Skip to content

Commit 5cbf981

Browse files
1 parent 444f526 commit 5cbf981

6 files changed

Lines changed: 37 additions & 12 deletions

File tree

advisories/github-reviewed/2026/03/GHSA-89vf-4333-qx8v/GHSA-89vf-4333-qx8v.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-89vf-4333-qx8v",
4-
"modified": "2026-03-25T20:47:31Z",
4+
"modified": "2026-04-09T19:06:46Z",
55
"published": "2026-03-23T20:53:28Z",
66
"aliases": [
77
"CVE-2026-33170"
88
],
99
"summary": "Rails Active Support has a possible XSS vulnerability in SafeBuffer#%",
10-
"details": "### Impact\n`SafeBuffer#%` does not propagate the `@html_unsafe` flag to the newly created buffer. If a `SafeBuffer` is mutated in place (e.g. via `gsub!`) and then formatted with `%` using untrusted arguments, the result incorrectly reports `html_safe? == true`, bypassing ERB auto-escaping and possibly leading to XSS.\n\n### Releases\nThe fixed releases are available at the normal locations.",
10+
"details": "### Impact\n`SafeBuffer#%` does not propagate the `@html_unsafe` flag to the newly created buffer. If a `SafeBuffer` is mutated in place (e.g. via `gsub!`) and then formatted with `%` using untrusted arguments, the result incorrectly reports `html_safe? == true`, bypassing ERB auto-escaping and possibly leading to XSS.\n\n### Releases\nThe fixed releases are available at the normal locations.\n\n### Credit\nThis issue was responsibly reported by @ch4n3-yoon",
1111
"severity": [
1212
{
1313
"type": "CVSS_V4",

advisories/github-reviewed/2026/04/GHSA-2679-6mx9-h9xc/GHSA-2679-6mx9-h9xc.json

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-2679-6mx9-h9xc",
4-
"modified": "2026-04-09T14:30:45Z",
4+
"modified": "2026-04-09T19:06:14Z",
55
"published": "2026-04-08T21:50:58Z",
66
"aliases": [
77
"CVE-2026-39987"
@@ -40,6 +40,10 @@
4040
"type": "WEB",
4141
"url": "https://github.com/marimo-team/marimo/security/advisories/GHSA-2679-6mx9-h9xc"
4242
},
43+
{
44+
"type": "ADVISORY",
45+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39987"
46+
},
4347
{
4448
"type": "WEB",
4549
"url": "https://github.com/marimo-team/marimo/pull/9098"
@@ -60,6 +64,6 @@
6064
"severity": "CRITICAL",
6165
"github_reviewed": true,
6266
"github_reviewed_at": "2026-04-08T21:50:58Z",
63-
"nvd_published_at": null
67+
"nvd_published_at": "2026-04-09T18:17:02Z"
6468
}
6569
}

advisories/github-reviewed/2026/04/GHSA-4ggg-h7ph-26qr/GHSA-4ggg-h7ph-26qr.json

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-4ggg-h7ph-26qr",
4-
"modified": "2026-04-09T14:31:07Z",
4+
"modified": "2026-04-09T19:05:56Z",
55
"published": "2026-04-08T19:53:48Z",
66
"aliases": [
77
"CVE-2026-39974"
@@ -43,6 +43,10 @@
4343
"type": "WEB",
4444
"url": "https://github.com/czlonkowski/n8n-mcp/security/advisories/GHSA-4ggg-h7ph-26qr"
4545
},
46+
{
47+
"type": "ADVISORY",
48+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39974"
49+
},
4650
{
4751
"type": "WEB",
4852
"url": "https://github.com/czlonkowski/n8n-mcp/commit/d9d847f230923d96e0857ccecf3a4dedcc9b0096"
@@ -63,6 +67,6 @@
6367
"severity": "HIGH",
6468
"github_reviewed": true,
6569
"github_reviewed_at": "2026-04-08T19:53:48Z",
66-
"nvd_published_at": null
70+
"nvd_published_at": "2026-04-09T17:16:30Z"
6771
}
6872
}

advisories/github-reviewed/2026/04/GHSA-5gfj-64gh-mgmw/GHSA-5gfj-64gh-mgmw.json

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-5gfj-64gh-mgmw",
4-
"modified": "2026-04-09T14:31:22Z",
4+
"modified": "2026-04-09T19:06:04Z",
55
"published": "2026-04-08T20:02:01Z",
66
"aliases": [
77
"CVE-2026-39981"
@@ -43,6 +43,14 @@
4343
"type": "WEB",
4444
"url": "https://github.com/Josh-XT/AGiXT/security/advisories/GHSA-5gfj-64gh-mgmw"
4545
},
46+
{
47+
"type": "ADVISORY",
48+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39981"
49+
},
50+
{
51+
"type": "WEB",
52+
"url": "https://github.com/Josh-XT/AGiXT/commit/2079ea5a88fa671a921bf0b5eba887a5a1b73d5f"
53+
},
4654
{
4755
"type": "PACKAGE",
4856
"url": "https://github.com/Josh-XT/AGiXT"
@@ -59,6 +67,6 @@
5967
"severity": "HIGH",
6068
"github_reviewed": true,
6169
"github_reviewed_at": "2026-04-08T20:02:01Z",
62-
"nvd_published_at": null
70+
"nvd_published_at": "2026-04-09T18:17:02Z"
6371
}
6472
}

advisories/github-reviewed/2026/04/GHSA-chqc-8p9q-pq6q/GHSA-chqc-8p9q-pq6q.json

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-chqc-8p9q-pq6q",
4-
"modified": "2026-04-09T14:31:27Z",
4+
"modified": "2026-04-09T19:06:10Z",
55
"published": "2026-04-08T20:02:25Z",
66
"aliases": [
77
"CVE-2026-39983"
@@ -43,6 +43,10 @@
4343
"type": "WEB",
4444
"url": "https://github.com/patrickjuchli/basic-ftp/security/advisories/GHSA-chqc-8p9q-pq6q"
4545
},
46+
{
47+
"type": "ADVISORY",
48+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39983"
49+
},
4650
{
4751
"type": "WEB",
4852
"url": "https://github.com/patrickjuchli/basic-ftp/commit/2ecc8e2c500c5234115f06fd1dbde1aa03d70f4b"
@@ -63,6 +67,6 @@
6367
"severity": "HIGH",
6468
"github_reviewed": true,
6569
"github_reviewed_at": "2026-04-08T20:02:25Z",
66-
"nvd_published_at": null
70+
"nvd_published_at": "2026-04-09T18:17:02Z"
6771
}
6872
}

advisories/github-reviewed/2026/04/GHSA-xrw6-gwf8-vvr9/GHSA-xrw6-gwf8-vvr9.json

Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-xrw6-gwf8-vvr9",
4-
"modified": "2026-04-09T14:30:59Z",
4+
"modified": "2026-04-09T19:05:46Z",
55
"published": "2026-04-08T19:52:58Z",
66
"aliases": [
77
"CVE-2026-39959"
@@ -78,6 +78,10 @@
7878
"type": "WEB",
7979
"url": "https://github.com/tmds/Tmds.DBus/security/advisories/GHSA-xrw6-gwf8-vvr9"
8080
},
81+
{
82+
"type": "ADVISORY",
83+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-39959"
84+
},
8185
{
8286
"type": "PACKAGE",
8387
"url": "https://github.com/tmds/Tmds.DBus"
@@ -93,11 +97,12 @@
9397
],
9498
"database_specific": {
9599
"cwe_ids": [
100+
"CWE-290",
96101
"CWE-400"
97102
],
98103
"severity": "HIGH",
99104
"github_reviewed": true,
100105
"github_reviewed_at": "2026-04-08T19:52:58Z",
101-
"nvd_published_at": null
106+
"nvd_published_at": "2026-04-09T17:16:30Z"
102107
}
103108
}

0 commit comments

Comments
 (0)