ep_etherpad-liteEPSS 0.14%via NVD
CVE-2026-55088Medium· 6.8
1mo ago

Etherpad is a real-time collaborative editor

Etherpad is a real-time collaborative editor. From 2.6.0 until 3.1.0, Etherpad's src/node/hooks/express/tokenTransfer.ts uses POST /tokenTransfer to store an author token for transfer between browsers and exposes it through GET /tokenTra…

▾ Sunlitep_etherpad-lite · ep_etherpad-liteEPSS 0.44%via NVD
CVE-2026-55087Medium· 6.1PoC
1mo ago

Etherpad is a real-time collaborative editor

Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad uses the attacker-controlled x-proxy-path request header in src/node/hooks/express/admin.ts when substituting paths into HTML, JavaScript, and CSS under /admi…

▾ Twilightep_etherpad-lite · ep_etherpad-liteEPSS 0.58%via NVD
CVE-2026-54491High· 7.1
1mo ago

Koel is a free, open-source music streaming solution

Koel is a free, open-source music streaming solution. Prior to 9.7.1, outbound podcast and radio fetch paths perform a point-in-time App\Helpers\Network::isPublicHost() or isSafeUrl() check without pinning the validated address, and most…

▾ Twilightphanan · phanan/koelEPSS 0.38%via NVD
CVE-2026-54494Medium
1mo ago

Koel is a free, open-source music streaming solution

Koel is a free, open-source music streaming solution. Prior to 9.7.1, App\Helpers\Network::isPublicHost() uses filter_var() with FILTER_FLAG_NO_PRIV_RANGE and FILTER_FLAG_NO_RES_RANGE, which treats NAT64 64:ff9b::/96 and 6to4 2002::/16 w…

▾ Sunlitphanan · phanan/koelEPSS 0.43%via NVD
CVE-2026-54492Medium· 4.3
1mo ago

Koel is a free, open-source music streaming solution

Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible createPodcastChannel.view route accepts an authenticated user's private URL because app/Http/Requests/Subsonic/CreatePodcastChannelRequest.php …

▾ Sunlitphanan · phanan/koelEPSS 0.41%via NVD
CVE-2026-54493High· 7.7
1mo ago

Koel is a free, open-source music streaming solution

Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible createInternetRadioStation.view and updateInternetRadioStation.view routes accept an authenticated user's streamUrl without the SafeUrl and Has…

▾ Twilightphanan · phanan/koelEPSS 0.41%via NVD
CVE-2026-52889Critical· 9.8
1mo ago

Formie is a Craft CMS plugin for creating forms

Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hidden field defaults such as HTTP User Agent, Referer URL, Current URL, Current URL without Query String, Query Parameter, and Cookie Valu…

▾ Midnightverbb · verbb/formieEPSS 1.3%via NVD
CVE-2026-52834High· 7.3
1mo ago

jxl-oxide is a pure Rust implementation of a JPEG XL decoder

jxl-oxide is a pure Rust implementation of a JPEG XL decoder. Prior to jxl-grid 0.6.2, decoding a crafted JPEG XL image on a 32-bit platform can overflow length calculations in AlignedGrid::with_alloc_tracker and related grid and subgrid…

▾ Twilightjxl-grid · jxl-gridEPSS 0.17%via NVD
CVE-2026-52792High
1mo ago

Algernon is a small self-contained pure-Go web server

Algernon is a small self-contained pure-Go web server. Prior to 1.17.9, Algernon on Windows selects a file handler in engine/handlers.go by calling filepath.Ext() without first rejecting NTFS-equivalent names such as x.lua::$DATA, x.lua.…

▾ Twilightxyproto · github.com/xyproto/algernonEPSS 0.63%via NVD
CVE-2026-49283High· 8.7
1mo ago

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.19.3, 4.20.2, 5.0.6, and 6.2.1, the HTTPArtifact::receive() flow can treat an unsigned embedded SAML Response as cryptographically vali…

▾ Twilightsimplesamlphp · simplesamlphp/saml2EPSS 0.47%via NVD
CVE-2026-49289High· 7.5
1mo ago

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. In 4.19.2 and 4.20.2, the library permits attacker-controlled XPath transforms while processing XML signatures in specially crafted SAML messages. XPath ev…

▾ Twilightsimplesamlphp · simplesamlphp/saml2EPSS 0.78%via NVD
CVE-2026-49253High· 7.1
1mo ago

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.11.11, electerm uses remote-supplied filenames directly with path.join() while receiving Zmodem and Trzsz transfers. In src/app/server/z…

▾ Twilightelecterm · electermEPSS 0.44%via NVD
CVE-2026-49255High· 8.8
1mo ago

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.11.11, electerm constructs operating system commands in src/app/lib/fs.js by interpolating untrusted file paths into the rmrf(), mv(), a…

▾ Twilightelecterm · electermEPSS 0.79%via NVD
CVE-2026-50149Medium· 6.5
1mo ago

Contour is a Kubernetes ingress controller using Envoy proxy

Contour is a Kubernetes ingress controller using Envoy proxy. In versions 1.23.0 through 1.33.4, when an `HTTPProxy` is configured with incompatible combination of both `.spec.virtualhost.tls.enableFallbackCertificate: true` and `.spec.v…

▾ Sunlitprojectcontour · github.com/projectcontour/contourEPSS 0.18%via NVD
CVE-2026-49870Medium· 5.9
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.6.1, POST /two-factor has no rate limiting, lockout, or attempt counter, allowing an attacker with valid credentials to submit unlimited TOTP guesses against the three accepte…

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.40%via NVD
CVEs tagged “ghsa” — page 40 · VulnSea