Vulnérabilités Supply chain
La partie Supply chain du flux de menaces de Stateward : 1658 incidents et techniques d’attaque curés, chacun expliquant comment cela s’est produit et comment l’éviter dans votre code.
1658 Supply chain entries · 58 curated · part of 1888 total advisories
1658 affichées
- HIGHSupply chainGHSA-7q9c-hpx7-9cwmnpm · @typespec/spector
TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop
- CRITICALSupply chainCVE-2026-73842Go · github.com/openchoreo/openchoreo
OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation
- MEDIUMSupply chainCVE-2026-73557PyPI · vllm
vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
- MEDIUMSupply chainCVE-2026-73556PyPI · vllm
vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
- MEDIUMSupply chainCVE-2026-73555PyPI · vllm
vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
- MEDIUMSupply chainCVE-2026-71486PyPI · vllm
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
- MEDIUMSupply chainCVE-2026-72792Go · github.com/siyuan-note/siyuan/kernel
SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password
- HIGHSupply chainCVE-2026-72793Go · github.com/siyuan-note/siyuan/kernel
SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers
- HIGHSupply chainCVE-2026-72795Go · github.com/siyuan-note/siyuan/kernel
SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers
- HIGHSupply chainCVE-2026-72794Go · github.com/siyuan-note/siyuan/kernel
SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf
- MEDIUMSupply chainCVE-2026-72796Go · github.com/siyuan-note/siyuan/kernel
SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers
- MEDIUMSupply chainCVE-2026-72797Go · github.com/siyuan-note/siyuan/kernel
SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers
- HIGHSupply chainCVE-2026-72798Go · github.com/siyuan-note/siyuan/kernel
SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns
- MEDIUMSupply chainCVE-2026-72799Go · github.com/siyuan-note/siyuan/kernel
SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers
- MEDIUMSupply chainCVE-2026-63733crates.io · surrealdb-core
SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
- HIGHSupply chainCVE-2026-63735crates.io · surrealdb
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
- HIGHSupply chainCVE-2026-75911crates.io · deepseek-tui
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
- HIGHSupply chainCVE-2026-75858crates.io · deepseek-tui
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
- HIGHSupply chainCVE-2026-75912crates.io · deepseek-tui
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
- CRITICALSupply chainCVE-2026-75856crates.io · deepseek-tui
CodeWhale: SSRF bypass - TOCTOU on DNS failure for DNS pinning
- HIGHSupply chainCVE-2026-75915crates.io · deepseek-tui
CodeWhale: js_execution leaks parent environment to model context via missing env scrub
- HIGHSupply chainCVE-2026-75913crates.io · deepseek-tui
CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval
- HIGHSupply chainCVE-2026-75857crates.io · deepseek-tui
CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)
- HIGHSupply chainCVE-2026-75859crates.io · deepseek-tui
CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
- HIGHSupply chainCVE-2026-75914crates.io · deepseek-tui
CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes
- MEDIUMSupply chainCVE-2025-71390crates.io · SurrealDB
SurrealDB allows bypass of deny-net flags via DNS resolution
- MEDIUMSupply chainCVE-2026-72800Go · github.com/siyuan-note/siyuan/kernel
SiYuan: Missing publish-access filter on getAttributeViewKeysByID discloses database column schema, plus two unscoped block-ID enumeration oracles (publish mode)
- HIGHSupply chainCVE-2026-72801Go · github.com/siyuan-note/siyuan/kernel
SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking
- MEDIUMSupply chainCVE-2026-72802Go · github.com/siyuan-note/siyuan/kernel
SiYuan: Absolute filesystem path and OS username disclosure via resolveAssetPath
- MEDIUMSupply chainCVE-2026-72803Go · github.com/siyuan-note/siyuan/kernel
SiYuan: Missing publish-access filter on getBlockAttrs and batchGetBlockAttrs discloses block attributes (name, alias, memo, custom fields) of protected documents
- HIGHSupply chainCVE-2026-72804Go · github.com/siyuan-note/siyuan/kernel
SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents
- MEDIUMSupply chainCVE-2026-72805Go · github.com/siyuan-note/siyuan/kernel
SiYuan: Missing publish-access check on getBlockBreadcrumb, getRefText, and getBlockTreeInfos discloses content and metadata of protected/forbidden documents
- MEDIUMSupply chainCVE-2026-72806Go · github.com/siyuan-note/siyuan/kernel
SiYuan: Password (protected) tier omitted in the attribute-view/database publish filter: Reader receives rows of protected documents without the password (publish mode)
- HIGHSupply chainCVE-2026-72807Go · github.com/siyuan-note/siyuan/kernel
SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel
- MEDIUMSupply chainCVE-2026-72808Go · github.com/siyuan-note/siyuan/kernel
SiYuan: Missing publish-access filter on getFileAnnotation discloses private PDF annotations of forbidden/protected documents (publish mode)
- HIGHSupply chainCVE-2026-72809Go · github.com/siyuan-note/siyuan/kernel
SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy
Recevez le digest hebdo des menaces
Les nouvelles vulnérabilités activement exploitées et les attaques marquantes, chacune avec son correctif, dans votre boîte mail. Sans spam, désinscription à tout moment.
Stateward confronte vos dépendances à cette intelligence à chaque pull request, et ne vous signale que ce qui atteint réellement votre code.
Voyez-le sur votre dépôt