Skip to content

Commit cca95b4

Browse files
1 parent d21e375 commit cca95b4

6 files changed

Lines changed: 32 additions & 12 deletions

File tree

advisories/github-reviewed/2026/03/GHSA-gjxx-92w9-8v8f/GHSA-gjxx-92w9-8v8f.json

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-gjxx-92w9-8v8f",
4-
"modified": "2026-03-27T19:58:19Z",
4+
"modified": "2026-04-06T16:44:03Z",
55
"published": "2026-03-27T19:58:19Z",
66
"aliases": [
77
"CVE-2026-34076"
@@ -109,6 +109,10 @@
109109
"type": "WEB",
110110
"url": "https://github.com/clerk/javascript/security/advisories/GHSA-gjxx-92w9-8v8f"
111111
},
112+
{
113+
"type": "ADVISORY",
114+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34076"
115+
},
112116
{
113117
"type": "PACKAGE",
114118
"url": "https://github.com/clerk/javascript"
@@ -121,6 +125,6 @@
121125
"severity": "HIGH",
122126
"github_reviewed": true,
123127
"github_reviewed_at": "2026-03-27T19:58:19Z",
124-
"nvd_published_at": null
128+
"nvd_published_at": "2026-04-01T18:16:29Z"
125129
}
126130
}

advisories/github-reviewed/2026/03/GHSA-v9p7-gf3q-h779/GHSA-v9p7-gf3q-h779.json

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-v9p7-gf3q-h779",
4-
"modified": "2026-03-30T17:07:54Z",
4+
"modified": "2026-04-06T16:43:56Z",
55
"published": "2026-03-30T17:07:53Z",
66
"aliases": [
77
"CVE-2026-33949"
@@ -43,6 +43,10 @@
4343
"type": "WEB",
4444
"url": "https://github.com/tinacms/tinacms/security/advisories/GHSA-v9p7-gf3q-h779"
4545
},
46+
{
47+
"type": "ADVISORY",
48+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33949"
49+
},
4650
{
4751
"type": "PACKAGE",
4852
"url": "https://github.com/tinacms/tinacms"
@@ -56,6 +60,6 @@
5660
"severity": "HIGH",
5761
"github_reviewed": true,
5862
"github_reviewed_at": "2026-03-30T17:07:53Z",
59-
"nvd_published_at": null
63+
"nvd_published_at": "2026-04-01T17:28:39Z"
6064
}
6165
}

advisories/github-reviewed/2026/03/GHSA-x2f5-332j-9xwq/GHSA-x2f5-332j-9xwq.json

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-x2f5-332j-9xwq",
4-
"modified": "2026-03-30T17:08:25Z",
4+
"modified": "2026-04-06T16:44:36Z",
55
"published": "2026-03-30T17:08:25Z",
66
"aliases": [
77
"CVE-2026-33990"
@@ -40,6 +40,10 @@
4040
"type": "WEB",
4141
"url": "https://github.com/docker/model-runner/security/advisories/GHSA-x2f5-332j-9xwq"
4242
},
43+
{
44+
"type": "ADVISORY",
45+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-33990"
46+
},
4347
{
4448
"type": "PACKAGE",
4549
"url": "https://github.com/docker/model-runner"
@@ -52,6 +56,6 @@
5256
"severity": "MODERATE",
5357
"github_reviewed": true,
5458
"github_reviewed_at": "2026-03-30T17:08:25Z",
55-
"nvd_published_at": null
59+
"nvd_published_at": "2026-04-01T17:28:39Z"
5660
}
5761
}

advisories/github-reviewed/2026/04/GHSA-63mg-xp9j-jfcm/GHSA-63mg-xp9j-jfcm.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-63mg-xp9j-jfcm",
4-
"modified": "2026-04-01T00:01:10Z",
4+
"modified": "2026-04-06T16:46:04Z",
55
"published": "2026-04-01T00:01:10Z",
66
"aliases": [
77
"CVE-2026-33578"
88
],
99
"summary": "OpenClaw: Google Chat and Zalouser group sender allowlist bypass via policy downgrade",
10-
"details": "## Summary\n\nWhen only a route-level group allowlist was configured, sender policy resolution silently downgraded from `allowlist` to `open` instead of preserving the configured group policy.\n\n## Impact\n\nAny member of an allowlisted Google Chat space or Zalouser group could interact with the bot even when the operator intended sender-level restrictions.\n\n## Affected Component\n\n`extensions/googlechat/src/monitor-access.ts, extensions/zalouser/src/monitor.ts`\n\n## Fixed Versions\n\n- Affected: `<= 2026.3.24`\n- Patched: `>= 2026.3.28`\n- Latest stable `2026.3.28` contains the fix.\n\n## Fix\n\nFixed by commit `e64a881ae0` (`Channels: preserve routed group policy`).",
10+
"details": "## Summary\n\nWhen only a route-level group allowlist was configured, sender policy resolution silently downgraded from `allowlist` to `open` instead of preserving the configured group policy.\n\n## Impact\n\nAny member of an allowlisted Google Chat space or Zalouser group could interact with the bot even when the operator intended sender-level restrictions.\n\n## Affected Component\n\n`extensions/googlechat/src/monitor-access.ts, extensions/zalouser/src/monitor.ts`\n\n## Fixed Versions\n\n- Affected: `<= 2026.3.24`\n- Patched: `>= 2026.3.28`\n- Latest stable `2026.3.28` contains the fix.\n\n## Fix\n\nFixed by commit `e64a881ae0` (`Channels: preserve routed group policy`).\n\nOpenClaw thanks @AntAISecurityLab for reporting.",
1111
"severity": [
1212
{
1313
"type": "CVSS_V3",

advisories/github-reviewed/2026/04/GHSA-g87c-r2jp-293w/GHSA-g87c-r2jp-293w.json

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-g87c-r2jp-293w",
4-
"modified": "2026-04-01T00:23:02Z",
4+
"modified": "2026-04-06T16:44:07Z",
55
"published": "2026-04-01T00:23:02Z",
66
"aliases": [
77
"CVE-2026-34603"
@@ -43,6 +43,10 @@
4343
"type": "WEB",
4444
"url": "https://github.com/tinacms/tinacms/security/advisories/GHSA-g87c-r2jp-293w"
4545
},
46+
{
47+
"type": "ADVISORY",
48+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34603"
49+
},
4650
{
4751
"type": "WEB",
4852
"url": "https://github.com/tinacms/tinacms/commit/f124eabaca10dac9a4d765c9e4135813c4830955"
@@ -60,6 +64,6 @@
6064
"severity": "HIGH",
6165
"github_reviewed": true,
6266
"github_reviewed_at": "2026-04-01T00:23:02Z",
63-
"nvd_published_at": null
67+
"nvd_published_at": "2026-04-01T17:28:41Z"
6468
}
6569
}

advisories/github-reviewed/2026/04/GHSA-g9c2-gf25-3x67/GHSA-g9c2-gf25-3x67.json

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-g9c2-gf25-3x67",
4-
"modified": "2026-04-01T00:25:22Z",
4+
"modified": "2026-04-06T16:44:11Z",
55
"published": "2026-04-01T00:25:22Z",
66
"aliases": [
77
"CVE-2026-34604"
@@ -43,6 +43,10 @@
4343
"type": "WEB",
4444
"url": "https://github.com/tinacms/tinacms/security/advisories/GHSA-g9c2-gf25-3x67"
4545
},
46+
{
47+
"type": "ADVISORY",
48+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34604"
49+
},
4650
{
4751
"type": "WEB",
4852
"url": "https://github.com/tinacms/tinacms/commit/f124eabaca10dac9a4d765c9e4135813c4830955"
@@ -60,6 +64,6 @@
6064
"severity": "HIGH",
6165
"github_reviewed": true,
6266
"github_reviewed_at": "2026-04-01T00:25:22Z",
63-
"nvd_published_at": null
67+
"nvd_published_at": "2026-04-01T17:28:41Z"
6468
}
6569
}

0 commit comments

Comments
 (0)