VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3811 CVEsRSS

CVE-2026-77246High· 7.4PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, an HTTP transport deployment with READ_ONLY_MODE=false accepts a request without an Authorization identity and permits …

▾ Midnightsooperset · mcp-atlassianEPSS 0.22%via NVD
CVE-2026-94462High· 7.1PoC
6d ago

Spree is an open source e-commerce solution built with Ruby on Rails

Spree is an open source e-commerce solution built with Ruby on Rails. From 5.4.0 until 5.4.4 and 5.5.4, PATCH /api/v3/store/carts/:id/associate in Spree::Api::V3::Store::CartsController#associate uses find_cart_for_association to locate …

▾ Midnightspree_api · spree_apiEPSS 0.28%via NVD
CVE-2026-77271High· 8.8PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, validate_safe_path defaults its base directory to os.getcwd(), and affected Confluence attachment call sites omit base_…

▾ Midnightmcp-atlassian · mcp_atlassianEPSS 0.42%via NVD
CVE-2026-77261High· 7.1
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, _make_ssrf_safe_hook is omitted from JiraFetcher and ConfluenceFetcher sessions created through the basic-auth and oaut…

▾ Twilightmcp-atlassian · mcp_atlassianEPSS 0.27%via NVD
CVE-2026-77260High· 8.3PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Confluence and Jira upload_attachment implementations accept an unconstrained file_path and open the referenced ser…

▾ Midnightsooperset · mcp-atlassianEPSS 0.32%via NVD
CVE-2026-77243High· 8.8PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, ENABLED_TOOLS and TOOLSETS are applied when tools are listed but are not rechecked when a tools/call request is dispatc…

▾ Midnightsooperset · mcp-atlassianEPSS 0.36%via NVD
CVE-2026-77274High· 8.2PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, validate_url_for_ssrf has a backslash authority confusion because it interprets the authority differently from the Requ…

▾ Midnightmcp-atlassian · mcp_atlassianEPSS 0.47%via NVD
CVE-2026-77258High· 7.7PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, upload_attachment in src/mcp_atlassian/confluence/attachments.py accepts a caller-controlled file_path and opens the se…

▾ Midnightsooperset · mcp-atlassianEPSS 0.33%via NVD
CVE-2026-77270Medium· 6.5PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the Jira and Confluence attachment upload tools treat caller-controlled file_path values as trusted server-local paths.…

▾ Twilightmcp-atlassian · mcp_atlassianEPSS 0.40%via NVD
CVE-2026-77265Medium· 5.9
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, header-supplied Jira or Confluence URLs are resolved and validated before the HTTP client resolves the hostname again f…

▾ Sunlitsooperset · mcp-atlassianEPSS 0.26%via NVD
CVE-2026-77244Critical· 10.0
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the HTTP transport accepts requests without a verified user identity and downstream fetcher construction falls back to …

▾ Midnightsooperset · mcp-atlassianEPSS 0.28%via NVD
CVE-2026-77267High· 8.3
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, the X-Atlassian-Jira-Url and X-Atlassian-Confluence-Url headers are processed by _process_authentication_headers and us…

▾ Twilightsooperset · mcp-atlassianEPSS 0.34%via NVD
CVE-2026-77251High· 8.3PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, Jira search accepts a forbidden project clause because it checks only for the presence of project syntax, Confluence se…

▾ Midnightsooperset · mcp-atlassianEPSS 0.25%via NVD
CVE-2026-77250Medium· 6.1PoC
6d ago

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira)

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, OAuthConfig writes a plaintext fallback file containing access and refresh tokens under the user's .mcp-atlassian direc…

▾ Twilightsooperset · mcp-atlassianEPSS 0.12%via NVD
CVE-2026-76819High· 8.6
6d ago

Rejected reason: Further research determined the issue results from a dependency.

Rejected reason: Further research determined the issue results from a dependency.

▾ Twilightprojectdiscovery · github.com/projectdiscovery/nuclei/v3via NVD
CVE-2026-85709Medium· 5.3PoC
6d ago

LightRAG provides simple and fast retrieval-augmented generation

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw Python exception text from error handlers in document_routes.py, graph_routes.py, query_routes.py, ollama_api.py, and l…

▾ TwilightHKUDS · LightRAGEPSS 0.39%via NVD
CVE-2026-85725Medium· 5.9PoC
6d ago

LightRAG provides simple and fast retrieval-augmented generation

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, verify_password in lightrag/api/passwords.py compares plaintext AUTH_ACCOUNTS password values with Python's == operator. The comparison can return after th…

▾ TwilightHKUDS · LightRAGEPSS 0.36%via NVD
CVE-2026-85740High· 7.1
6d ago

LightRAG provides simple and fast retrieval-augmented generation

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, _validated_addresses in lightrag/parser/markdown/parser.py evaluates the literal resolved address with ipaddress.is_global without consistently classifying…

▾ TwilightHKUDS · LightRAGEPSS 0.22%via NVD
CVE-2026-85734Critical· 9.1
6d ago

LightRAG provides simple and fast retrieval-augmented generation

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the POST /login endpoint in lightrag/api/lightrag_server.py does not impose a rate limit, account lockout, delay, or counter for failed authentication atte…

▾ MidnightHKUDS · LightRAGEPSS 0.36%via NVD
CVE-2026-86062Medium· 6.1PoC
6d ago

LightRAG provides simple and fast retrieval-augmented generation

LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, lightrag_webui/src/components/retrieval/ChatMessage.tsx renders answer and thinking content with react-markdown, rehypeRaw, and skipHtml=false without an H…

▾ TwilightHKUDS · LightRAGEPSS 0.25%via NVD
CVE-2026-76805Medium· 5.3
6d ago

Nuclei is a vulnerability scanner built on a simple YAML-based DSL

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST/fuzz payload path in pkg/fuzz/parts.go can evaluate substituted runtime data more than once, creating a second evaluation pass that all…

▾ Sunlitprojectdiscovery · nucleiEPSS 0.41%via NVD
CVE-2026-76804Medium· 5.5
6d ago

Nuclei is a vulnerability scanner built on a simple YAML-based DSL

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the workflow template loading path does not enforce the -file capability gate when resolving file: protocol templates referenced by a workflow. …

▾ Sunlitprojectdiscovery · nucleiEPSS 0.17%via NVD
CVE-2026-76803Medium· 5.3
6d ago

Nuclei is a vulnerability scanner built on a simple YAML-based DSL

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the nuclei/mysql JavaScript library does not enforce the local-file sandbox when a JavaScript template supplies the allowAllFiles MySQL DSN opti…

▾ Sunlitprojectdiscovery · nucleiEPSS 0.40%via NVD
CVE-2026-76802Medium· 4.7⚖ disputed
6d ago

Nuclei is a vulnerability scanner built on a simple YAML-based DSL

Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From 3.0.0 until 3.10.0, the DAST template loading branch does not apply the unsigned code-template signature check before accepting a template that contains both a fuzz…

▾ Sunlitprojectdiscovery · nucleiEPSS 0.18%via NVD
CVE-2026-56682Medium· 5.3PoC
6d ago

9Router is an AI router & token saver

9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without the sanitizing custom-server.js wrapper use the client-supplied X-9r-Real-Ip value as the bucket key in getClientIp, …

▾ Twilightdecolua · 9routerEPSS 0.47%via NVD
CVE-2026-79913Medium· 6.5
6d ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, the ValidateExternalURL server-side request forgery guard in pkg/request/ssrf.go passes resolved addresses to checkIP without decoding NAT64, IPv4-compatible…

▾ Sunlitcloudreve · cloudreveEPSS 0.40%via NVD
CVE-2026-77633High· 7.1
6d ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, PrepareUpload in pkg/filemanager/fs/dbfs/upload.go checks a stale in-memory user storage value through validateUserCapacity and later applies an unconditiona…

▾ Twilightcloudreve · cloudreveEPSS 0.37%via NVD
CVE-2026-77637Low· 3.8
6d ago

Cloudreve is a self-hosted file management and sharing system

Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, tool.GET("wopi") and tool.POST("mail") in routers/router.go inherit ScopeAdminRead but omit the RequiredScopes(types.ScopeAdminWrite) middleware applied to n…

▾ Sunlitcloudreve · cloudreveEPSS 0.33%via NVD
CVE-2026-75510Medium· 5.1PoC
6d ago

Novu provides an API for sending notifications through multiple channels

Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu's @novu/js In-App Inbox and the @novu/react Inbox component accept a notification call-to-action redirect.url from the v1 cta.data object and…

▾ Twilightnovuhq · novuEPSS 0.35%via NVD
CVE-2026-88010Medium· 6.3
6d ago

Traefik is an open source HTTP reverse proxy and load balancer

Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.7.13, checkPassword in pkg/middlewares/auth/basic_auth.go constructs the BasicAuth singleflight key from the submitted password and stored secret. Concur…

▾ Sunlittraefik · traefikEPSS 0.69%via NVD
CVEs tagged “ghsa” — page 5 · VulnSea