Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
Zed Extension Sandbox Escape via Tar Symlink Following
OpenClaw affected by Stored XSS in Control UI via unsanitized assistant name/avatar in inline script injection
Claude Code Has Permission Deny Bypass Through Symbolic Links
Arbitrary Host File Overwrite via Symlink in Firecracker Jailer
@backstage/cli-common has a possible `resolveSafeChildPath` Symlink Chain Bypass
Copier safe template has arbitrary filesystem write access via directory symlinks when _preserve_symlinks: true
Copier safe template has arbitrary filesystem read access via symlinks when _preserve_symlinks: false
Forgejo before 13
NVIDIA Resiliency Extension for Linux contains a vulnerability in log aggregation, where an attacker could cause predictable log-file names
Ugreen DH2100+ USB symlink
Static Web Server is vulnerable to symbolic link Path Traversal
WebPros Plesk before 18
Apptainer ineffective application of selinux and apparmor --security options
Singluarity ineffectively applies of selinux / apparmor LSM process labels
Open OnDemand allowlist bypass using symlinks in directory downloads (TOCTOU)
runc: LSM labels can be bypassed with malicious config using dummy procfs files
container escape due to /dev/console mount and related races
runc container escape via "masked path" abuse due to mount race conditions
youki container escape and denial of service due to arbitrary write gadgets and procfs write redirects
youki container escape via "masked path" abuse due to mount race conditions
Showing 1 - 20 of 1,000+ results