VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3826 CVEsRSS

GHSA-xhcr-cqfr-m3hvHigh
1mo ago

atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)

atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE)

▾ Twilightatomic-agents-stack · atomic-agents-stackvia GHSA
GHSA-j659-8xh6-5pq5High
1mo ago

atomic-agents-stack: Parallel helper/delegate batch reserves $0 for models absent from the pricing table, bypassing the cost-cap fan-out guard

atomic-agents-stack: Parallel helper/delegate batch reserves $0 for models absent from the pricing table, bypassing the cost-cap fan-out guard

▾ Twilightatomic-agents-stack · atomic-agents-stackvia GHSA
GHSA-mpwr-8vm7-h73fMedium
1mo ago

package pkcs12: Authentication bypass in Decode functions

package pkcs12: Authentication bypass in Decode functions

▾ Sunlitsrc · software.sslmate.com/src/go-pkcs12via GHSA
CVE-2026-53766Medium· 6.1
1mo ago

chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots

chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots

▾ Sunlitchrome-devtools-mcp · chrome-devtools-mcpEPSS 0.12%via GHSA
CVE-2026-56677High· 8.6
1mo ago

9Router is an AI router & token saver

9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in src/app/api/auth/oidc/test/route.js passes the user-controlled issuerUrl parameter to fetchOidcDiscovery() in src/lib/auth/oidc.js with…

▾ Twilight9router · 9routerEPSS 0.38%via NVD
CVE-2026-64849High· 8.5CISA KEVPoC
1mo ago

mlflow: MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS …

A flaw was found in MLflow. An unauthenticated remote attacker can exploit a Server-Side Request Forgery (SSRF) vulnerability by sending a specially crafted request to the webhook test endpoint. This occurs because the system validates onl…

▾ AbyssalRed Hat · Red Hat OpenShift AI 3.4EPSS 9.8%via CSAF
CVE-2026-69146Medium· 6.5
1mo ago

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.13.0 until 3.15.0, LogInputs is absent from BEFORE_REQUEST_HANDLERS in the mlflow/server/auth package, allowing any a…

▾ Sunlitmlflow · mlflowEPSS 0.39%via NVD
CVE-2026-69148High· 7.1
1mo ago

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, CreateModelVersion accepts a run_id or model_id after _validate_source_run() or _validate_source_model() in…

▾ Twilightmlflow · mlflowEPSS 0.37%via NVD
CVE-2026-59903Medium· 6.5PoC
1mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.http.cors.CorsHandler setVaryHeader replaces application Vary headers such as Authorization or Cookie w…

▾ Twilightnetty · nettyEPSS 0.25%via NVD
CVE-2026-68517Medium· 6.5
1mo ago

Glances is an open-source system cross-platform monitoring tool

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, the cors_origins guard in glances/outputs/glances_restful_api.py uses exact list equality instead of wildcard membership, allowing a multi-origin list conta…

▾ Sunlitglances · glancesEPSS 0.46%via NVD
CVE-2026-59894Medium
1mo ago

sqlparse is a non-validating SQL parser module for Python

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse/filters/output.py fails to escape existing backslashes before quotes in sqlparse.format output_format='python' and output_format='php' and the correspond…

▾ Sunlitsqlparse · sqlparseEPSS 0.18%via NVD
CVE-2026-62982High· 8.8
1mo ago

Glances is an open-source system cross-platform monitoring tool

Glances is an open-source system cross-platform monitoring tool. From 4.5.2 until 4.5.6, _sanitize_mustache_dict() in glances/actions.py skips nested list and dictionary strings such as process cmdline values, allowing pipe characters to…

▾ Twilightglances · glancesEPSS 0.20%via NVD
CVE-2026-68519High
1mo ago

Glances is an open-source system cross-platform monitoring tool

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, GlancesActions.run() in glances/actions.py ignores --disable-config-exec for on-alert action commands and invokes secure_popen() with shell operators enable…

▾ Twilightglances · glancesEPSS 0.18%via NVD
CVE-2026-68520Medium· 5.3
1mo ago

Glances is an open-source system cross-platform monitoring tool

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.6, as_dict_secure() in glances/config.py checks only option names and exposes public_username and credentials embedded in public_api values through unauthentic…

▾ Sunlitglances · glancesEPSS 0.40%via NVD
CVE-2026-71491High· 7.5
1mo ago

sqlparse is a non-validating SQL parser module for Python

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, group_comments in sqlparse/engine/grouping.py repeatedly rescans comment-only statements before the MAX_GROUPING_TOKENS guard, causing quadratic CPU consumption t…

▾ TwilightRed Hat · Red Hat OpenStack Platform 16.2EPSS 0.26%via NVD
CVE-2026-47683High· 7.5
1mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, the bufferAllocLimit enforcement in lib/setup-sandbox.js does not cover Buffer.concat(list, totalLength) or Buffer.from(arrayLike) with an attacker-controlled length, allowin…

▾ Twilightvm2 · vm2EPSS 0.54%via NVD
CVE-2026-47686Critical· 9.9
1mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbox.js sanitizes SuppressedError.error, SuppressedError.suppressed, and AggregateError.errors but does not sanitize Error.cause, allowing s…

▾ Midnightvm2 · vm2EPSS 0.58%via NVD
CVE-2026-47698Critical· 9.8
1mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.js fail to block stacked indirection through Function.prototype.call around dangerous host prototype getter and setter mutators, allowing …

▾ Midnightvm2 · vm2EPSS 0.97%via NVD
GHSA-m5w8-4gq2-6f8xCritical· 10.0
1mo ago

vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)

vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)

▾ Midnightvm2 · vm2via GHSA
GHSA-v836-6xw4-9cx3High· 7.5
1mo ago

vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass

vm2 has Memory Exhaustion DoS via bufferAllocLimit Bypass

▾ Twilightvm2 · vm2via GHSA
GHSA-92hr-gmr6-h8cpMedium
1mo ago

Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling

Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling

▾ Sunlitep_etherpad-lite · ep_etherpad-litevia GHSA
CVE-2026-54284High· 7.5
1mo ago

sqlparse is a non-validating SQL parser module for Python

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, TokenList construction and string conversion in sqlparse/sql.py repeatedly flatten nested token subtrees constructed by group_parenthesis and group_case, causing …

▾ Twilightsqlparse · sqlparseEPSS 0.33%via NVD
CVE-2026-59893High· 7.5
1mo ago

sqlparse is a non-validating SQL parser module for Python

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, SQL_REGEX in sqlparse/keywords.py and the per-position loop in sqlparse/lexer.py repeatedly scan unmatched dollar-quoted literal and multiline-comment delimiters,…

▾ Twilightsqlparse · sqlparseEPSS 0.34%via NVD
GHSA-fhgh-wq4q-r37xHigh· 7.8
1mo ago

uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set

uniget CLI: Metadata signature verification only runs when UNIGET_IGNORE_METADATA_SIGNATURE is set

▾ Twilightuniget-org · gitlab.com/uniget-org/clivia GHSA
CVE-2026-59902High· 7.5
1mo ago

Netty is an asynchronous, event-driven network application framework

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, io.netty.handler.codec.sctp.SctpMessageCompletionHandler limits incomplete messages and fragment counts but not maxBufferedByt…

▾ Twilightnetty · nettyEPSS 0.67%via NVD
CVE-2026-64859Critical· 9.1
1mo ago

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, return User.AccessToken as access_token bec…

▾ MidnightQuantumNous · github.com/QuantumNous/new-apiEPSS 0.63%via NVD
CVE-2026-64868High· 7.5
1mo ago

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webhook, POST /api/creem/webhook, and POST /api/waffo/webhook read and log full request bodie…

▾ TwilightQuantumNous · github.com/QuantumNous/new-apiEPSS 0.64%via NVD
CVE-2026-64866Medium
1mo ago

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. From 0.9.1.3 until 1.0.0-rc.7, AdminResetPasskey in controller/passkey.go lacks the canManageTargetRole authorization check for DELE…

▾ SunlitQuantumNous · github.com/QuantumNous/new-apiEPSS 0.47%via NVD
CVE-2026-71479Critical· 9.1
1mo ago

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_completion_tokens, maxOutputTokens, audio…

▾ MidnightQuantumNous · github.com/QuantumNous/new-apiEPSS 0.65%via NVD
CVE-2026-64865Medium
1mo ago

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.16, repeated PUT /api/user/self requests that update language or sidebar_modules can race relay billing because co…

▾ SunlitQuantumNous · github.com/QuantumNous/new-apiEPSS 0.29%via NVD
CVEs tagged “ghsa” — page 45 · VulnSea