$ gh advisory list --reviewed
Security advisories
// github advisory database · npm · composer · actions — aggiornato 2026-08-14 07:26 UTC
Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS
hashi-vault-js: Vault token and secret values exposed in thrown errors
ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token
ep_etherpad-lite: Import/export uses Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwrite
ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header
Pimcore: ClassDefinition UID regex missing end anchor allows SQL injection via Block.php unquoted table name
phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumeration
LibreNMS: Reflected XSS via Proxmox instance/vmid GET parameters injected into document.title JavaScript assignment
Winter: Authenticated backend users can bypass Users controller permission checks
Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and unauthorized asset uploads
Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax
Winter: Stored XSS through Editor Settings custom styles
Winter: Stored XSS through Brand Settings custom styles
Duplicate Advisory: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure
Hono: Proxy Helper does not remove response headers listed in the `Connection` header
Hono: Algorithmic Complexity DoS in Language Middleware
CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules
CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames
CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions
CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure()
jsii-diff: Command Injection via npm: package argument
API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion)
SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header
Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS
Smarty Security stream restriction bypass through stream: resource
Smarty: Symlink path traversal out of trusted directories
Craft CMS: Passkey login accepts replayed WebAuthn assertions
Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts
Craft CMS: Authenticated leak of secret environment variables
Craft CMS:Authorization bypass: view-only Categories user can modify category structure via structures/move-element
Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics
Craft CMS: Incorrect path validation could potentially lead to path traversal
Craft CMS: Stored XSS in the control panel via unescaped draft name
PHP_CodeSniffer gitblame report command injection via crafted filename
node-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending in a truncated multi-byte UTF-8 character → adjacent heap memory disclosed to JavaScript
node-re2: String.prototype.replace(re2, template) aborts the Node process (uncatchable ToLocalChecked on empty MaybeLocal) when the result exceeds V8's max string length
ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633
PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF
Craft CMS: Arbitrary user password reset leading to administrator account takeover
Craft CMS: Authenticated RCE through Twig sandbox escape
Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets
Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass
league/commonmark: Denial of service via deeply nested XML output
league/commonmark: Denial of service via colliding heading slugs
league/commonmark: Denial of service via duplicate footnote definitions
league/commonmark: Denial of service via adjacent inline attribute blocks
league/commonmark: Quadratic-time denial of service when parsing crafted Markdown
league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes
JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported
Silverstripe: XSS in breadcrumbs in page list view
Nx: Zip-Slip in the self-hosted remote cache
Mermaid radar diagrams are vulnerable to DoS
Mermaid configuration APIs allow prototype pollution
Mermaid allows CSS injection applying to sibling elements of the diagram
Mermaid Architecture diagrams are vulnerable to prototype pollution
Contao: Possible path traversal in job download URIs
Mermaid XY Charts are vulnerable to an infinite loop DoS
Contao crawler leaks auth credentials to external hosts
Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template
Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types
Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries
Statamic: Unsafe method invocation via Antlers template resolution allows data destruction
Statamic: Account takeover via OAuth email matching without email-verification check
Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence
Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation
Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host
Nuxt: Unauthorized Component Instantiation via Server Island Props
Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients
Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)
Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering
Electron: Sandboxed iframes can launch external protocol handlers
Electron: DevTools embedder handler executes arbitrary files via shell open
Electron: contextBridge object copy honors prototype setters
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter
Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path
Electron: window.open features string controls some window options considered privileged
Electron: ProtocolResponse.url reuses the default session cache instead of the registering session
Electron: HTTP redirect followed into local file loader
Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads
Electron: Extension tab APIs operate across session boundaries
Electron: shell.openPath path validation bypass via embedded null byte
Electron: Context isolation bypass via Function.prototype.bind hijack
Electron: Cross-origin iframe can position native autofill popup
Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin
Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size
Electron: Parent process code-sign check is spoofable
Ghost Content API filter bypass reveals private fields
Ghost: Cross-Site Scripting in Feature Image Captions
Guzzle: Noncanonical host can bypass host-based checks
Guzzle: Noncanonical cookie domain keeps subdomain scope
Duplicate Advisory: Guzzle: Host-only cookie scope is not preserved
Duplicate Advisory: Guzzle: URI fragments disclosed in redirect Referer headers
Duplicate Advisory: Guzzle: Unbounded response cookies risk denial of service
Duplicate Advisory: Guzzle: Proxy-Authorization headers can be sent to origin servers
WPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that leaks user existence + profile (defeats explicit anti-enumeration design)
Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers
githubtoplanguages: Command Injection via Issue Title in Discord Notification Workflow
Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration
Setup PHP: GitHub tokens configured by setup-php may be exposed through pinned affected Composer versions
Setup PHP: Command Injection in Repository-Derived PHP Version Resolution
Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses
actions-mkdocs: Command Injection via issue title in internal GitHub Actions workflow
wenxian: Command Injection in GitHub Actions Workflow via `issue_comment.body`
Trivy ecosystem supply chain was briefly compromised
Zen-AI-Pentest has Shell Injection via untrusted issue title in ZenClaw Discord Integration workflow
Egress Policy Bypass via DNS over HTTPS (DoH) in Harden-Runner (Community Tier)
Egress Policy Bypass via DNS over TCP in Harden-Runner (Community Tier)
xygeni-action v5 tag poisoned with C2 backdoor
Black's vulnerable version parsing leads to RCE in GitHub Action
Trivy Action has a script injection via sourced env file in composite action
Super-linter is vulnerable to command injection via crafted filenames in Super-linter Action
Harden-Runner: Bypassing Logging of Outbound Connections Using sendto, sendmsg, and sendmmsg in Harden-Runner (Community Tier)
j178/prek-action vulnerable to arbitrary code injection in composite action
Argument injection vulnerability in SonarQube Scan Action
PyPI publish GitHub Action vulnerable to injectable expression expansions in action steps
Command Injection via sonarqube-scan-action GitHub Action
lychee link checking action affected by arbitrary code injection in composite action
m00nl1ght-dev/steam-workshop-deploy: Exposure of Version-Control Repository to an Unauthorized Control Sphere and Insufficiently Protected Credentials
tj-actions/branch-names has a Command Injection Vulnerability
RageAgainstThePixel/setup-steamcmd leaked authentication token in job output logs
buildalon/setup-steamcmd leaked authentication token in job output logs
Cromwell GitHub Actions Secrets exfiltration via `Issue_comment`
Bullfrog's DNS over TCP bypasses domain filtering
OZI-Project/ozi-publish Code Injection vulnerability
Harden-Runner allows evasion of 'disable-sudo' policy
canonical/get-workflow-version-action can leak a partial GITHUB_TOKEN in exception output
Multiple Reviewdog actions were compromised during a specific time period
tj-actions changed-files through 45.0.7 allows remote attackers to discover secrets by reading actions logs.
GitHub PAT written to debug artifacts
Artifact poisoning vulnerability in action-download-artifact v5 and earlier
Harden-Runner has a command injection weaknesses in `setup.ts` and `arc-runner.ts`
@actions/download-artifact has an Arbitrary File Write via artifact extraction
GitHub Actions Script Injection in `ultralytics/actions`
fish-shop/syntax-check Improper Neutralization of Delimiters
github-slug-action use of `set-env` Runner commands which are processed via stdout
Potential Actions command injection in output filenames (GHSL-2023-275)
tj-actions/changed-files has Potential Actions command injection in output filenames (GHSL-2023-271)
memory overflow vulnerability in OpenEXR-viewer
tj-actions/branch-names's Improper Sanitization of Branch Name Leads to Arbitrary Code Injection
Actions expression injection in `filter-test-configs` (`GHSL-2023-181`)
Data written to GitHub Actions Cache may expose secrets
Arbitrary command injection in embano1/wip
github-slug-action vulnerable to arbitrary code execution
Azure/setup-kubectl: Escalation of privilege vulnerability for v3 and lower
Docker Command Escaping in the GitHub Actions Runner
run-terraform allows for RCE via terraform plan
Nessun risultato per «».