Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
CVE-2026-59222MediumOpen WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials
CVE-2026-59860HighMicrosoft Kiota: XML Doc-Comment Newline Breakout Code Injection
Microsoft Kiota: XML Doc-Comment Newline Breakout Code Injection
GHSA-76q6-2p6h-xjqrLow· 1.8ImageMagick: Heap Buffer Over-Write in X11 import with crafted window title
ImageMagick: Heap Buffer Over-Write in X11 import with crafted window title
GHSA-rjg6-39jm-rgg4Critical· 9.9@better-auth/scim: account takeover and stale access via SCIM provider-id collision
@better-auth/scim: account takeover and stale access via SCIM provider-id collision
GHSA-h3rm-78g3-j7cpHigh· 7.1@better-auth/stripe: cross-organization billing tampering in organization subscription actions
@better-auth/stripe: cross-organization billing tampering in organization subscription actions
GHSA-qq9h-g4jm-xgf3High· 8.3Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
CVE-2026-59861High· 7.5Microsoft Kiota: Code Generation Literal Injection in Kiota Ruby Generator
Microsoft Kiota: Code Generation Literal Injection in Kiota Ruby Generator
CVE-2026-59862High· 7.5Microsoft Kiota: Code Generation Literal Injection in Kiota Python Generator
Microsoft Kiota: Code Generation Literal Injection in Kiota Python Generator
CVE-2026-59859HighMicrosoft Kiota: Code Generation Literal Injection in Kiota PHP Generator
Microsoft Kiota: Code Generation Literal Injection in Kiota PHP Generator
CVE-2026-13769Medium· 5.5AWS CLI: Overly permissive File Permissions
AWS CLI: Overly permissive File Permissions
GHSA-wqjv-9729-c5q2Medium· 5.3SvelteKit: Big remote form function payloads can cause Node process to crash
SvelteKit: Big remote form function payloads can cause Node process to crash
GHSA-866w-xmhq-wj7xMedium· 4.3SvelteKit: Prototype pollution in file input deletion path in remote-function forms
SvelteKit: Prototype pollution in file input deletion path in remote-function forms
CVE-2026-59864CriticalMicrosoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions
Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions
CVE-2026-59867High· 7.1Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
CVE-2026-59863HighMicrosoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
CVE-2026-59865CriticalMicrosoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
CVE-2026-59866HighMicrosoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
CVE-2026-59952MediumValibot: record() issue paths can make flatten() throw for inherited Object property names
Valibot: record() issue paths can make flatten() throw for inherited Object property names
GHSA-p5rm-jg5c-8c77MediumMicrosoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass)
Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass)
GHSA-53g2-mvcc-q9x3Medium· 4.6Trix: Stored XSS via HTMLParser attribute injection on paste
Trix: Stored XSS via HTMLParser attribute injection on paste
CVE-2026-61632Medium· 5.3PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path
PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path
CVE-2026-62343Medium· 4.7ImageMagick: Heap Buffer Over-Write in morphology operation when an invalid kernel is provided
ImageMagick: Heap Buffer Over-Write in morphology operation when an invalid kernel is provided
CVE-2026-62363Medium· 5.0ImageMagick: Heap Buffer Over-Write in fx operation
ImageMagick: Heap Buffer Over-Write in fx operation
CVE-2026-62946Medium· 5.1ImageMagick: Integer Overflow in JNX decoder causes heap buffer over-write when processing extremly large files on 32-bit builds
ImageMagick: Integer Overflow in JNX decoder causes heap buffer over-write when processing extremly large files on 32-bit builds
GHSA-38hq-7x33-php4Medium· 4.7@backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass
@backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass
GHSA-7gfh-x38p-prh3Critical· 9.8Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)
Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)
GHSA-3rp5-jjmw-4wv2High· 7.0GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
GHSA-664h-wqgq-64gwMedium· 6.5Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)
Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)
GHSA-w28w-gp39-m4p6Critical· 10.0Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
GHSA-r28c-9q8g-f849High· 7.5PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure
PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to Arbitrary .map File Disclosure