Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

43 advisories

Loading
Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter Moderate
CVE-2026-88978 was published for github.com/hatchet-dev/hatchet (Go) Sep 22, 2026
d3do-23 Credited to d3do-23
SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath Moderate
CVE-2026-72802 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 3, 2026
Shirshakhtml Credited to Shirshakhtml
Vikunja vulnerable to authenticated cross-tenant kanban-bucket relocation via `project_view_id` mass-assignment Moderate
CVE-2026-55067 was published for code.vikunja.io/api (Go) Aug 28, 2026
voraci0us Credited to voraci0us
Hatchet allows cross-tenant write/DoS to other tenants' workers via Dispatcher gRPC UpsertWorkerLabels and Unsubscribe Moderate
CVE-2026-54746 was published for github.com/hatchet-dev/hatchet (Go) Aug 28, 2026
sajdakabir Credited to sajdakabir
Duplicate Advisory: The reference filter for getRefIDs checks visibility but not the password tier, disclosing that password-protected documents reference a given block Moderate
GHSA-gq43-vcrh-6jw8 was published for github.com/siyuan-note/siyuan/kernel (Go) Aug 13, 2026 • withdrawn
Duplicate Advisory: Absolute filesystem path and OS username disclosure via resolveAssetPath Moderate
GHSA-72xp-24p9-7vpf was published for github.com/siyuan-note/siyuan/kernel (Go) Aug 12, 2026 • withdrawn
OpenList: Arbitrary File Read via Path Prefix Confusion in Share Creation API Moderate
CVE-2026-69160 was published for github.com/OpenListTeam/OpenList/v4 (Go) Jul 24, 2026
cns1rius Credited to cns1rius, xrgzs, jyxjjj, and sondt99 xrgzs xrgzs
jyxjjj jyxjjj sondt99 sondt99
OpenList: Search metadata/count disclosure via Non-Separator-Aware Path Check in Bleve Search Moderate
GHSA-p6ph-3jx2-3337 was published for github.com/OpenListTeam/OpenList/v4 (Go) Jul 24, 2026
cns1rius Credited to cns1rius, jyxjjj, and xrgzs jyxjjj jyxjjj
xrgzs xrgzs
Gitea LFS Deploy-Key Privilege Escalation Moderate
CVE-2026-58435 was published for code.gitea.io/gitea (Go) Jul 21, 2026
adrian-doyensec Credited to adrian-doyensec
Gitea: Cross-repository issue/comment attachment re-linking can expose private attachment content Moderate
CVE-2026-57886 was published for code.gitea.io/gitea (Go) Jul 21, 2026
zulloper Credited to zulloper
Gitea: draft release attachment disclosure via missing web authorization Moderate
CVE-2026-58432 was published for code.gitea.io/gitea (Go) Jul 21, 2026
z3r0s6 Credited to z3r0s6
Gitea tracked-time deletion is not scoped to the requested issue Moderate
CVE-2026-25782 was published for code.gitea.io/gitea (Go) Jul 3, 2026
Mattermost doesn't validate channel ownership of an existing subscription before applying edits Moderate
CVE-2026-6062 was published for github.com/mattermost/mattermost-server (Go) Jun 22, 2026
Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join Moderate
CVE-2026-54324 was published for github.com/daytonaio/daytona (Go) Jun 17, 2026
vnth4nhnt Credited to vnth4nhnt
gittuf's policy can be rolled back to prior valid versions Moderate
CVE-2026-44544 was published for github.com/gittuf/gittuf (Go) May 7, 2026
andrew Credited to andrew
ShellHub has cross-tenant IDOR in `GET /api/namespaces/:tenant` via API Key bypasses membership check Moderate
CVE-2026-44426 was published for github.com/shellhub-io/shellhub (Go) May 7, 2026
Edu0x01 Credited to Edu0x01
ShellHub has cross-tenant IDOR in `GET /api/sessions/:uid` that discloses SSH session data Moderate
CVE-2026-44423 was published for github.com/shellhub-io/shellhub (Go) May 6, 2026
Edu0x01 Credited to Edu0x01
ShellHub has cross-tenant IDOR in `GET /api/devices/:uid` that discloses device data of any namespace Moderate
CVE-2026-44424 was published for github.com/shellhub-io/shellhub (Go) May 6, 2026
Edu0x01 Credited to Edu0x01
Hatchet affected by cross-tenant information disclosure in `listTasksByDAGIds` Moderate
CVE-2026-42572 was published for github.com/hatchet-dev/hatchet (Go) May 6, 2026
sajdakabir Credited to sajdakabir and zerotrail-ai zerotrail-ai zerotrail-ai
Velocidex Velociraptor has an authorization bypass vulnerability Moderate
CVE-2026-7573 was published for www.velocidex.com/golang/velociraptor (Go) May 6, 2026
Focalboard doesn't validate file ownership when serving uploaded files Moderate
CVE-2026-28736 was published for github.com/mattermost/focalboard (Go) Apr 3, 2026
Vikunja has a Link Share Delete IDOR — Missing Project Ownership Check Allows Cross-Project Link Share Deletion Moderate
CVE-2026-33700 was published for code.vikunja.io/api (Go) Mar 25, 2026
New API: IDOR in VideoProxy allows cross-user video content access via missing ownership check Moderate
CVE-2026-30886 was published for github.com/QuantumNous/new-api (Go) Mar 23, 2026
Mistz1 Credited to Mistz1 and Calcium-Ion Calcium-Ion Calcium-Ion
Vikunja has an IDOR in Task Comments Allows Reading Arbitrary Comments Moderate
CVE-2026-33313 was published for code.vikunja.io/api (Go) Mar 20, 2026
File Browser has an Authorization Policy Bypass in Public Share Download Flow Moderate
CVE-2026-32761 was published for https://github.com/filebrowser/filebrowser (Go) Mar 18, 2026
Ahmad-jarwan Credited to Ahmad-jarwan and hacdias hacdias hacdias
ProTip! Advisories are also available from the GraphQL API