Skip to content

Commit 0eb358c

Browse files
1 parent c0544c0 commit 0eb358c

5 files changed

Lines changed: 280 additions & 0 deletions

File tree

Lines changed: 60 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,60 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-2hp7-mfr2-4fg8",
4+
"modified": "2026-09-27T15:31:07Z",
5+
"published": "2026-09-27T15:31:07Z",
6+
"aliases": [
7+
"CVE-2026-100872"
8+
],
9+
"details": "Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthenticated attackers to modify order totals after gateway transaction initiation. Attackers can pay a small amount, enlarge the order after gateway capture, and have the system mark the inflated order as fully paid while the gateway captured only the original amount.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"
14+
},
15+
{
16+
"type": "CVSS_V4",
17+
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
18+
}
19+
],
20+
"affected": [],
21+
"references": [
22+
{
23+
"type": "WEB",
24+
"url": "https://github.com/Sylius/Sylius/security/advisories/GHSA-vv4h-q2x8-74g4"
25+
},
26+
{
27+
"type": "ADVISORY",
28+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-100872"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://github.com/Sylius/Sylius/pull/19216"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://github.com/Sylius/Sylius/commit/9e9aeaacbc97b1fc01d573e44d6679194527905d"
37+
},
38+
{
39+
"type": "WEB",
40+
"url": "https://github.com/Sylius/Sylius"
41+
},
42+
{
43+
"type": "WEB",
44+
"url": "https://github.com/Sylius/Sylius/releases/tag/v2.2.9"
45+
},
46+
{
47+
"type": "WEB",
48+
"url": "https://www.vulncheck.com/advisories/sylius-2-x-before-2.1.16-and-2.2.9-payment-amount-overwrite"
49+
}
50+
],
51+
"database_specific": {
52+
"cwe_ids": [
53+
"CWE-345"
54+
],
55+
"severity": "HIGH",
56+
"github_reviewed": false,
57+
"github_reviewed_at": null,
58+
"nvd_published_at": "2026-09-27T13:16:38Z"
59+
}
60+
}
Lines changed: 40 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,40 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-j3gx-2q66-wg27",
4+
"modified": "2026-09-27T15:31:08Z",
5+
"published": "2026-09-27T15:31:08Z",
6+
"aliases": [
7+
"CVE-2026-101041"
8+
],
9+
"details": "The account recovery (password reset) functionality in the vulnerability-lookup web application contains a time-of-check-to-time-of-use (TOCTOU) race condition in the consumption of single-use recovery tokens. The original implementation verified the token nonce against the stored digest and then consumed (cleared) it in separate database operations. Two concurrent HTTP requests presenting the same valid recovery token could both pass the verification check before either transaction committed, allowing both to set their own password on the target account. The last transaction to commit overwrites the first, enabling an attacker who possesses a valid recovery token to replace the legitimate user's password with one of their choosing.\n\nA secondary defect in the same endpoint (confirm_account) allowed a valid recovery link to be used to set an empty or trivially short password (e.g., three characters). The view handler performed only a manual equality comparison between the two password fields and never invoked the form's validation logic, bypassing the intended minimum-length and complexity constraints.\n\nThe affected component is the user account recovery endpoint (/user/confirm_account/<token>) and the associated token verification and consumption logic in the User model (website/models/user.py) and the view layer (website/web/views/user.py).",
10+
"severity": [
11+
{
12+
"type": "CVSS_V4",
13+
"score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
14+
}
15+
],
16+
"affected": [],
17+
"references": [
18+
{
19+
"type": "ADVISORY",
20+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-101041"
21+
},
22+
{
23+
"type": "WEB",
24+
"url": "https://github.com/vulnerability-lookup/vulnerability-lookup/commit/5462bab62d76df852619e01eb67da36c023c8c40"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://github.com/vulnerability-lookup/vulnerability-lookup/commit/ad6f22882975516adf193a1a920aaa54025c71d4"
29+
}
30+
],
31+
"database_specific": {
32+
"cwe_ids": [
33+
"CWE-20"
34+
],
35+
"severity": "MODERATE",
36+
"github_reviewed": false,
37+
"github_reviewed_at": null,
38+
"nvd_published_at": "2026-09-27T15:16:27Z"
39+
}
40+
}
Lines changed: 56 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,56 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-mvf3-jgvq-79hc",
4+
"modified": "2026-09-27T15:31:07Z",
5+
"published": "2026-09-27T15:31:07Z",
6+
"aliases": [
7+
"CVE-2026-101032"
8+
],
9+
"details": "navi through 2.24.0 fails to properly escape cheatsheet variable values when substituting them into shell commands. Attackers can inject shell metacharacters through crafted file names in suggestion command directories to execute arbitrary commands with victim privileges.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"
14+
},
15+
{
16+
"type": "CVSS_V4",
17+
"score": "CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
18+
}
19+
],
20+
"affected": [],
21+
"references": [
22+
{
23+
"type": "ADVISORY",
24+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-101032"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://github.com/denisidoro/navi/issues/1037"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://github.com/denisidoro/navi"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://github.com/denisidoro/navi/blob/5515367dc8a2a561d2d82b8352f729b1da4120d3/src/commands/core/actor.rs#L159-L193"
37+
},
38+
{
39+
"type": "WEB",
40+
"url": "https://github.com/denisidoro/navi/blob/5515367dc8a2a561d2d82b8352f729b1da4120d3/src/common/shell.rs#L39-L50"
41+
},
42+
{
43+
"type": "WEB",
44+
"url": "https://www.vulncheck.com/advisories/navi-through-2.24.0-os-command-injection-via-cheatsheet-variables"
45+
}
46+
],
47+
"database_specific": {
48+
"cwe_ids": [
49+
"CWE-78"
50+
],
51+
"severity": "HIGH",
52+
"github_reviewed": false,
53+
"github_reviewed_at": null,
54+
"nvd_published_at": "2026-09-27T14:16:28Z"
55+
}
56+
}
Lines changed: 60 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,60 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-mxrg-842r-h599",
4+
"modified": "2026-09-27T15:31:07Z",
5+
"published": "2026-09-27T15:31:07Z",
6+
"aliases": [
7+
"CVE-2026-100871"
8+
],
9+
"details": "Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 fail to include firewall identification in JWT tokens issued by separate Admin and Shop API endpoints. Attackers can register a shop customer account using an administrator's email address and obtain a token that the Admin API resolves to that administrator, granting full administrative access.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
14+
},
15+
{
16+
"type": "CVSS_V4",
17+
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
18+
}
19+
],
20+
"affected": [],
21+
"references": [
22+
{
23+
"type": "WEB",
24+
"url": "https://github.com/Sylius/Sylius/security/advisories/GHSA-f6mx-qxjc-55xf"
25+
},
26+
{
27+
"type": "ADVISORY",
28+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-100871"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://github.com/Sylius/Sylius/pull/19213"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://github.com/Sylius/Sylius/commit/cdfb672a4d174eb2c73159b25cf5b5f44088f45c"
37+
},
38+
{
39+
"type": "WEB",
40+
"url": "https://github.com/Sylius/Sylius"
41+
},
42+
{
43+
"type": "WEB",
44+
"url": "https://github.com/Sylius/Sylius/releases/tag/v2.2.9"
45+
},
46+
{
47+
"type": "WEB",
48+
"url": "https://www.vulncheck.com/advisories/sylius-before-1.12.25-1.13.17-1.14.20-2.1.16-and-2.2.9-jwt-audience-confusion-allows-admin-api-authentication"
49+
}
50+
],
51+
"database_specific": {
52+
"cwe_ids": [
53+
"CWE-287"
54+
],
55+
"severity": "HIGH",
56+
"github_reviewed": false,
57+
"github_reviewed_at": null,
58+
"nvd_published_at": "2026-09-27T13:16:38Z"
59+
}
60+
}
Lines changed: 64 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,64 @@
1+
{
2+
"schema_version": "1.4.0",
3+
"id": "GHSA-xxhh-mxcg-vmh8",
4+
"modified": "2026-09-27T15:31:07Z",
5+
"published": "2026-09-27T15:31:07Z",
6+
"aliases": [
7+
"CVE-2026-101033"
8+
],
9+
"details": "KitchenOwl through 0.7.10 fails to verify that category IDs belong to the caller's household in expense and item operations. Authenticated attackers can enumerate category IDs from other households to read their category names, budgets, and colors, breaking household isolation.",
10+
"severity": [
11+
{
12+
"type": "CVSS_V3",
13+
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
14+
},
15+
{
16+
"type": "CVSS_V4",
17+
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
18+
}
19+
],
20+
"affected": [],
21+
"references": [
22+
{
23+
"type": "ADVISORY",
24+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-101033"
25+
},
26+
{
27+
"type": "WEB",
28+
"url": "https://github.com/TomBursch/kitchenowl/issues/1154"
29+
},
30+
{
31+
"type": "WEB",
32+
"url": "https://github.com/TomBursch/kitchenowl/pull/1155"
33+
},
34+
{
35+
"type": "WEB",
36+
"url": "https://github.com/TomBursch/kitchenowl/commit/c15f6cb21a98d5eb70746bee6b63773a6d6a6251"
37+
},
38+
{
39+
"type": "WEB",
40+
"url": "https://github.com/TomBursch/kitchenowl"
41+
},
42+
{
43+
"type": "WEB",
44+
"url": "https://github.com/TomBursch/kitchenowl/blob/09aaf5fbd2343fcc10b12e906c63c3764dd38919/backend/app/controller/expense/expense_controller.py#L115-L118"
45+
},
46+
{
47+
"type": "WEB",
48+
"url": "https://github.com/TomBursch/kitchenowl/blob/09aaf5fbd2343fcc10b12e906c63c3764dd38919/backend/app/controller/item/item_controller.py#L86-L88"
49+
},
50+
{
51+
"type": "WEB",
52+
"url": "https://www.vulncheck.com/advisories/kitchenowl-through-0.7.10-idor-via-unchecked-category-id"
53+
}
54+
],
55+
"database_specific": {
56+
"cwe_ids": [
57+
"CWE-639"
58+
],
59+
"severity": "MODERATE",
60+
"github_reviewed": false,
61+
"github_reviewed_at": null,
62+
"nvd_published_at": "2026-09-27T14:16:29Z"
63+
}
64+
}

0 commit comments

Comments
 (0)