VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

GHSA-86cx-wwf4-phq4Medium· 6.5
2mo ago

OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API

OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API

▾ SunlitOpenListTeam · github.com/OpenListTeam/OpenList/v4via GHSA
CVE-2026-16584High· 7.0
2mo ago

AWS API MCP Server Security Policy Bypass via Startup Initialization Failure

AWS API MCP Server Security Policy Bypass via Startup Initialization Failure

▾ Twilightawslabs.aws-api-mcp-server · awslabs.aws-api-mcp-serverEPSS 0.23%via GHSA
GHSA-6v4m-fw66-8r4xMedium
2mo ago

Shescape: Path disclosure on Unix with Zsh

Shescape: Path disclosure on Unix with Zsh

▾ Sunlitshescape · shescapevia GHSA
GHSA-w4hw-qcx7-56prCritical
2mo ago

Shescape: Shell injection via unescaped parentheses on Windows with CMD

Shescape: Shell injection via unescaped parentheses on Windows with CMD

▾ Midnightshescape · shescapevia GHSA
GHSA-q53c-4prm-w95qMedium
2mo ago

Shescape: Home-directory disclosure in assignment context on Unix with Dash

Shescape: Home-directory disclosure in assignment context on Unix with Dash

▾ Sunlitshescape · shescapevia GHSA
GHSA-gm3r-q2wp-hw87High
2mo ago

Shescape: Quadratic-time denial of service in the flag-protection

Shescape: Quadratic-time denial of service in the flag-protection

▾ Twilightshescape · shescapevia GHSA
GHSA-fp43-vj7g-pg92High· 7.5
2mo ago

OmniFaces: Forged combined-resource IDs and related output/push boundaries

OmniFaces: Forged combined-resource IDs and related output/push boundaries

▾ Twilightomnifaces · org.omnifaces:omnifacesvia GHSA
GHSA-fwjx-9p69-h25hMedium· 6.1
2mo ago

Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data

Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data

▾ Sunlitjandedobbeleer · github.com/jandedobbeleer/oh-my-poshvia GHSA
GHSA-6xj8-qv9j-xcjqHigh· 7.8
2mo ago

Oh My Posh: Arbitrary command execution via template injection in the path segment

Oh My Posh: Arbitrary command execution via template injection in the path segment

▾ Twilightjandedobbeleer · github.com/jandedobbeleer/oh-my-poshvia GHSA
GHSA-3r53-75j5-3g7jMedium· 5.6
2mo ago

Quasar: Prototype pollution in the extend() utility

Quasar: Prototype pollution in the extend() utility

▾ Sunlitquasar · quasarvia GHSA
GHSA-hmj8-5xmh-5573High· 7.5
2mo ago

libp2p: yamux connection DoS via oversized data frame

libp2p: yamux connection DoS via oversized data frame

▾ Twilightlibp2p · libp2pvia GHSA
CVE-2026-16756High· 7.5
2mo ago

Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service

Smithy-RS: Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service

▾ Twilightaws-smithy-http-server · aws-smithy-http-serverEPSS 0.75%via GHSA
GHSA-xg4h-6gfc-h4m8High
2mo ago

etcd: Watch API authorization bypass via open-ended range requests

etcd: Watch API authorization bypass via open-ended range requests

▾ Twilightetcd · go.etcd.io/etcd/v3via GHSA
CVE-2026-16796High· 7.3
2mo ago

AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()

AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()

▾ Twilightbedrock-agentcore · bedrock-agentcoreEPSS 0.73%via GHSA
CVE-2026-59223Medium· 4.3
2mo ago

Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching

Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching

▾ Sunlitopen-webui · open-webuiEPSS 0.38%via GHSA
CVE-2026-59224High· 8.0
2mo ago

Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)

Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)

▾ Twilightopen-webui · open-webuiEPSS 0.39%via GHSA
CVE-2026-59212Medium· 5.4
2mo ago

Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete

Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete

▾ Sunlitopen-webui · open-webuiEPSS 0.42%via GHSA
CVE-2026-59225Medium· 5.4
2mo ago

Open WebUI: Arena task endpoints can bypass underlying model access controls

Open WebUI: Arena task endpoints can bypass underlying model access controls

▾ Sunlitopen-webui · open-webuiEPSS 0.37%via GHSA
CVE-2026-59221High· 7.7
2mo ago

open-webui terminal proxy path traversal guard bypass via 9x encoded traversal

open-webui terminal proxy path traversal guard bypass via 9x encoded traversal

▾ Twilightopen-webui · open-webuiEPSS 0.48%via GHSA
CVE-2026-44907High· 7.5
2mo ago

react-server-dom: Denial of Service in Server Functions

react-server-dom: Denial of Service in Server Functions

▾ Twilightreact-server-dom-webpack · react-server-dom-webpackEPSS 0.60%via GHSA
GHSA-j9fc-w3mr-x6mvHigh· 8.8
2mo ago

Budibase: Privilege escalation via public role assignment API missing app-level authorization

Budibase: Privilege escalation via public role assignment API missing app-level authorization

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-4qcj-m5wp-jmf4Medium· 4.3
2mo ago

Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings

Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings

▾ Sunlitbudibase · @budibase/servervia GHSA
GHSA-fcrw-f7gg-6g9fMedium· 4.9
2mo ago

Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users

Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users

▾ Sunlitbudibase · @budibase/servervia GHSA
GHSA-c8vc-7pv3-g98pHigh
2mo ago

Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)

Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-q6x4-v3qx-85qwCritical· 9.6
2mo ago

Budibase: SQL Injection via `multipleStatements: true`

Budibase: SQL Injection via `multipleStatements: true`

▾ Midnightbudibase · @budibase/servervia GHSA
GHSA-ppr4-5f46-j9c6High
2mo ago

Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile

Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-xcx6-4f2g-hhgxHigh· 7.7
2mo ago

Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs

Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-xg5g-26x8-cvf4High· 8.5
2mo ago

Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution

Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution

▾ Twilightbudibase · @budibase/servervia GHSA
GHSA-hp6v-6jw7-gv2fCritical
2mo ago

Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified

Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified

▾ Midnightbudibase · @budibase/servervia GHSA
GHSA-mqhr-6j6h-74p5Critical
2mo ago

Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak

Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak

▾ Midnightbudibase · @budibase/servervia GHSA
CVEs tagged “ghsa” — page 64 · VulnSea