目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

安全情报专区 679 — 搜索: GHSA ×

精选漏洞公告、利用分析、安全博客、GHSA Advisory 等情报来源,已自动清洗 + 中英双语呈现,持续更新。

240
已接入情报源
120
当前稳定在线
1,259
24 小时新增
679+
AI 处理情报
持续监听、清洗、翻译并进行 AI 分析 监听情报
Clear
示例:RCE · SSRF · GHSA · 反序列化
筛选
精品
CVSS 7.8
datamodel-code-generator 代码注入漏洞 GHSA-884-q54q-mmx3
github.com · 2026-07-29

### 漏洞概述 - **漏洞类型**:代码注入 - **漏洞来源**:GraphQL union descriptions 包含回车符(carriage returns) ### 影响范围 - **受影响版本**:0.60.1 - **漏洞编号**:GHSA-884-q54q-mmx3 ### 修复方案 - **修复版本**:0.60.1 - **修复内容**:修复了由 GraphQL unio…

Read more
精品
CVSS 8.8
koxudaxi/datamodel-code-generator 多个代码注入漏洞修复公告 (GHSA)
github.com · 2026-07-29

### 漏洞概述 该网页截图显示了一个名为 `koxudaxi/datamodel-code-generator` 的 GitHub 仓库的发布页面,版本为 0.60.2。在“Security”部分,列出了几个安全漏洞的修复情况。 ### 影响范围 1. **Fixed code injection from schema-provided `default_factory` values** -…

Read more
CVSS 7.5
github-mcp-server 空指针崩溃漏洞 (GHSA-w4q6-qx23-4rg7)
github.com · 2026-07-29

### 漏洞概述 该漏洞涉及 `github-mcp-server` 项目中的一个问题,具体为在处理 `completion/complete` 请求时,如果请求参数缺失或为空,会导致空指针异常(nil pointer dereference),从而引发进程崩溃。此问题已被标记为安全漏洞,并分配了 GHSA 编号:`GHSA-w4q6-qx23-4rg7`。 ### 影响范围 - **本地标准服务…

Read more
精品
CVSS 8.8
Camaleon CMS 认证RCE漏洞(GHSA-7x4w-g9h-r4v9)及PoC
github.com · 2026-07-29

### 漏洞概述 **漏洞名称**: Camaleon CMS - Authenticated RCE via `select_eval` Custom Field **漏洞描述**: - `select_eval` 自定义字段类型在 `field.options[:command]` 中存储任意 Ruby 表达式,并通过 `instance_eval` 在 ERB 视图中执行。 - 在 v2.9…

Read more
CVSS 8.2
Next.js App Router Server Actions DoS漏洞(GHSA-m99w-x7hq-7vf/CVE-2025-6441)
github.com · 2026-07-28

# 漏洞概述 - **漏洞名称**: Denial of Service in App Router using Server Actions - **漏洞编号**: GHSA-m99w-x7hq-7vf - **严重程度**: 8.2 / 10 - **CVSS v4 base metrics**: - **Attack Vector**: Network - **Attack Complexi…

Read more
精品
CVSS 9.1
epa4all VAU服务器认证绕过漏洞(GHSA-vvh7-x6c7-46gh)
github.com · 2026-07-25

# VAU Server Authentication Bypass via Missing A_24624-01 Verification in epa4all ## 漏洞概述 - **漏洞名称**: VAU Server Authentication Bypass via Missing A_24624-01 Verification in epa4all - **漏洞编号**: GHSA-v…

Read more
CVSS 6.3
Jan 0.8.x Trusted Hosts/CORS绕过漏洞 (GHSA-x6p8-7cp8-c3p6)
github.com · 2026-07-25

### 漏洞概述 - **漏洞标题**: fix: enforce Trusted Hosts allowlist when binding 0.0.0.0 (GHSA-x6p8-7cp8-c3p6) - **漏洞编号**: #8506 - **漏洞描述**: 当Jan的本地API服务器绑定到0.0.0.0时,用户配置的`trusted_hosts`被替换为`trusted_hosts`中的`wi…

Read more
CVSS 6.3
Parse Server GraphQL信息泄露漏洞(GHSA-2g9g-4f6f-16rf)
github.com · 2026-07-24

### 漏洞概述 - **漏洞名称**: GraphQL error messages disclose pointer and relation target class names when public introspection is disabled - **漏洞ID**: GHSA-2g9g-4f6f-16rf - **严重程度**: 中等 (6.3 / 10) - **CVSS v4…

Read more
精品
CVSS 10.0
Next.js React Flight 协议远程代码执行漏洞(GHSA-9g9r-h5gf-34mp)
github.com · 2026-07-24

### 漏洞概述 Next.js 存在一个远程代码执行(RCE)漏洞,该漏洞影响使用 React flight 协议的特定 React 包。 ### 影响范围 - **受影响的包**:`next` - **受影响的版本**: - `>= 14.3.0-canary.77, = 15.2.0-canary.0, = 15.3.0-canary.0, = 15.4.0-canary.0, = 16.0…

Read more
CVSS 5.3
Webhook未授权事件注入漏洞修复(GHSA-x82h-9r8v-m672)
github.com · 2026-07-24

### 漏洞概述 - **漏洞名称**: 强制Webhook签名验证(GHSA-x82h-9r8v-m672) - **漏洞类型**: 未授权Webhook事件注入(CWE-306, CVSS 5.3) - **漏洞描述**: 在目标服务器上,当未配置`SignatureValidator`时,失败的Webhook接收器会静默接受未认证的载荷,而不是拒绝它们。 ### 影响范围 - **受影响组件…

Read more
n8n @n8n/computer-use沙盒绕过漏洞(GHSA-fpg6-x68q-5793)公告
github.com · 2026-07-22

### 漏洞概述 - **漏洞名称**: computer-use Shell Sandbox Not Enforced on Linux and Windows - **漏洞编号**: GHSA-fpg6-x68q-5793 - **严重程度**: 中等 (5.5 / 10) - **描述**: 在 `@n8n/computer-use` 包中,沙盒限制仅在 macOS 上应用。在 Linux …

Read more
n8n AI Agents项目查看者权限提升漏洞 (GHSA-x5vx-c2c8-m3w9)
github.com · 2026-07-22

### 漏洞概述 - **漏洞名称**: AI Agents Project Viewer Privilege Escalation via run_node_tool - **漏洞ID**: GHSA-x5vx-c2c8-m3w9 - **严重程度**: 7.2 / 10 (High) - **发布日期**: 2023年10月2日 ### 影响范围 - **受影响版本**: - = 2.30.1…

Read more
CVSS 5.1
n8n GHSA-89gh-3pgc-v5h2 凭证明文泄露漏洞
github.com · 2026-07-22

### 漏洞概述 - **漏洞名称**:Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data - **漏洞编号**:GHSA-89gh-3pgc-v5h2 - **严重程度**:5.1/10(中等) - **发布日期**:2周前 ### 影响范围 - **受影响版本**: - n8n < 1…

Read more
精品
CVSS 8.9
n8n Git节点竞争条件远程代码执行漏洞(GHSA-g3r5-9h93-4j2c)
github.com · 2026-07-22

### 漏洞概述 - **漏洞名称**: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution - **漏洞编号**: GHSA-g3r5-9h93-4j2c - **严重程度**: High (8.9/10) - **发布日期**: 2 weeks ago ### …

Read more
精品
CVSS 8.2
FOGProject未认证RCE致加密凭证擦除(GHSA-95pr-mcrf-x2zg)
github.com · 2026-07-22

### 漏洞概述 **漏洞编号**: GHSA-95pr-mcrf-x2zg **漏洞标题**: 093 Unauthenticated clearAES and clearPMTasks allow remote destruction of host encryption keys and power schedules **漏洞描述**: FOGProject 中的 `clearAES` 和…

Read more
CVSS 7.5
GHSA-wrfp-f35c-j28w: GitHub Actions工作流命令注入漏洞及POC分析
github.com · 2026-07-22

### 漏洞概述 - **漏洞名称**: Command injection in the `test_dispatcher` GitHub Actions workflow - **漏洞ID**: GHSA-wrfp-f35c-j28w - **严重程度**: 高 (7.5 / 10) - **CVSS v3 基础指标**: - 攻击向量: 网络 - 攻击复杂度: 低 - 特权要求: 无 - 用…

Read more
CVSS 4.3
Electric Database隐私信息泄露漏洞(GHSA-c82q-v86f-c87f)及修复指南
github.com · 2026-07-22

### 漏洞概述 - **漏洞名称**: Excluded columns can be inferred via subset where clauses - **漏洞ID**: GHSA-c82q-v86f-c87f - **严重程度**: Low - **CVE ID**: 无已知CVE - **弱点**: CWE-200 - **报告者**: geo-chen ### 影响范围 - **受…

Read more
精品
CVSS 8.8
GHSA-6xj3 跨租户权限提升漏洞分析
github.com · 2026-07-22

# 漏洞总结 ## 漏洞概述 - **漏洞编号**: GHSA-6xj3 - **漏洞类型**: 跨租户权限提升(Cross-tenant privilege escalation) - **严重程度**: 高 - **发现者**: CodeRabbit - **修复状态**: 已修复 ## 影响范围 - 影响平台服务中的以下操作: - 工作区(workspace) - 问题(issue) - 项…

Read more
精品
CVSS 9.8
GHSA- Grav CMS Blueprint::dynamicData() 远程代码执行漏洞
github.com · 2026-07-21

### 漏洞概述 - **漏洞名称**: Remote code execution via unrestricted callable in Blueprint::dynamicData() - **漏洞ID**: GHSA-g2p-q2f-74v5 - **严重程度**: High - **发布日期**: 2 weeks ago - **报告者**: YuvalMi, MathHub25, L…

Read more
精品
CVSS 9.1
RT REST API权限提升与信息泄露漏洞(GHSA-7rx2-x357-wv74)
github.com · 2026-07-21

### 漏洞概述 - **漏洞名称**:Privilege escalation and information disclosure via REST 2.0 user collection endpoint - **漏洞ID**:GHSA-7rx2-x357-wv74 - **发布日期**:2023年5月21日 - **严重程度**:Critical (9.1/10) ### 影响范围 - *…

Read more

每篇文章经过自动 HTML→Markdown 清洗 + LLM 去噪 + 中英双语翻译。原始链接保留在文章末尾。

想看哪个安全博客 / 公告源?邮件告诉我们,每周新接 1-2 个。