VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3820 CVEsRSS

CVE-2026-49976Medium· 6.5
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.6.1, a user with the import permission can use CSV update mode to overwrite the email address of a non-admin user and then request a password reset to take over that account. …

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.47%via NVD
CVE-2026-50550Medium· 5.8
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.5.0, a user who can edit other users can reset a superadmin's two-factor authentication through app/Http/Controllers/Api/UsersController.php postTwoFactorReset(). The endpoint…

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.27%via NVD
CVE-2026-55482Medium· 6.3
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, a non-superadmin can use app/Http/Controllers/Assets/BulkAssetsController.php update() to submit company_id directly without Company::getIdForCurrentUser(), allowing asse…

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.33%via NVD
CVE-2026-55483Medium
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.6.0, an authenticated user with users.create permission can submit the admin permission while creating a user because store() in app/Http/Controllers/Users/UsersController.php…

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.41%via NVD
CVE-2026-55519Medium· 5.4
1mo ago

Snipe-IT is an IT asset/license management system

Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an authenticated user with generic asset edit permission can delete files attached to assets outside the user's ownership or company assignment. The destroy() methods in …

▾ Sunlitsnipe · snipe/snipe-itEPSS 0.37%via NVD
GHSA-fwwx-3362-3947Critical· 8.8
1mo ago

Duplicate Advisory: Grav: Blueprint dynamic-data bare-function branch is denylist-gated and omits error_log, giving arbitrary file write

Duplicate Advisory: Grav: Blueprint dynamic-data bare-function branch is denylist-gated and omits error_log, giving arbitrary file write

▾ Midnightgetgrav · getgrav/gravvia GHSA
GHSA-9pr6-8r9w-wvmjCritical· 8.7
1mo ago

Duplicate Advisory: Grav: detectXss() misses an event-handler attribute after an unpaired quote in an unquoted attribute value, giving stored XSS

Duplicate Advisory: Grav: detectXss() misses an event-handler attribute after an unpaired quote in an unquoted attribute value, giving stored XSS

▾ Midnightgetgrav · getgrav/gravvia GHSA
GHSA-993v-76jg-67xrMedium· 5.4
1mo ago

Duplicate Advisory: Grav: Single invalid UTF-8 byte disables every rule in Security::detectXss(), bypassing the page-content XSS safety gate

Duplicate Advisory: Grav: Single invalid UTF-8 byte disables every rule in Security::detectXss(), bypassing the page-content XSS safety gate

▾ Sunlitgetgrav · getgrav/gravvia GHSA
GHSA-m97h-2qj3-5773Critical· 9.1
1mo ago

Duplicate Advisory: Grav: Missing admin.super guard on core group blueprint access field allows admin.users operator to escalate to super-admin

Duplicate Advisory: Grav: Missing admin.super guard on core group blueprint access field allows admin.users operator to escalate to super-admin

▾ Midnightgetgrav · getgrav/gravvia GHSA
GHSA-2rhw-8953-48q3High· 5.9
1mo ago

Duplicate Advisory: Grav: Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server (`index.php`)

Duplicate Advisory: Grav: Unauthenticated Path Traversal via Missing Directory-Boundary Check in `plugin-asset-map.php` Static Asset Server (`index.php`)

▾ Twilightgetgrav · getgrav/gravvia GHSA
GHSA-q8cg-5m48-5c25Medium· 7.6
1mo ago

Duplicate Advisory: Grav: Stored XSS via Markdown audio/video media <source> URL

Duplicate Advisory: Grav: Stored XSS via Markdown audio/video media <source> URL

▾ Sunlitgetgrav · getgrav/gravvia GHSA
CVE-2026-75837Critical· 9.1
1mo ago

Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction

Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admin.users operator can save a group with access[admin][super]=true to escalate to super-ad…

▾ Midnightgetgrav · getgrav/gravEPSS 0.49%via NVD
CVE-2026-75834Medium· 5.4
1mo ago

Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php)

Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). All XSS detection patterns use the PCRE /u (UTF-8) modifier, so a single invalid UTF-8 b…

▾ Sunlitgetgrav · getgrav/gravEPSS 0.26%via NVD
CVE-2026-75831High· 7.6
1mo ago

Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownElement method

Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownElement method. The media URL fragment is concatenated unescaped into rawHtml source elements, allo…

▾ Twilightgetgrav · getgrav/gravEPSS 0.35%via NVD
CVE-2026-75828High· 8.7
1mo ago

Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute values bypass event-handler detection

Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute values bypass event-handler detection. Authenticated editors can inject event handlers like o…

▾ Twilightgetgrav · getgrav/gravEPSS 0.39%via NVD
CVE-2026-75827High· 8.8PoC
1mo ago

Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist

Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist. Attackers with page-edit or blueprint-config acces…

▾ Midnightgetgrav · getgrav/gravEPSS 0.86%via NVD
CVE-2026-74907Medium· 5.9
1mo ago

Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string prefix matching instead of directory-boundary validation

Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string prefix matching instead of directory-boundary validation. Unauthenticated attackers can access files in sibling direc…

▾ Sunlitgetgrav · getgrav/gravEPSS 0.43%via NVD
CVE-2026-75914High· 7.5
1mo ago

CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading files

CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading files. Attackers can create workspace symlinks pointing to external files with image ext…

▾ Twilightdeepseek-tui · deepseek-tuiEPSS 0.53%via NVD
CVE-2026-75859High· 7.5
1mo ago

CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on the victim's system

CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on the victim's system. A malicious .codewhale/config.toml file in a cloned repository can …

▾ Twilightdeepseek-tui · deepseek-tuiEPSS 0.53%via NVD
CVE-2026-75857High· 7.0
1mo ago

CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool, whose approval_requirement returns ApprovalRequirement::Auto

CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool, whose approval_requirement returns ApprovalRequirement::Auto. This overrides the default Required approval for code-…

▾ Twilightdeepseek-tui · deepseek-tuiEPSS 0.15%via NVD
CVE-2026-75913Critical· 9.3
1mo ago

CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool

CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-supplied rev parameter is passed unvalidated into the git show argv without an --end-of-opt…

▾ Midnightdeepseek-tui · deepseek-tuiEPSS 0.48%via NVD
CVE-2026-75915High· 7.5
1mo ago

CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_execution tool that fails to scrub parent process environment variables before spawning Node.js

CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_execution tool that fails to scrub parent process environment variables before spawning Node.js. Attackers can craft malicious JavaScript c…

▾ Twilightdeepseek-tui · deepseek-tuiEPSS 0.68%via NVD
CVE-2026-75856High· 8.6
1mo ago

CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-use attacks

CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-use attacks. Attackers can manipulate DNS responses to fail initial resolution checks an…

▾ Twilightdeepseek-tui · deepseek-tuiEPSS 0.50%via NVD
CVE-2026-75912High· 7.4
1mo ago

CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool that allows attackers to read arbitrary files by injecting git options into the unvalidated rev parameter

CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool that allows attackers to read arbitrary files by injecting git options into the unvalidated rev parameter. Attackers can supply rev values…

▾ Twilightdeepseek-tui · deepseek-tuiEPSS 0.45%via NVD
CVE-2026-75858High· 7.8
1mo ago

CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval tool

CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval tool. The tool's approval_requirement() returns ApprovalRequirement::Auto, which the engine trea…

▾ Twilightdeepseek-tui · deepseek-tuiEPSS 0.36%via NVD
CVE-2026-75911High· 7.8
1mo ago

CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config files, allowing attackers to enable arbitrary shell command execution by committing a malicious .codewhale/config.toml…

CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config files, allowing attackers to enable arbitrary shell command execution by committing a malicious .codewhale/config.toml…

▾ Twilightdeepseek-tui · deepseek-tuiEPSS 0.25%via NVD
CVE-2026-16732Medium· 6.1
1mo ago

fastify: fastify: Request spoofing via numeric trustProxy configuration (CVE-2026-16732)

A flaw was found in fastify. When configured with a numeric `trustProxy` value, an attacker who can directly access the Fastify origin, bypassing the front-facing proxy, can spoof forwarded request fields. This vulnerability allows for hos…

▾ SunlitRed Hat · Red Hat OpenShift Dev SpacesEPSS 0.16%via CSAF
GHSA-vjf8-9fx6-mv6xMedium
1mo ago

Triton VM Soundness Vulnerability due to Missing Constraint

Triton VM Soundness Vulnerability due to Missing Constraint

▾ Sunlittriton-vm · triton-vmvia GHSA
GHSA-qxq5-qhx6-94qwHigh· 7.8
1mo ago

Incomplete Fix in MONAI: algo_from_pickle() pickle.loads() RCE still present in v1.5.2 despite GHSA-89gg-p5r5-q6r4 claiming patch

Incomplete Fix in MONAI: algo_from_pickle() pickle.loads() RCE still present in v1.5.2 despite GHSA-89gg-p5r5-q6r4 claiming patch

▾ Twilightmonai · monaivia GHSA
GHSA-rghg-q7wp-9767High
1mo ago

MONAI vulnerable to OS command injection

MONAI vulnerable to OS command injection

▾ TwilightMONAI · MONAIvia GHSA
CVEs tagged “ghsa” — page 41 · VulnSea