Tagged “ghsa”
CVEs tagged ghsa, newest first.
3827 CVEsRSS
CVE-2026-50015High· 7.3pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)
pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)
CVE-2026-53520Medium· 6.5Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing
Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing
CVE-2026-53521Medium· 6.4Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context
Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context
CVE-2026-53519Critical· 9.1PoCNezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key
Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key
CVE-2026-54242Medium· 4.9Statamic Vulnerable to Server-Side Request Forgery via Glide (DNS rebinding)
Statamic Vulnerable to Server-Side Request Forgery via Glide (DNS rebinding)
CVE-2026-54243Medium· 6.1Statamic Vulnerable to CSV formula injection in form submission exports
Statamic Vulnerable to CSV formula injection in form submission exports
CVE-2026-53522Medium· 6.5Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS
Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS
CVE-2026-53523Medium· 6.8Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection
Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection
CVE-2026-54244Low· 3.5Statamic CMS's incorrect authorization lets view-only users submit Live Preview content reserved for editors
Statamic CMS's incorrect authorization lets view-only users submit Live Preview content reserved for editors
CVE-2026-53464Medium· 4.0ImageMagick: Memory Leak in wand option parser when providing invalid arguments
ImageMagick: Memory Leak in wand option parser when providing invalid arguments
CVE-2026-53465Medium· 6.2ImageMagick has a Heap Buffer Over-Write in SF3 encoder when writing multi-frame image
ImageMagick has a Heap Buffer Over-Write in SF3 encoder when writing multi-frame image
CVE-2026-55180Medium· 6.5pnpm: Repository config can expand victim environment secrets into registry requests before scripts run
pnpm: Repository config can expand victim environment secrets into registry requests before scripts run
CVE-2026-55487High· 7.5pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle
pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle
CVE-2026-55697High· 7.5pnpm: Repository-controlled configDependencies can select a pacquet native install engine
pnpm: Repository-controlled configDependencies can select a pacquet native install engine
CVE-2026-49340High· 8.1gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host
gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host
CVE-2026-49339High· 7.1gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists
gonic: Path Traversal in playlist `id` bypasses ownership check, enabling any user to read/delete other users' playlists
CVE-2026-49338High· 7.1Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)
Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)
CVE-2026-55698High· 8.8pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes
pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes
CVE-2026-55699Medium· 6.5pnpm: Reserved bin name deletes PNPM_HOME during global remove
pnpm: Reserved bin name deletes PNPM_HOME during global remove
CVE-2026-55700High· 7.1pnpm: `stage download` writes outside its destination directory via manifest name/version traversal
pnpm: `stage download` writes outside its destination directory via manifest name/version traversal
GHSA-ww5p-j6cj-6mqqMediumNezha Dashboard: DDNS and Notification credential exposure via unredacted list API
Nezha Dashboard: DDNS and Notification credential exposure via unredacted list API
CVE-2026-53462Medium· 5.9ImageMagick has a Use-After-Free when allocation in CheckPrimitiveExtent fails
ImageMagick has a Use-After-Free when allocation in CheckPrimitiveExtent fails
CVE-2026-44024Critical· 9.8PoCFluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
Fluentd is Vulnerable to Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder
CVE-2026-44025High· 7.5Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
Fluentd is Vulnerable to Exposure of Sensitive Information via Monitor Agent API
CVE-2026-44160High· 7.5Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
Fluentd is Vulnerable to Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`
CVE-2026-44161High· 7.2Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
Fluentd is Vulnerable to Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`
CVE-2026-46406Medium@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write
@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write
CVE-2026-46560High· 7.5OpenAM: Unauthenticated Authentication Bypass via RADIUS Spoofing
OpenAM: Unauthenticated Authentication Bypass via RADIUS Spoofing
CVE-2026-48714Critical· 9.1i18next-http-middleware: MissingKeyHandler does not reject keys whose segments contain prototype-polluting names
i18next-http-middleware: MissingKeyHandler does not reject keys whose segments contain prototype-polluting names
CVE-2026-48713Critical· 9.1i18next-fs-backend vulnerable to prototype pollution via crafted missing-key string
i18next-fs-backend vulnerable to prototype pollution via crafted missing-key string