VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2026-59222Medium
2mo ago

Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials

Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials

▾ Sunlitopen-webui · open-webuiEPSS 0.46%via GHSA
CVE-2026-59860High
2mo ago

Microsoft Kiota: XML Doc-Comment Newline Breakout Code Injection

Microsoft Kiota: XML Doc-Comment Newline Breakout Code Injection

▾ TwilightMicrosoft · Microsoft.OpenApi.KiotaEPSS 1.4%via GHSA
GHSA-76q6-2p6h-xjqrLow· 1.8
2mo ago

ImageMagick: Heap Buffer Over-Write in X11 import with crafted window title

ImageMagick: Heap Buffer Over-Write in X11 import with crafted window title

▾ SunlitMagick · Magick.NET-Q16-AnyCPUvia GHSA
GHSA-rjg6-39jm-rgg4Critical· 9.9
2mo ago

@better-auth/scim: account takeover and stale access via SCIM provider-id collision

@better-auth/scim: account takeover and stale access via SCIM provider-id collision

▾ Midnightbetter-auth · @better-auth/scimvia GHSA
GHSA-h3rm-78g3-j7cpHigh· 7.1
2mo ago

@better-auth/stripe: cross-organization billing tampering in organization subscription actions

@better-auth/stripe: cross-organization billing tampering in organization subscription actions

▾ Twilightbetter-auth · @better-auth/stripevia GHSA
GHSA-qq9h-g4jm-xgf3High· 8.3
2mo ago

Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in

Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in

▾ Twilightbetter-auth · better-authvia GHSA
CVE-2026-59861High· 7.5
2mo ago

Microsoft Kiota: Code Generation Literal Injection in Kiota Ruby Generator

Microsoft Kiota: Code Generation Literal Injection in Kiota Ruby Generator

▾ TwilightMicrosoft · Microsoft.OpenAPI.KiotaEPSS 2.0%via GHSA
CVE-2026-59862High· 7.5
2mo ago

Microsoft Kiota: Code Generation Literal Injection in Kiota Python Generator

Microsoft Kiota: Code Generation Literal Injection in Kiota Python Generator

▾ TwilightMicrosoft · Microsoft.OpenAPI.KiotaEPSS 1.4%via GHSA
CVE-2026-59859High
2mo ago

Microsoft Kiota: Code Generation Literal Injection in Kiota PHP Generator

Microsoft Kiota: Code Generation Literal Injection in Kiota PHP Generator

▾ TwilightMicrosoft · Microsoft.OpenApi.KiotaEPSS 1.4%via GHSA
CVE-2026-13769Medium· 5.5
2mo ago

AWS CLI: Overly permissive File Permissions

AWS CLI: Overly permissive File Permissions

▾ Sunlitawscli · awscliEPSS 0.16%via OSV
GHSA-wqjv-9729-c5q2Medium· 5.3
2mo ago

SvelteKit: Big remote form function payloads can cause Node process to crash

SvelteKit: Big remote form function payloads can cause Node process to crash

▾ Sunlitsveltejs · @sveltejs/kitvia GHSA
GHSA-866w-xmhq-wj7xMedium· 4.3
2mo ago

SvelteKit: Prototype pollution in file input deletion path in remote-function forms

SvelteKit: Prototype pollution in file input deletion path in remote-function forms

▾ Sunlitsveltejs · @sveltejs/kitvia GHSA
CVE-2026-59864Critical
2mo ago

Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions

Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions

▾ MidnightMicrosoft · Microsoft.OpenApi.KiotaEPSS 1.3%via GHSA
CVE-2026-59867High· 7.1
2mo ago

Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref

Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref

▾ TwilightMicrosoft · Microsoft.OpenApi.KiotaEPSS 2.4%via GHSA
CVE-2026-59863High
2mo ago

Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF

Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF

▾ TwilightMicrosoft · Microsoft.OpenApi.KiotaEPSS 1.4%via GHSA
CVE-2026-59865Critical
2mo ago

Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`

Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`

▾ MidnightMicrosoft · Microsoft.OpenApi.KiotaEPSS 4.4%via GHSA
CVE-2026-59866High
2mo ago

Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName

Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName

▾ TwilightMicrosoft · Microsoft.OpenApi.KiotaEPSS 1.4%via GHSA
CVE-2026-59952Medium
2mo ago

Valibot: record() issue paths can make flatten() throw for inherited Object property names

Valibot: record() issue paths can make flatten() throw for inherited Object property names

▾ Sunlitvalibot · valibotEPSS 0.52%via GHSA
GHSA-p5rm-jg5c-8c77Medium
2mo ago

Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass)

Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass)

▾ SunlitMicrosoft · Microsoft.OpenApi.Kiotavia GHSA
GHSA-53g2-mvcc-q9x3Medium· 4.6
2mo ago

Trix: Stored XSS via HTMLParser attribute injection on paste

Trix: Stored XSS via HTMLParser attribute injection on paste

▾ Sunlittrix · trixvia GHSA
CVE-2026-61632Medium· 5.3
2mo ago

PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path

PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path

▾ Sunlitpymdown-extensions · pymdown-extensionsEPSS 0.40%via OSV
CVE-2026-62343Medium· 4.7
2mo ago

ImageMagick: Heap Buffer Over-Write in morphology operation when an invalid kernel is provided

ImageMagick: Heap Buffer Over-Write in morphology operation when an invalid kernel is provided

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.12%via GHSA
CVE-2026-62363Medium· 5.0
2mo ago

ImageMagick: Heap Buffer Over-Write in fx operation

ImageMagick: Heap Buffer Over-Write in fx operation

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.13%via GHSA
CVE-2026-62946Medium· 5.1
2mo ago

ImageMagick: Integer Overflow in JNX decoder causes heap buffer over-write when processing extremly large files on 32-bit builds

ImageMagick: Integer Overflow in JNX decoder causes heap buffer over-write when processing extremly large files on 32-bit builds

▾ SunlitMagick · Magick.NET-Q16-AnyCPUEPSS 0.12%via GHSA
GHSA-38hq-7x33-php4Medium· 4.7
2mo ago

@backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass

@backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass

▾ Sunlitbackstage · @backstage/plugin-auth-backendvia GHSA
GHSA-7gfh-x38p-prh3Critical· 9.8
2mo ago

Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)

Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)

▾ Midnightvelocityjs · velocityjsvia GHSA
GHSA-3rp5-jjmw-4wv2High· 7.0
2mo ago

GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)

GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)

▾ Twilightgitpython · gitpythonvia GHSA
GHSA-664h-wqgq-64gwMedium· 6.5
2mo ago

Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)

Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)

▾ Sunlitmongoose · mongoosevia GHSA
GHSA-w28w-gp39-m4p6Critical· 10.0
2mo ago

Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer

Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer

▾ Midnightprompty · @prompty/corevia GHSA
GHSA-r28c-9q8g-f849High· 7.5
2mo ago

PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure

PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure

▾ Twilightpostcss · postcssvia GHSA
CVEs tagged “ghsa” — page 66 · VulnSea