VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3826 CVEsRSS

CVE-2026-54662High· 8.3
2mo ago

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template

▾ Twilightswagger-typescript-api · swagger-typescript-apiEPSS 0.48%via GHSA
CVE-2026-54663Medium· 6.1
2mo ago

swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`

swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`

▾ Sunlitswagger-typescript-api · swagger-typescript-apiEPSS 0.32%via GHSA
CVE-2026-54661High· 8.3
2mo ago

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template

swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template

▾ Twilightswagger-typescript-api · swagger-typescript-apiEPSS 0.48%via GHSA
CVE-2026-54664High· 8.3
2mo ago

swagger-typescript-api vulnerable to code injection via unescaped enum string values

swagger-typescript-api vulnerable to code injection via unescaped enum string values

▾ Twilightswagger-typescript-api · swagger-typescript-apiEPSS 0.48%via GHSA
CVE-2026-54666High· 8.3
2mo ago

swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies

swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies

▾ Twilightswagger-typescript-api · swagger-typescript-apiEPSS 0.48%via GHSA
CVE-2026-55415High· 7.5
2mo ago

datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements

datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.49%via OSV
CVE-2026-54690High· 8.2
2mo ago

datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)

datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.39%via OSV
CVE-2026-54656High· 7.8
2mo ago

`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data

`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.25%via GHSA
CVE-2026-55391High· 7.5
2mo ago

datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding

datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.30%via OSV
CVE-2026-54653High· 8.8
2mo ago

`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field

`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.71%via OSV
CVE-2026-55389High· 7.5
2mo ago

datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-…

datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.55%via OSV
CVE-2026-54654High· 7.8
2mo ago

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.21%via OSV
CVE-2026-62325Critical· 9.1
2mo ago

goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)

goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)

▾ Midnightpatrickhener · github.com/patrickhener/goshs/v2EPSS 0.59%via GHSA
CVE-2026-54719High· 7.5
2mo ago

goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)

goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of GHSA-wvhv-qcqf-f3cx)

▾ Twilightpatrickhener · github.com/patrickhener/goshsEPSS 0.47%via GHSA
CVE-2026-64863Critical· 9.1
2mo ago

goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite

goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite

▾ Midnightgoshs · goshs.de/goshs/v2EPSS 0.63%via GHSA
CVE-2026-66063Medium· 6.5
2mo ago

goshs has a Path Traversal issue

goshs has a Path Traversal issue

▾ Sunlitgoshs · goshs.de/goshs/v2EPSS 0.34%via GHSA
CVE-2026-54638High· 7.5
2mo ago

gotd/td is a T Telegram MTProto API client in Go

gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted_message.go read attacker controlled dataLen from an unauthenticated MTProto unencrypted packet and allocated make([]…

▾ Twilightgotd · github.com/gotd/tdEPSS 0.63%via NVD
CVE-2026-54658Critical· 9.8
2mo ago

@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution

@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution

▾ Midnighthypequery · @hypequery/clickhouseEPSS 0.82%via GHSA
CVE-2026-54650High· 8.6
2mo ago

openhole exposes localhost to the internet in one command

openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded r.URL.Path instead of preserving the original request target with r.URL.EscapedPath(), allowing…

▾ Twilightbablilayoub · github.com/bablilayoub/openholeEPSS 0.53%via NVD
CVE-2026-54639High· 8.8
2mo ago

Style Dictionary - Prototype Pollution in convertTokenData utility function

Style Dictionary - Prototype Pollution in convertTokenData utility function

▾ Twilightstyle-dictionary · style-dictionaryEPSS 0.36%via GHSA
GHSA-6xx4-9wp6-65p7Medium· 6.5
2mo ago

skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source

skilo add follows symbolic links, allowing arbitrary local file disclosure from a malicious skill source

▾ Sunlitskilo · skilovia GHSA
CVE-2026-54659Medium
2mo ago

Pagy I18n locale option is not validated before being used in a file path

Pagy I18n locale option is not validated before being used in a file path

▾ Sunlitpagy · pagyEPSS 0.54%via GHSA
CVE-2026-66064Medium· 5.3
2mo ago

goshs has ACL Bypass & Path Traversal

goshs has ACL Bypass & Path Traversal

▾ Sunlitpatrickhener · github.com/patrickhener/goshs/v2EPSS 0.45%via GHSA
CVE-2026-52888Medium· 6.8
2mo ago

NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass

NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass

▾ Sunlitnocobase · @nocobase/plugin-collection-sqlEPSS 0.47%via GHSA
CVE-2026-55390High· 7.5
2mo ago

datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate

datamodel-code-generator vulnerable to arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.53%via GHSA
CVE-2026-54691High· 8.2
2mo ago

datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects

datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.38%via OSV
CVE-2026-55403Low· 3.7
2mo ago

datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas

datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas

▾ Sunlitdatamodel-code-generator · datamodel-code-generatorEPSS 0.34%via OSV
CVE-2026-54655High· 7.8
2mo ago

`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator

`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.21%via GHSA
CVE-2026-54621High· 7.8
2mo ago

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description

`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description

▾ Twilightdatamodel-code-generator · datamodel-code-generatorEPSS 0.21%via OSV
CVE-2026-50570High· 8.5
2mo ago

Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption

Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption

▾ Twilightfission · github.com/fission/fissionEPSS 0.46%via GHSA
CVEs tagged “ghsa” — page 61 · VulnSea