$ gh advisory list --reviewed
Security advisories
// github advisory database · npm · composer · actions — aggiornato 2026-09-14 12:05 UTC
yayson: Prototype pollution in Store/LegacyStore deserialization
@Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft
@Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)
FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix
Shopper: Missing authorization on product removal actions in CollectionProducts component
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
Shopper: privilege escalation via improper Livewire admin component authorization
Shopping privilege escalation through missing authorization in Settings components
Shopper: Negative discount values accepted and propagated through order calculation pipeline
Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers
@jhb.software/payload-alt-text-plugin: Alt Text Endpoint Authorization Bypass via Payload Local API `overrideAccess` Omission
@argos-ci/core: CI Branch Name OS Command Injection
OmniRoute ACP Custom-Agent Remote Code Execution (RCE)
n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution
n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content
n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints
n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions
n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers
n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service
n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter
n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution
n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket
Angular: SSR XSS via Unescaped <template> Content Across DocumentFragment Boundaries in Fallback Raw-Content Elements
Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSR
Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent`
Angular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compiler
Pimcore: SQL Injection in Custom Reports via Malicious Report Configuration
n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node
n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path
n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint
n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution
@eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name
@openhop/server: Path Traversal in Flow ID File Operations
functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import
@yeger/turbo-graph: Unauthenticated Network-Exposed Task Execution via /api/run
Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients
smol-toml: Denial of Service via malformed TOML documents
n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy
Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain
Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list
Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain
OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree
multer vulnerable to Denial of Service via crafted multipart field names
multer vulnerable to Denial of Service via file descriptor leak on aborted uploads
multer vulnerable to file size limit bypass via async fileFilter race condition
multer vulnerable to Denial of Service via oversized array index in field names
morgan vulnerable to Log Forging via unescaped Unicode line separators
mongodb: Reject "." and NUL bytes in database and collection names
Astro: Remote code execution through AVIF image optimization
Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base
Composer arbitrary command execution via a malicious package's Perforce source URL
sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
phpseclib — non-constant-time X25519 scalar multiplication permits full private-key recovery
Tiptap: Quadratic ReDoS in block and inline Markdown attribute parsing
Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory
Hono: Unbounded dot-notation nesting in `parseBody()` can cause memory exhaustion
Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections
CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver
CakePHP: SmtpTransport vulnerable to CRLF header injection
Laravel Excel writes exports outside the configured filesystem disk when given a caller-controlled path
Grav: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challenge
Grav: Twig sandbox config exfiltration via grav.offsetGet + dump filter (CVE-2026-44738 bypass)
Grav: Decompression Bomb via ZipArchiver - Missing Extraction Limits
Sulu: Stored XSS via media download inline-disposition override
Sulu: Fix authorization bypass when creating preview links
Sulu: Media move/update authorization bypass (IDOR)
Kirby: Access to image files outside of the site root via path traversal in the media handling
Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()
EasyAdmin custom-action dispatcher bypasses access_control on other routes
Livewire DOM-based cross-site scripting during client-side state handling
elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE)
elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connections
TYPO3 CMS - Broken Access Control in Backend and Install Tool
Filament: Multi-factor authentication (app) codes can still be used after a newer code has been used
Filament: Password validity disclosure for accounts denied panel access on login page
Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled
league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension
league/commonmark: Denial of service in the SmartPunct and Attributes extensions
league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed
league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters
Smarty: SSRF via redirect bypass of trusted_uri using {fetch}
Kirby: System path exposure from error messages in the REST API
Kirby: File upload permissions are not checked during processing of chunk data
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback
TYPO3 CMS - Unrestricted File Upload in Form Framework
Snipe-IT has an Improper Privilege Management issue
silverstripe/versioned has XSS in archive admin restore
PrivateBin has reflected JSON injection in backend responses via unescaped REQUEST_URI
PrivateBin has stored Cross-Side-Scripting (XSS) vulnerability in attachment download link via dangerous MIME types with required user-interaction
Pimcore Vulnerable to Remote Code Execution via DataObject Class-Definition Field Name
Pimcore Hotspotimage getDataFromResource() unrestricted Serialize::unserialize over object-store column (PHP Object Injection, CWE-502)
Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation
Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes
Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass
conflibot vulnerable to command injection via crafted pull request branch names under pull_request_target
githubtoplanguages: Command Injection via Issue Title in Discord Notification Workflow
Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration
Setup PHP: GitHub tokens configured by setup-php may be exposed through pinned affected Composer versions
Setup PHP: Command Injection in Repository-Derived PHP Version Resolution
Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses
actions-mkdocs: Command Injection via issue title in internal GitHub Actions workflow
wenxian: Command Injection in GitHub Actions Workflow via `issue_comment.body`
Trivy ecosystem supply chain was briefly compromised
Zen-AI-Pentest has Shell Injection via untrusted issue title in ZenClaw Discord Integration workflow
Egress Policy Bypass via DNS over HTTPS (DoH) in Harden-Runner (Community Tier)
Egress Policy Bypass via DNS over TCP in Harden-Runner (Community Tier)
xygeni-action v5 tag poisoned with C2 backdoor
Black's vulnerable version parsing leads to RCE in GitHub Action
Trivy Action has a script injection via sourced env file in composite action
Super-linter is vulnerable to command injection via crafted filenames in Super-linter Action
Harden-Runner: Bypassing Logging of Outbound Connections Using sendto, sendmsg, and sendmmsg in Harden-Runner (Community Tier)
j178/prek-action vulnerable to arbitrary code injection in composite action
Argument injection vulnerability in SonarQube Scan Action
PyPI publish GitHub Action vulnerable to injectable expression expansions in action steps
Command Injection via sonarqube-scan-action GitHub Action
lychee link checking action affected by arbitrary code injection in composite action
m00nl1ght-dev/steam-workshop-deploy: Exposure of Version-Control Repository to an Unauthorized Control Sphere and Insufficiently Protected Credentials
tj-actions/branch-names has a Command Injection Vulnerability
RageAgainstThePixel/setup-steamcmd leaked authentication token in job output logs
buildalon/setup-steamcmd leaked authentication token in job output logs
Cromwell GitHub Actions Secrets exfiltration via `Issue_comment`
Bullfrog's DNS over TCP bypasses domain filtering
OZI-Project/ozi-publish Code Injection vulnerability
Harden-Runner allows evasion of 'disable-sudo' policy
canonical/get-workflow-version-action can leak a partial GITHUB_TOKEN in exception output
Multiple Reviewdog actions were compromised during a specific time period
tj-actions changed-files through 45.0.7 allows remote attackers to discover secrets by reading actions logs.
GitHub PAT written to debug artifacts
Artifact poisoning vulnerability in action-download-artifact v5 and earlier
Harden-Runner has a command injection weaknesses in `setup.ts` and `arc-runner.ts`
@actions/download-artifact has an Arbitrary File Write via artifact extraction
GitHub Actions Script Injection in `ultralytics/actions`
fish-shop/syntax-check Improper Neutralization of Delimiters
github-slug-action use of `set-env` Runner commands which are processed via stdout
Potential Actions command injection in output filenames (GHSL-2023-275)
tj-actions/changed-files has Potential Actions command injection in output filenames (GHSL-2023-271)
memory overflow vulnerability in OpenEXR-viewer
tj-actions/branch-names's Improper Sanitization of Branch Name Leads to Arbitrary Code Injection
Actions expression injection in `filter-test-configs` (`GHSL-2023-181`)
Data written to GitHub Actions Cache may expose secrets
Arbitrary command injection in embano1/wip
github-slug-action vulnerable to arbitrary code execution
Azure/setup-kubectl: Escalation of privilege vulnerability for v3 and lower
Docker Command Escaping in the GitHub Actions Runner
Nessun risultato per «».