Published issues
Permalink
CVE-2026-40505
3.3 LOW
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): Low (L)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): None (N)
updated
4 months, 4 weeks ago
by @LeSuisse
Activity log
-
Created suggestion
5 months ago
-
@LeSuisse
ignored
10 packages
- python312Packages.pymupdf
- python313Packages.pymupdf
- python314Packages.pymupdf
- python312Packages.pymupdf4llm
- python313Packages.pymupdf4llm
- python314Packages.pymupdf4llm
- zathuraPkgs.zathura_pdf_mupdf
- python312Packages.pymupdf-fonts
- python313Packages.pymupdf-fonts
- python314Packages.pymupdf-fonts
4 months, 4 weeks ago
-
@LeSuisse
accepted
4 months, 4 weeks ago
-
@LeSuisse
published on GitHub
4 months, 4 weeks ago
MuPDF mutool ANSI Injection via Metadata
MuPDF
-
<0f17d789fe8c29b41e47663be82514aaca3a4dfb
updated
4 months, 4 weeks ago
by @LeSuisse
Activity log
-
Created suggestion
5 months ago
-
@LeSuisse
accepted
4 months, 4 weeks ago
-
@LeSuisse
published on GitHub
4 months, 4 weeks ago
Apache Airflow: JWT token appearing in logs
Permalink
CVE-2026-40259
8.1 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): High (H)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): High (H)
updated
4 months, 4 weeks ago
by @LeSuisse
Activity log
-
Created suggestion
5 months ago
-
@LeSuisse
accepted
4 months, 4 weeks ago
-
@LeSuisse
published on GitHub
4 months, 4 weeks ago
SiYuan: Publish Reader Can Arbitrarily Delete Attribute View Files via removeUnusedAttributeView API
siyuan
-
==< 0.0.0-20260407035653-2f416e5253f1
-
==< 3.6.4
updated
4 months, 4 weeks ago
by @LeSuisse
Activity log
-
Created suggestion
5 months ago
-
@LeSuisse
accepted
4 months, 4 weeks ago
-
@LeSuisse
published on GitHub
4 months, 4 weeks ago
SiYuan: Incomplete sanitization of bazaar README allows stored XSS via iframe srcdoc (incomplete fix for CVE-2026-33066)
Permalink
CVE-2026-40959
9.3 CRITICAL
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Changed (C)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Changed (C)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): High (H)
updated
4 months, 4 weeks ago
by @LeSuisse
Activity log
-
Created suggestion
5 months ago
-
@LeSuisse
ignored
2 packages
- luanti-client
- luanti-server
4 months, 4 weeks ago
-
@LeSuisse
ignored
3 maintainers
4 months, 4 weeks ago
maintainer.ignore
-
@LeSuisse
accepted
4 months, 4 weeks ago
-
@LeSuisse
published on GitHub
4 months, 4 weeks ago
Luanti 5 before 5.15.2, when LuaJIT is used, allows a …
Permalink
CVE-2026-33472
4.8 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): Required (R)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): High (H)
-
Integrity (I): None (N)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): None (N)
updated
4 months, 4 weeks ago
by @LeSuisse
Activity log
-
Created suggestion
5 months ago
-
@LeSuisse
ignored
package cryptomator-cli
4 months, 4 weeks ago
-
@LeSuisse
ignored
2 maintainers
4 months, 4 weeks ago
maintainer.ignore
-
@LeSuisse
accepted
4 months, 4 weeks ago
-
@LeSuisse
published on GitHub
4 months, 4 weeks ago
Cryptomator Hub OAuth token exchange HTTP downgrade via getAuthority() scheme confusion (CVE-2026-32303 bypass)
Permalink
CVE-2026-40960
8.1 HIGH
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Local (L)
-
Attack Complexity (AC): High (H)
-
Privileges Required (PR): None (N)
-
User Interaction (UI): None (N)
-
Scope (S): Changed (C)
-
Confidentiality (C): High (H)
-
Integrity (I): High (H)
-
Availability (A): High (H)
-
Modified Attack Vector (MAV): Local (L)
-
Modified Attack Complexity (MAC): High (H)
-
Modified Privileges Required (MPR): None (N)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Changed (C)
-
Modified Integrity (MI): High (H)
-
Modified Availability (MA): High (H)
updated
4 months, 4 weeks ago
by @LeSuisse
Activity log
-
Created suggestion
5 months ago
-
@LeSuisse
ignored
2 packages
- luanti-client
- luanti-server
4 months, 4 weeks ago
-
@LeSuisse
ignored
3 maintainers
4 months, 4 weeks ago
maintainer.ignore
-
@LeSuisse
accepted
4 months, 4 weeks ago
-
@LeSuisse
published on GitHub
4 months, 4 weeks ago
Luanti 5 before 5.15.2 sometimes allows unintended access to an …
Permalink
CVE-2026-33214
4.3 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Unchanged (U)
-
Confidentiality (C): None (N)
-
Integrity (I): Low (L)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): None (N)
-
Modified Scope (MS): Unchanged (U)
-
Modified Integrity (MI): Low (L)
-
Modified Availability (MA): None (N)
updated
5 months ago
by @LeSuisse
Activity log
-
Created suggestion
5 months ago
-
@LeSuisse
ignored
8 packages
- python313Packages.weblate-fonts
- python314Packages.weblate-fonts
- python312Packages.weblate-schemas
- python313Packages.weblate-schemas
- python314Packages.weblate-schemas
- python312Packages.weblate-language-data
- python313Packages.weblate-language-data
- python314Packages.weblate-language-data
5 months ago
-
@LeSuisse
accepted
5 months ago
-
@LeSuisse
published on GitHub
5 months ago
Weblate has improper access control for the translation memory API
Permalink
CVE-2026-33220
6.8 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): Required (R)
-
Scope (S): Changed (C)
-
Confidentiality (C): High (H)
-
Integrity (I): None (N)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): Required (R)
-
Modified Confidentiality (MC): High (H)
-
Modified Scope (MS): Changed (C)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): None (N)
updated
5 months ago
by @LeSuisse
Activity log
-
Created suggestion
5 months ago
-
@LeSuisse
ignored
8 packages
- python313Packages.weblate-fonts
- python314Packages.weblate-fonts
- python312Packages.weblate-schemas
- python313Packages.weblate-schemas
- python314Packages.weblate-schemas
- python312Packages.weblate-language-data
- python313Packages.weblate-language-data
- python314Packages.weblate-language-data
5 months ago
-
@LeSuisse
accepted
5 months ago
-
@LeSuisse
published on GitHub
5 months ago
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
Permalink
CVE-2026-40256
5.0 MEDIUM
-
CVSS version (CVSS): 3.1
-
Attack Vector (AV): Network (N)
-
Attack Complexity (AC): Low (L)
-
Privileges Required (PR): Low (L)
-
User Interaction (UI): None (N)
-
Scope (S): Changed (C)
-
Confidentiality (C): Low (L)
-
Integrity (I): None (N)
-
Availability (A): None (N)
-
Modified Attack Vector (MAV): Network (N)
-
Modified Attack Complexity (MAC): Low (L)
-
Modified Privileges Required (MPR): Low (L)
-
Modified User Interaction (MUI): None (N)
-
Modified Confidentiality (MC): Low (L)
-
Modified Scope (MS): Changed (C)
-
Modified Integrity (MI): None (N)
-
Modified Availability (MA): None (N)
updated
5 months ago
by @LeSuisse
Activity log
-
Created suggestion
5 months ago
-
@LeSuisse
ignored
8 packages
- python313Packages.weblate-fonts
- python314Packages.weblate-fonts
- python312Packages.weblate-schemas
- python313Packages.weblate-schemas
- python314Packages.weblate-schemas
- python312Packages.weblate-language-data
- python313Packages.weblate-language-data
- python314Packages.weblate-language-data
5 months ago
-
@LeSuisse
accepted
5 months ago
-
@LeSuisse
published on GitHub
5 months ago
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision