Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
GHSA-86cx-wwf4-phq4Medium· 6.5OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API
CVE-2026-16584High· 7.0AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
AWS API MCP Server Security Policy Bypass via Startup Initialization Failure
GHSA-6v4m-fw66-8r4xMediumShescape: Path disclosure on Unix with Zsh
Shescape: Path disclosure on Unix with Zsh
GHSA-w4hw-qcx7-56prCriticalShescape: Shell injection via unescaped parentheses on Windows with CMD
Shescape: Shell injection via unescaped parentheses on Windows with CMD
GHSA-q53c-4prm-w95qMediumShescape: Home-directory disclosure in assignment context on Unix with Dash
Shescape: Home-directory disclosure in assignment context on Unix with Dash
GHSA-gm3r-q2wp-hw87HighShescape: Quadratic-time denial of service in the flag-protection
Shescape: Quadratic-time denial of service in the flag-protection
GHSA-fp43-vj7g-pg92High· 7.5OmniFaces: Forged combined-resource IDs and related output/push boundaries
OmniFaces: Forged combined-resource IDs and related output/push boundaries
GHSA-fwjx-9p69-h25hMedium· 6.1Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data
GHSA-6xj8-qv9j-xcjqHigh· 7.8Oh My Posh: Arbitrary command execution via template injection in the path segment
Oh My Posh: Arbitrary command execution via template injection in the path segment
GHSA-3r53-75j5-3g7jMedium· 5.6Quasar: Prototype pollution in the extend() utility
Quasar: Prototype pollution in the extend() utility
GHSA-hmj8-5xmh-5573High· 7.5libp2p: yamux connection DoS via oversized data frame
libp2p: yamux connection DoS via oversized data frame
CVE-2026-16756High· 7.5Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service
GHSA-xg4h-6gfc-h4m8Highetcd: Watch API authorization bypass via open-ended range requests
etcd: Watch API authorization bypass via open-ended range requests
CVE-2026-16796High· 7.3AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
CVE-2026-59223Medium· 4.3Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
CVE-2026-59224High· 8.0Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
CVE-2026-59212Medium· 5.4Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
CVE-2026-59225Medium· 5.4Open WebUI: Arena task endpoints can bypass underlying model access controls
Open WebUI: Arena task endpoints can bypass underlying model access controls
CVE-2026-59221High· 7.7open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal
CVE-2026-44907High· 7.5react-server-dom: Denial of Service in Server Functions
react-server-dom: Denial of Service in Server Functions
GHSA-j9fc-w3mr-x6mvHigh· 8.8Budibase: Privilege escalation via public role assignment API missing app-level authorization
Budibase: Privilege escalation via public role assignment API missing app-level authorization
GHSA-4qcj-m5wp-jmf4Medium· 4.3Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings
Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings
GHSA-fcrw-f7gg-6g9fMedium· 4.9Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users
Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users
GHSA-c8vc-7pv3-g98pHighBudibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)
Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)
GHSA-q6x4-v3qx-85qwCritical· 9.6Budibase: SQL Injection via `multipleStatements: true`
Budibase: SQL Injection via `multipleStatements: true`
GHSA-ppr4-5f46-j9c6HighBudibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile
Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile
GHSA-xcx6-4f2g-hhgxHigh· 7.7Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs
Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs
GHSA-xg5g-26x8-cvf4High· 8.5Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution
Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution
GHSA-hp6v-6jw7-gv2fCriticalBudibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified
Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified
GHSA-mqhr-6j6h-74p5CriticalBudibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak
Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak