Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

59 advisories

Loading
elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connections Moderate
CVE-2026-81890 was published for studio-42/elfinder (Composer) Sep 2, 2026
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
arc has unauthenticated cluster node admission when `cluster.shared_secret` is unset Moderate
CVE-2026-55678 was published for github.com/basekick-labs/arc (Go) Aug 28, 2026
sondt99 Credited to sondt99
YOURLS has stored XSS in referrer statistics chart via crafted Referer header High
CVE-2026-63135 was published for yourls/yourls (Composer) Aug 21, 2026
sondt99 Credited to sondt99, dgw, ozh, and LeoColomb dgw dgw
ozh ozh LeoColomb LeoColomb
netty-incubator-codec-ohttp: Binary HTTP parser infinite loop on known-length field section boundary High
CVE-2026-63124 was published for io.netty.incubator:netty-incubator-codec-bhttp (Maven) Aug 20, 2026
sondt99 Credited to sondt99 and VuiVeIshere VuiVeIshere VuiVeIshere
netty-incubator-codec-ohttp: Binary HTTP parser unchecked varint length overflow causes decoder crash Moderate
CVE-2026-61799 was published for io.netty.incubator:netty-incubator-codec-bhttp (Maven) Aug 20, 2026
sondt99 Credited to sondt99
netty-incubator-codec-ohttp: BoringSSL HPKE private key bytes exposed through toString() and exception messages High
CVE-2026-61798 was published for io.netty.incubator:netty-incubator-codec-ohttp-hpke-classes-boringssl (Maven) Aug 20, 2026
sondt99 Credited to sondt99
NocoBase backup restore schema name allows command injection Moderate
CVE-2026-55410 was published for @nocobase/plugin-backups (npm) Aug 20, 2026
sondt99 Credited to sondt99
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API Moderate
CVE-2026-69160 was published for github.com/OpenListTeam/OpenList/v4 (Go) Jul 24, 2026
cns1rius Credited to cns1rius, xrgzs, jyxjjj, and sondt99 xrgzs xrgzs
jyxjjj jyxjjj sondt99 sondt99
MagicMirror socket payload secret placeholder expansion can disclose SECRET_* environment variables Moderate
CVE-2026-63640 was published for magicmirror (npm) Aug 18, 2026
sondt99 Credited to sondt99
sondt99 Credited to sondt99
OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversal High
CVE-2026-73509 was published for github.com/OpenListTeam/OpenList/v4 (Go) Jul 24, 2026
sondt99 Credited to sondt99, jyxjjj, and xrgzs jyxjjj jyxjjj
xrgzs xrgzs
Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint High
CVE-2026-73406 was published for @budibase/server (npm) Jul 24, 2026
sondt99 Credited to sondt99
OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files Moderate
CVE-2026-54706 was published for onionshare-cli (pip) Jul 31, 2026
sondt99 Credited to sondt99
OnionShare Receive mode writes uploaded files even when file uploads are disabled Moderate
CVE-2026-54707 was published for onionshare-cli (pip) Jul 31, 2026
sondt99 Credited to sondt99
Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens Moderate
CVE-2026-49447 was published for github.com/azukaar/cosmos-server (Go) Jul 28, 2026
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
PHPSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion High
CVE-2026-59933 was published for phpoffice/phpspreadsheet (Composer) Jul 23, 2026
sondt99 Credited to sondt99
PHPSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion High
CVE-2026-59932 was published for phpoffice/phpspreadsheet (Composer) Jul 23, 2026
sondt99 Credited to sondt99
PHPSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist High
CVE-2026-59931 was published for phpoffice/phpspreadsheet (Composer) Jul 23, 2026
longcalif Credited to longcalif and sondt99 sondt99 sondt99
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
PraisonAI: Arbitrary File Read/Write via `multiedit` Tool Without Path Validation Critical
CVE-2026-57145 was published for praisonai (pip) Jun 18, 2026
sondt99 Credited to sondt99
PraisonAI: Remote Code Execution via Sandbox Escape in `codeMode` Tool Critical
CVE-2026-57141 was published for praisonai (npm) Jun 18, 2026
sondt99 Credited to sondt99
PraisonAI: IMAP Command Injection via Unsanitized Email Search Parameters High
CVE-2026-57130 was published for praisonaiagents (pip) Jun 18, 2026
sondt99 Credited to sondt99
PraisonAI: Arbitrary File Read via `@file:` Mention Path Traversal High
CVE-2026-57129 was published for praisonaiagents (pip) Jun 18, 2026
sondt99 Credited to sondt99
PraisonAI: Unauthenticated Event Injection via SSE `/publish` Endpoint Moderate
CVE-2026-57128 was published for praisonaiagents (pip) Jun 18, 2026
sondt99 Credited to sondt99
Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise Critical
CVE-2026-55579 was published for pheditor/pheditor (Composer) Jul 16, 2026
sondt99 Credited to sondt99
ProTip! Advisories are also available from the GraphQL API