Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-jgh3-fggc-mcpm
  • Go/github.com/obot-platform/obot
Obot: Server-Side Request Forgery via remote MCP server URL yesterday
  • Fix available
  • Severity - 7.6 (High)
GHSA-pr6h-vr44-xq8j
  • Go/github.com/obot-platform/obot
Obot: MCP Registry API readable without authentication yesterday
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-xwmw-prc4-v3cr
  • Go/github.com/obot-platform/obot
Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion yesterday
  • Fix available
  • Severity - 8.8 (High)
GHSA-vr5f-w35q-98jp
  • Go/github.com/perses/perses
Perses's unvalidated project parameter enables filesystem path traversal yesterday
  • Fix available
  • Severity - 7.1 (High)
GHSA-4227-9989-jrhx
  • Go/github.com/perses/perses
Perses's missing authorization in datasource proxy allows cross-scope secret disclosure yesterday
  • Fix available
  • Severity - 8.3 (High)
GHSA-cjgj-2fwf-4c2w
  • Go/github.com/perses/perses
Perses's project query parameter authorization bypass exposes cross-project resources yesterday
  • Fix available
  • Severity - 7.1 (High)
GHSA-5gm3-9crp-6g3v
  • Go/github.com/f1bonacc1/process-compose
Process Compose: Browser DNS rebinding lets websites control local process-compose MCP tools yesterday
  • Fix available
  • Severity - 5.1 (Medium)
GHSA-p5vg-v7mj-f6q4
  • Go/github.com/frain-dev/convoy
Convoy: Cross-Tenant Source IDOR Leaks Plaintext Message Broker Credentials yesterday
  • Fix available
  • Severity - 7.1 (High)
GHSA-w72w-9qmj-c9qm
  • Go/github.com/anycable/anycable
AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including Secrets yesterday
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-5p54-whvp-x327
  • Go/github.com/anycable/anycable
AnyCable: Pusher REST API Does Not Verify Request Body MD5 Enabling Signed-Request Replay with Arbitrary Body yesterday
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-qg2g-g9w3-m5h8
  • Go/github.com/stacklok/toolhive
ToolHive: containerized MCP servers can reach host services via host.docker.internal, enabling lateral movement yesterday
  • Fix available
  • Severity - 8.8 (High)
GHSA-c8w2-fgvx-vhv4
  • Go/github.com/kcp-dev/kcp
kcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspace yesterday
  • Fix available
  • Severity - 9.9 (Critical)
GHSA-qg67-7m6v-qg25
  • Go/zotregistry.dev/zot/v2
zot: Bearer authentication maps DELETE to push scope, allowing unauthorized deletion yesterday
  • Fix available
  • Severity - 8.1 (High)
GHSA-f94q-w3w8-cj67
  • Go/github.com/projectcapsule/capsule
Capsule: hostnameRegexHandler.OnUpdate validates stale (old) Tenant regex, allowing invalid AllowedHostnames regex to bypass webhook validation yesterday
  • Fix available
  • Severity - 6.8 (Medium)
GHSA-gjw4-3v3v-rqxg
  • Go/github.com/projectcapsule/capsule
Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement yesterday
  • Fix available
  • Severity - 7.1 (High)
GHSA-gxjc-74v5-3vx3
  • Go/github.com/projectcapsule/capsule
Capsule: Malformed ForbiddenAnnotations.Regex can bypass Tenant validation and trigger namespace admission panic yesterday
  • Fix available
  • Severity - 4.9 (Medium)