Open Source Vulnerabilities
deepseek-tui, deepseek-tui, codewhale-tui, codewhale
CodeWhale: SSRF bypass - TOCTOU on DNS failure for DNS pinning
deepseek-tui/ deepseek-tui/ codewhale-tui/ codewhale
CodeWhale: SSRF bypass - TOCTOU on DNS failure for DNS pinning
deepseek-tui, deepseek-tui, codewhale-tui, codewhale
CodeWhale: js_execution leaks parent environment to model context via missing env scrub
deepseek-tui/ deepseek-tui/ codewhale-tui/ codewhale
CodeWhale: js_execution leaks parent environment to model context via missing env scrub
deepseek-tui, deepseek-tui, codewhale-tui, codewhale
CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval
deepseek-tui/ deepseek-tui/ codewhale-tui/ codewhale
CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval
deepseek-tui, deepseek-tui, codewhale-tui, codewhale
CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)
deepseek-tui/ deepseek-tui/ codewhale-tui/ codewhale
CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)
Frappe CRM: Authentication Bypass via Logged Invitation Keys in crm/api
Frappe CRM: Authentication Bypass via Logged Invitation Keys in crm/api
deepseek-tui, deepseek-tui, codewhale-tui, codewhale
CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
deepseek-tui/ deepseek-tui/ codewhale-tui/ codewhale
CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
Nango < 0.71.6 Missing Authentication RCE via runner tRPC server
Nango < 0.71.6 Missing Authentication RCE via runner tRPC server
linux-aws-5.4, linux-gcp-5.4, linux-gcp
linux-aws-5.4, linux-gcp, linux-gcp-5.4 vulnerabilities
linux-aws-5.4/ linux-gcp-5.4/ linux-gcp
linux-aws-5.4, linux-gcp, linux-gcp-5.4 vulnerabilities
Admidio: CSRF on Plugin Install, Uninstall, and Update via Unprotected GET Requests
Admidio: CSRF on Plugin Install, Uninstall, and Update via Unprotected GET Requests
microcode, microcode
Updated microcode packages fix security vulnerabilities
microcode/ microcode
Updated microcode packages fix security vulnerabilities
mbedtls
Updated mbedtls packages fix security vulnerabilities
tomcat, tomcat
Updated tomcat packages fix security vulnerabilities
tomcat/ tomcat
Updated tomcat packages fix security vulnerabilities
linux-aws, linux-lts-xenial, linux, linux-kvm, linux-fips
linux, linux-aws, linux-fips, linux-kvm, linux-lts-xenial vulnerabilities
linux-aws/ linux-lts-xenial/ linux/ linux-kvm/ linux-fips
linux, linux-aws, linux-fips, linux-kvm, linux-lts-xenial vulnerabilities
SolidInvoice allows cross-user access to API token request history via writable DataGrid LiveComponent props
SolidInvoice allows cross-user access to API token request history via writable DataGrid LiveComponent props
SolidInvoice's long-lived API tokens accepted as URL query parameters, exposing credentials in server logs and browser history
SolidInvoice's long-lived API tokens accepted as URL query parameters, exposing credentials in server logs and browser history
Libtpms: libtpms: heap out-of-bounds read in tpm2 state unmarshalling via unchecked block_skip_read() blocksize
Libtpms: libtpms: heap out-of-bounds read in tpm2 state unmarshalling via unchecked block_skip_read() blocksize
Emlog: Stored XSS via Tag Name in Article Editor
Emlog: Zip Slip Path Traversal in Plugin/Template ZIP Upload Enables RCE
Emlog: Zip Slip Path Traversal in Plugin/Template ZIP Upload Enables RCE
Emlog: Stored XSS via Parsedown Markdown Processing - Raw HTML Not Sanitized
Emlog: Stored XSS via Parsedown Markdown Processing - Raw HTML Not Sanitized
Emlog Blind SQL Injection via Authentication Cookie
SolidInvoice's user invitation tokens have no expiry, allowing indefinite unauthorized company access via leaked or old invitation links
SolidInvoice's user invitation tokens have no expiry, allowing indefinite unauthorized company access via leaked or old invitation links
SolidInvoice: PHP unserialize() called on client-controlled data in DataGrid LiveComponent context prop
SolidInvoice: PHP unserialize() called on client-controlled data in DataGrid LiveComponent context prop
ILIAS Arbitrary SQL Injection via Repository Trash Table Sort Parameter
ILIAS Arbitrary SQL Injection via Repository Trash Table Sort Parameter
deepseek-tui, deepseek-tui, codewhale-tui, codewhale
CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes
deepseek-tui/ deepseek-tui/ codewhale-tui/ codewhale
CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes
@simplewebauthn/server
SimpleWebAuthn: Registration verification does not sufficiently ensure that attestation certificates chain to a trust anchor
@simplewebauthn/server
SimpleWebAuthn: Registration verification does not sufficiently ensure that attestation certificates chain to a trust anchor
SurrealDB, SurrealDB, SurrealDB, SurrealDB
SurrealDB allows bypass of deny-net flags via DNS resolution
SurrealDB/ SurrealDB/ SurrealDB/ SurrealDB
SurrealDB allows bypass of deny-net flags via DNS resolution
Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p)
Note Mark: Path traversal via unsanitized book/note slug in migrate export (sibling of GHSA-g49p)
undici vulnerable to Denial of Service via orphaned RetryHandler response body
undici vulnerable to Denial of Service via orphaned RetryHandler response body
, Kernel
selinux: require every boolean value to be defined
, Kernel
selinux: reject an unclaimed class value in security_get_classes()
/ Kernel
selinux: reject an unclaimed class value in security_get_classes()
, Kernel
ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked()
/ Kernel
ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked()
, Kernel
ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses
/ Kernel
ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses
, Kernel
drm/amdgpu: Reject UVD message with invalid number of h265 refs
/ Kernel
drm/amdgpu: Reject UVD message with invalid number of h265 refs
, Kernel
drm/amdgpu: Reject UVD message with dimensions above 4096
/ Kernel
drm/amdgpu: Reject UVD message with dimensions above 4096
, Kernel
drm/amdgpu: Fix UVD dpb min size calculation for H264
, Kernel
net: packet: fix wrong transport_header when sending VLAN-tagged frame
/ Kernel
net: packet: fix wrong transport_header when sending VLAN-tagged frame
, Kernel
net: tap: fix wrong transport_header when sending VLAN-tagged frame
/ Kernel
net: tap: fix wrong transport_header when sending VLAN-tagged frame
, Kernel
net/tls: Fail tls_sw_splice_read() after a failed async decrypt
/ Kernel
net/tls: Fail tls_sw_splice_read() after a failed async decrypt
, Kernel
drm/xe/oa: Fix sync entry leak on OA config emit failure
/ Kernel
drm/xe/oa: Fix sync entry leak on OA config emit failure
node-undici, node-undici, node-undici
node-undici, node-undici, node-undici
node-undici, node-undici, node-undici
node-undici, node-undici, node-undici
node-undici, node-undici, node-undici
node-undici, node-undici, node-undici
node-undici, node-undici, node-undici
