VulnSea

Tagged “ghsa”

CVEs tagged ghsa, newest first.

3827 CVEsRSS

CVE-2026-55075High· 7.4
2mo ago

Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass

Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass

▾ Twilightcoder · github.com/coder/coder/v2EPSS 0.48%via GHSA
CVE-2026-55077High· 7.2
2mo ago

Coder: User-admin role can reset owner account password

Coder: User-admin role can reset owner account password

▾ Twilightcoder · github.com/coder/coder/v2EPSS 0.61%via GHSA
CVE-2026-55427High· 8.3
2mo ago

Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`

Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`

▾ Twilightcoder · github.com/coder/coder/v2EPSS 0.47%via GHSA
CVE-2026-55079Medium· 4.9
2mo ago

Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service

Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service

▾ Sunlitcoder · github.com/coder/coder/v2EPSS 0.61%via GHSA
CVE-2026-55429High· 8.7
2mo ago

Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID

Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID

▾ Twilightcoder · github.com/coder/coder/v2EPSS 0.51%via GHSA
CVE-2026-55428High· 8.2
2mo ago

Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator

Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator

▾ Twilightcoder · github.com/coder/coder/v2EPSS 0.40%via GHSA
CVE-2026-55430Medium· 5.8
2mo ago

Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access

Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access

▾ Sunlitcoder · github.com/coder/coder/v2EPSS 0.21%via GHSA
CVE-2026-55078Medium· 6.5
2mo ago

Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service

Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service

▾ Sunlitcoder · github.com/coder/coder/v2EPSS 0.60%via GHSA
CVE-2026-55431High· 7.7
2mo ago

Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps

Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps

▾ Twilightcoder · github.com/coder/coder/v2EPSS 0.34%via GHSA
CVE-2026-55432Medium· 5.4
2mo ago

Coder's sub-agent app registration bypasses template port-sharing policy enforcement

Coder's sub-agent app registration bypasses template port-sharing policy enforcement

▾ Sunlitcoder · github.com/coder/coder/v2EPSS 0.32%via GHSA
CVE-2026-55433Medium· 5.4
2mo ago

Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers

Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers

▾ Sunlitcoder · github.com/coder/coder/v2EPSS 0.39%via GHSA
CVE-2026-55434Medium· 6.5
2mo ago

Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints

Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints

▾ Sunlitcoder · github.com/coder/coder/v2EPSS 0.55%via GHSA
CVE-2026-55435Medium· 5.4
2mo ago

Suspended Coder users retain access to AI Bridge LLM proxy endpoints

Suspended Coder users retain access to AI Bridge LLM proxy endpoints

▾ Sunlitcoder · github.com/coder/coder/v2EPSS 0.32%via GHSA
CVE-2026-55436High· 7.4
2mo ago

Coder's AI Bridge Proxy skips TLS certificate verification in default configuration

Coder's AI Bridge Proxy skips TLS certificate verification in default configuration

▾ Twilightcoder · github.com/coder/coder/v2EPSS 0.26%via GHSA
CVE-2026-55437Medium· 5.4
2mo ago

Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component

Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component

▾ Sunlitcoder · github.com/coder/coder/v2EPSS 0.32%via GHSA
CVE-2026-55438Medium· 5.8
2mo ago

Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing

Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing

▾ Sunlitcoder · github.com/coder/coder/v2EPSS 0.22%via GHSA
GHSA-vjc7-jrh9-9j86Critical· 10.0
2mo ago

9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats

9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats

▾ Midnight9router · 9routervia GHSA
CVE-2026-55615Critical
2mo ago

Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879

Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879

▾ Midnightlangroid · langroidEPSS 0.46%via GHSA
CVE-2026-54496Critical· 9.3
2mo ago

Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness

Zebra: Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness

▾ Midnightzebrad · zebradEPSS 0.32%via GHSA
CVE-2026-55790High
2mo ago

Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget

Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget

▾ Twilightcraftcms · craftcms/cmsEPSS 0.46%via GHSA
CVE-2026-55792Medium
2mo ago

Craft CMS: Sensitive File Disclosure / Server-Side File Read

Craft CMS: Sensitive File Disclosure / Server-Side File Read

▾ Sunlitcraftcms · craftcms/cmsEPSS 0.40%via GHSA
CVE-2026-55793Medium
2mo ago

Craft CMS: Stored XSS via Structure entry title in table view

Craft CMS: Stored XSS via Structure entry title in table view

▾ Sunlitcraftcms · craftcms/cmsEPSS 0.41%via GHSA
CVE-2026-55794High
2mo ago

Craft CMS: Potential authenticated Remote Code Execution via referrer redirect

Craft CMS: Potential authenticated Remote Code Execution via referrer redirect

▾ Twilightcraftcms · craftcms/cmsEPSS 0.41%via GHSA
CVE-2026-55500Critical· 9.9
2mo ago

9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover

9routers has Exposure of Sensitive Information and Unprotected Database Import/Export, Allowing Complete Credential Theft and Database Takeover

▾ Midnight9router · 9routerEPSS 0.69%via GHSA
CVE-2026-35342Low· 3.3
2mo ago

mktemp: empty TMPDIR creates temp files in CWD instead of /tmp

mktemp: empty TMPDIR creates temp files in CWD instead of /tmp

▾ Sunlituu_mktemp · uu_mktempEPSS 0.15%via GHSA
CVE-2026-35346Low· 3.3
2mo ago

comm: lossy UTF-8 conversion silently corrupts non-UTF-8 output

comm: lossy UTF-8 conversion silently corrupts non-UTF-8 output

▾ Sunlituu_comm · uu_commEPSS 0.17%via GHSA
CVE-2026-35373Low· 3.3
2mo ago

ln: rejects non-UTF-8 source filenames in target-directory mode

ln: rejects non-UTF-8 source filenames in target-directory mode

▾ Sunlituu_ln · uu_lnEPSS 0.14%via GHSA
CVE-2026-35355Medium· 6.3
2mo ago

install: TOCTOU symlink race (unlink-then-create without O_EXCL) allows arbitrary file overwrite

install: TOCTOU symlink race (unlink-then-create without O_EXCL) allows arbitrary file overwrite

▾ Sunlituu_install · uu_installEPSS 0.11%via GHSA
CVE-2026-35343Low· 3.3
2mo ago

cut: -s (only-delimited) ignored when delimiter is a newline

cut: -s (only-delimited) ignored when delimiter is a newline

▾ Sunlituu_cut · uu_cutEPSS 0.15%via GHSA
CVE-2026-35356Medium· 6.3
2mo ago

install -D: symlink race in directory creation allows arbitrary file overwrite

install -D: symlink race in directory creation allows arbitrary file overwrite

▾ Sunlituu_install · uu_installEPSS 0.11%via GHSA
CVEs tagged “ghsa” — page 83 · VulnSea