Skip to content

The catalog

Browse GHSA Reproductions

85 verified reproductions

RSS Feed

85 reproductions

Clear filters
Active GHSA
REPRO-2026-00153 published

Jupyter Server: path traversal via faulty startswith() root containment check

CVE-2026-35397 high Security Variant found pip
jupyter-server
25m 14s May 22, 2026
REPRO-2026-00152 published

apko: symlink-following path traversal writes files outside the build root

CVE-2026-42574 high Security Variant found go
apko
20m 23s May 22, 2026
REPRO-2026-00151 published

Twig: sandbox bypass via SourcePolicy filter check enables arbitrary PHP callables

CVE-2026-24425 high Security Variant found composer
twig/twig
13m 7s May 22, 2026
REPRO-2026-00150 published

PhpSpreadsheet: SSRF via unsafe stream wrapper in IOFactory::load()

CVE-2026-34084 critical Security Variant found composer
phpoffice/phpspreadsheet
12m 53s May 22, 2026
REPRO-2026-00149 published

PraisonAI: ZipSlip path traversal via unchecked tar symlink linkname in _safe_extractall

CVE-2026-44340 high Security Variant found pip
praisonai
17m 42s May 22, 2026
REPRO-2026-00148 published

Mistune: ReDoS via catastrophic backtracking in LINK_TITLE_RE

CVE-2026-33079 high Security Variant found pip
mistune
14m 50s May 22, 2026
REPRO-2026-00147 published

Faraday: SSRF via protocol-relative URL overriding base authority

CVE-2026-25765 medium Security Variant found rubygems
faraday
10m 15s May 22, 2026
REPRO-2026-00146 published

fast-uri: host confusion via percent-encoded authority delimiter in normalize()

CVE-2026-6322 high Security Variant found npm
fast-uri
10m 18s May 22, 2026
REPRO-2026-00145 published

fast-uri: path traversal via percent-encoded segments decoded before normalization

CVE-2026-6321 high Security Variant found npm
fast-uri
10m 8s May 22, 2026
REPRO-2026-00144 published

phpMyFAQ: unauthenticated SQL injection via User-Agent header in captcha API

CVE-2026-46364 critical Security Variant found composer
thorsten/phpmyfaq
62m 14s May 22, 2026
REPRO-2026-00143 published

@wdio/browserstack-service: OS command injection via crafted git branch name

CVE-2026-25244 critical Security Variant found npm
@wdio/browserstack-service
59m 49s May 22, 2026
REPRO-2026-00142 published

libheif: integer underflow out-of-bounds read crash via crafted HEIF stsc box

CVE-2026-32738 medium Security Variant found c
libheif
50m 30s May 22, 2026
REPRO-2026-00139 published

libjwt: JWT algorithm-confusion authentication bypass via RSA JWK without alg

CVE-2026-44699 critical Security Variant found c
libjwt
13m 26s May 22, 2026
REPRO-2026-00138 published

FastMCP: path traversal to authenticated SSRF in OpenAPIProvider _build_url()

CVE-2026-32871 critical Security Variant found pip
fastmcp
37m 15s May 22, 2026
REPRO-2026-00136 published

Microsoft APM: arbitrary file disclosure via symlink-following on apm install

CVE-2026-45539 high Security Variant found pip
apm
29m 1s May 22, 2026
REPRO-2026-00134 published

lodash: prototype pollution in _.unset/_.omit deletes global prototype methods

CVE-2025-13465 medium Security Variant found npm
lodash
29m 27s May 22, 2026
REPRO-2026-00124 published

Vim modeline handling for the tabpanel option allows sandbox escape via autocmd_add, enabling OS command execution when opening a crafted file.

CVE-2026-34714 critical Security Variant found github
Vim
19m 38s Apr 1, 2026
REPRO-2026-00119 published

PyTorch: weights_only Unpickler RCE via SETITEM Type Confusion

CVE-2026-24747 high Security Variant found pip
torch
48m 8s Mar 2, 2026
REPRO-2026-00115 published

eBay MCP Server Environment Variable Injection via Crafted Prompts

CVE-2026-27203 high Security npm
@anthropic-ai/ebay-mcp-server
11m 39s Feb 20, 2026
REPRO-2026-00114 published

D-Tale Remote Code Execution via Custom Filter Input

CVE-2026-27194 critical Security pip
dtale
11m 53s Feb 20, 2026