Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Security Intel Hub 644— Search: GHSA×

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Clear
Examples: RCE · SSRF · GHSA · log4j
Filter
CVSS 8.2
PasswordPusher data: URI Redirect-Based XSS via Trusted Domain (GHSA-76c2-66gp-6f2f)
github.com · 2026-07-09

# Vulnerability Overview - **Vulnerability Name**: data: URI Scheme Accepted as URL Push Payload Enables Redirect-Based XSS via Trusted Domain - **Vulnerability ID**: GHSA-76c2-66gp-6f2f - **Severity*…

Read more
LiteLLM Custom Code Guardrails Production Endpoints Bypass (CVE-2024-59821)
github.com · 2026-07-09

### Vulnerability Overview - **Vulnerability Name**: Custom Code Guardrails production endpoints bypass code safety checks - **Vulnerability ID**: GHSA-72mb-9m7m-h278 - **Severity**: Low (2.1 / 10) - …

Read more
CVSS 6.8
Midscene Bridge Server CSWSH and Authenticated DoS Vulnerability Fix (GHSA-mhp4-4x5-p9df)
github.com · 2026-07-09

### Vulnerability Overview This vulnerability affects a service named "Bridge Server" (running on port 3766) and involves the following security issues: 1. **Cross-Site WebSocket Hijacking (CSWSH)**: …

Read more
CVSS 7.5
yt-dlp _write_link_file URL validation and escaping fix (GHSA-6v4j-42gp-vj32)
github.com · 2026-07-09

### Vulnerability Overview This vulnerability involves an issue with the validation and escaping of values in the `--write-link` output within the `yt-dlp` project. Specifically, when attempting to wr…

Read more
CVSS 7.5
NATS MQTT Pre-Auth DoS Vulnerability via CONNECT Packets (CVE-2020-58210)
github.com · 2026-07-09

### Vulnerability Overview Certain MQTT CONNECT packets can exhaust pre-authentication memory. ### Affected Versions - **Affected versions**: <= 2.14.2, <= 2.12.11 - **Fixed versions**: 2.14.3, 2.12.1…

Read more
CVSS 6.8
Composio CLI Sensitive File Upload Vulnerability Fix (GHSA-hp3h-89pf-5q58)
github.com · 2026-07-09

### Vulnerability Overview This vulnerability involves a sensitive file upload path issue in the ComposioHQ/composio project. Specifically, the file upload path in the CLI tool fails to properly enfor…

Read more
n8n AI Agents Credential Domain Restriction Bypass via MCP Connector (CVE-2026-9207)
github.com · 2026-07-10

### Vulnerability Overview - **Vulnerability Name**: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector - **Vulnerability ID**: GHSA-h44j-f5r5-ph73 - **Severity**: High (7.1…

Read more
CVSS 6.5
CVE-2026-56953: Unauthorized Exfiltration of Private Saved-Search Criteria via Missing Publish-Access Filter
github.com · 2026-07-10

# Vulnerability Overview - **Vulnerability Name**: Publish-mode Reader can exfiltrate private saved-search Criteria via /api/storage/getCriteria (missing publish-access filter) - **Vulnerability ID**:…

Read more
CVSS 5.4
CowAgent Cloud Skill Installation Path Traversal (GHSA)
github.com · 2026-07-10

### Vulnerability Overview **Title**: [Security] Authenticated cloud skill installation path traversal writes files outside the intended `skills/` root #2873 **Description**: The cloud skill managemen…

Read more
CVSS 4.4
osquery Unprivileged Local File Read via File Carving Temp Files (CVE-2026-45388)
github.com · 2026-07-11

### Vulnerability Overview - **Vulnerability Name**: Unprivileged users can temporarily read file carve contents - **Vulnerability ID**: GHSA-fg79-9q88-62hh - **Severity**: Moderate (4.4 / 10) - **CVS…

Read more
NanaZip UFS Parser Unbounded Memory Allocation (DoS) Vulnerability (GHSA-m34h-jf84-m74h) and PoC
github.com · 2026-07-11

### Vulnerability Overview **Vulnerability Name**: Unbounded memory allocation (DoS) in NanaZip UFS parser via unvalidated fs_bsize/fs_fsize superblock fields **Description**: The UFS/FFS image proces…

Read more
CVSS 6.5
FreeRDP rdpecam out-of-bounds read vulnerability fix details
github.com · 2026-07-11

### Vulnerability Overview **Vulnerability Name**: Out-of-bounds read in the camera device enumerator server (`rdpecam`) via unterminated DeviceName / VirtualChannelName **Vulnerability ID**: GHSA-47h…

Read more
Premium intel
CVSS 8.6
CVE-2024-21747: Multipart form-data parser bypass via embedded line breaks
github.com · 2026-07-11

# Multipart form-data parser silently strips embedded line breaks from form-field values, enabling request-body inspection bypass ## Vulnerability Overview - **Vulnerability Name**: Multipart form-dat…

Read more
CVSS 4.3
Roundcube TNEF Decoder Infinite Loop Vulnerability Fix (GHSA #18193)
github.com · 2026-07-15

### Vulnerability Overview - **Vulnerability Name**: Infinite Loop Vulnerability in TNEF (winmail.dat) Decoder - **Vulnerability ID**: #18193 - **Submitter**: alecpj - **Submission Date**: May 30, 202…

Read more
Premium intel
CVSS 8.8
phpMyFAQ Admin API Privilege Escalation: Non-SuperAdmin Creates SuperAdmin User
github.com · 2026-07-15

### Vulnerability Overview **Vulnerability Name**: Privilege escalation in admin API: `user/add` allows a non-SuperAdmin admin to create a SuperAdmin (incomplete fix of the GHSA-xvp4 / GHSA-985r autho…

Read more
CVSS 7.8
Tabby Drag-and-drop Path Injection Leading to RCE (Incomplete Fix for GHSA-m937-jm93-pfp6)
github.com · 2026-07-16

### Vulnerability Overview **Title**: Drag-and-drop path injection still allows RCE via shell command substitution (incomplete fix for GHSA-m937-jm93-pfp6) **Description**: Tabby's drag-and-drop decor…

Read more
GHSA-9723: Activepieces Cross-tenant File Download via Missing JWT Audience Check
github.com · 2026-07-17

### Vulnerability Overview - **Vulnerability Name**: Cross-tenant file download via missing JWT audience check on step-files signed URL - **Vulnerability ID**: GHSA-9723-fmff-mc24 - **Severity**: Mode…

Read more
CVSS 5.4
CVE-2026-61718: Authorization Bypass Allows Read-only UI Users to Delete Cache Files
github.com · 2026-07-17

# Vulnerability Overview - **Vulnerability Title**: Read-only Web UI users can delete job cache files due to missing authorization on `/cache/` routes - **Vulnerability ID**: GHSA-q7m-935c-v39g - **Se…

Read more
Kirby CMS CVE-2026-44174 Arbitrary Method Call via REST API Fix
github.com · 2026-07-17

# Vulnerability Overview - **Vulnerability Name**: Arbitrary Method Invocation via REST API Search and Collection Query Endpoints - **Vulnerability ID**: GHSA-86rh-h242-8jxp - **Severity**: High (8.7 …

Read more
CVE-2026-54466: Message corruption via abuse of protocol length headers in websocket-driver
github.com · 2026-07-18

# Vulnerability Overview **Vulnerability Name**: Message corruption via abuse of protocol length headers **Vulnerability ID**: GHSA-xv28-6w52-cph6 **CVE ID**: CVE-2026-54466 **Severity**: Critical (9.…

Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.