Skip to content

File tree

9 files changed

+69
-21
lines changed

9 files changed

+69
-21
lines changed

advisories/github-reviewed/2025/12/GHSA-6h2f-wjhf-4wjx/GHSA-6h2f-wjhf-4wjx.json

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-6h2f-wjhf-4wjx",
4-
"modified": "2025-12-10T20:21:54Z",
4+
"modified": "2025-12-11T15:51:44Z",
55
"published": "2025-12-10T20:21:54Z",
66
"aliases": [
77
"CVE-2025-67720"
@@ -43,6 +43,10 @@
4343
"type": "WEB",
4444
"url": "https://github.com/Mayuri-Chan/pyrofork/security/advisories/GHSA-6h2f-wjhf-4wjx"
4545
},
46+
{
47+
"type": "ADVISORY",
48+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-67720"
49+
},
4650
{
4751
"type": "WEB",
4852
"url": "https://github.com/Mayuri-Chan/pyrofork/commit/2f2d515575cc9c360bd74340a61a1d2b1e1f1f95"
@@ -59,6 +63,6 @@
5963
"severity": "MODERATE",
6064
"github_reviewed": true,
6165
"github_reviewed_at": "2025-12-10T20:21:54Z",
62-
"nvd_published_at": null
66+
"nvd_published_at": "2025-12-11T02:16:19Z"
6367
}
6468
}

advisories/github-reviewed/2025/12/GHSA-6w82-v552-wjw2/GHSA-6w82-v552-wjw2.json

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-6w82-v552-wjw2",
4-
"modified": "2025-12-10T20:02:23Z",
4+
"modified": "2025-12-11T15:49:34Z",
55
"published": "2025-12-09T17:24:21Z",
66
"aliases": [
77
"CVE-2025-67648"
@@ -97,6 +97,10 @@
9797
"type": "WEB",
9898
"url": "https://github.com/shopware/shopware/security/advisories/GHSA-6w82-v552-wjw2"
9999
},
100+
{
101+
"type": "ADVISORY",
102+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-67648"
103+
},
100104
{
101105
"type": "WEB",
102106
"url": "https://github.com/shopware/shopware/commit/c9242c02c84595d9fa3e2adf6a264bc90a657b58"
@@ -113,6 +117,6 @@
113117
"severity": "HIGH",
114118
"github_reviewed": true,
115119
"github_reviewed_at": "2025-12-09T17:24:21Z",
116-
"nvd_published_at": null
120+
"nvd_published_at": "2025-12-11T00:16:23Z"
117121
}
118122
}

advisories/github-reviewed/2025/12/GHSA-898v-775g-777c/GHSA-898v-775g-777c.json

Lines changed: 14 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-898v-775g-777c",
4-
"modified": "2025-12-09T19:16:37Z",
4+
"modified": "2025-12-11T15:49:17Z",
55
"published": "2025-12-09T17:19:42Z",
66
"aliases": [
77
"CVE-2025-67510"
@@ -43,9 +43,21 @@
4343
"type": "WEB",
4444
"url": "https://github.com/neuron-core/neuron-ai/security/advisories/GHSA-898v-775g-777c"
4545
},
46+
{
47+
"type": "ADVISORY",
48+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-67510"
49+
},
50+
{
51+
"type": "WEB",
52+
"url": "https://github.com/neuron-core/neuron-ai/commit/44bab85d92bf162898ee48d0bcef6ba0d29b59c9"
53+
},
4654
{
4755
"type": "PACKAGE",
4856
"url": "https://github.com/neuron-core/neuron-ai"
57+
},
58+
{
59+
"type": "WEB",
60+
"url": "https://github.com/neuron-core/neuron-ai/releases/tag/2.8.12"
4961
}
5062
],
5163
"database_specific": {
@@ -56,6 +68,6 @@
5668
"severity": "CRITICAL",
5769
"github_reviewed": true,
5870
"github_reviewed_at": "2025-12-09T17:19:42Z",
59-
"nvd_published_at": null
71+
"nvd_published_at": "2025-12-10T23:15:48Z"
6072
}
6173
}

advisories/github-reviewed/2025/12/GHSA-9rwj-6rc7-p77c/GHSA-9rwj-6rc7-p77c.json

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-9rwj-6rc7-p77c",
4-
"modified": "2025-12-10T18:43:24Z",
4+
"modified": "2025-12-11T15:49:44Z",
55
"published": "2025-12-10T00:02:21Z",
66
"aliases": [
77
"CVE-2025-67644"
@@ -40,6 +40,10 @@
4040
"type": "WEB",
4141
"url": "https://github.com/langchain-ai/langgraph/security/advisories/GHSA-9rwj-6rc7-p77c"
4242
},
43+
{
44+
"type": "ADVISORY",
45+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-67644"
46+
},
4347
{
4448
"type": "WEB",
4549
"url": "https://github.com/langchain-ai/langgraph/commit/297242913f8ad2143ee3e2f72e67db0911d48e2a"
@@ -56,6 +60,6 @@
5660
"severity": "HIGH",
5761
"github_reviewed": true,
5862
"github_reviewed_at": "2025-12-10T00:02:21Z",
59-
"nvd_published_at": null
63+
"nvd_published_at": "2025-12-11T00:16:23Z"
6064
}
6165
}

advisories/github-reviewed/2025/12/GHSA-f4cf-9rvr-2rcx/GHSA-f4cf-9rvr-2rcx.json

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-f4cf-9rvr-2rcx",
4-
"modified": "2025-12-10T20:02:40Z",
4+
"modified": "2025-12-11T15:51:21Z",
55
"published": "2025-12-10T18:20:01Z",
66
"aliases": [
77
"CVE-2025-67717"
@@ -84,6 +84,10 @@
8484
"type": "WEB",
8585
"url": "https://github.com/zitadel/zitadel/security/advisories/GHSA-f4cf-9rvr-2rcx"
8686
},
87+
{
88+
"type": "ADVISORY",
89+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-67717"
90+
},
8791
{
8892
"type": "WEB",
8993
"url": "https://github.com/zitadel/zitadel/commit/826039c6208fe71df57b3a94c982b5ac5b0af12c"
@@ -100,6 +104,6 @@
100104
"severity": "MODERATE",
101105
"github_reviewed": true,
102106
"github_reviewed_at": "2025-12-10T18:20:01Z",
103-
"nvd_published_at": null
107+
"nvd_published_at": "2025-12-11T01:16:01Z"
104108
}
105109
}

advisories/github-reviewed/2025/12/GHSA-m654-769v-qjv7/GHSA-m654-769v-qjv7.json

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-m654-769v-qjv7",
4-
"modified": "2025-12-10T20:11:40Z",
4+
"modified": "2025-12-11T15:51:30Z",
55
"published": "2025-12-10T20:11:40Z",
66
"aliases": [
77
"CVE-2025-67718"
@@ -59,10 +59,18 @@
5959
"type": "WEB",
6060
"url": "https://github.com/formio/formio/security/advisories/GHSA-m654-769v-qjv7"
6161
},
62+
{
63+
"type": "ADVISORY",
64+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-67718"
65+
},
6266
{
6367
"type": "WEB",
6468
"url": "https://github.com/formio/formio/commit/1665b7c99e3cf3246db7ff0b4ff732231dc6903b"
6569
},
70+
{
71+
"type": "WEB",
72+
"url": "https://github.com/formio/formio/commit/1836bdd9f55f5888ff397c257b2108c09d3de478"
73+
},
6674
{
6775
"type": "PACKAGE",
6876
"url": "https://github.com/formio/formio"
@@ -75,6 +83,6 @@
7583
"severity": "HIGH",
7684
"github_reviewed": true,
7785
"github_reviewed_at": "2025-12-10T20:11:40Z",
78-
"nvd_published_at": null
86+
"nvd_published_at": "2025-12-11T01:16:01Z"
7987
}
8088
}

advisories/github-reviewed/2025/12/GHSA-mr6f-h57v-rpj5/GHSA-mr6f-h57v-rpj5.json

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-mr6f-h57v-rpj5",
4-
"modified": "2025-12-10T21:55:26Z",
4+
"modified": "2025-12-11T15:51:53Z",
55
"published": "2025-12-10T21:35:58Z",
66
"aliases": [
77
"CVE-2025-67716"
@@ -40,6 +40,10 @@
4040
"type": "WEB",
4141
"url": "https://github.com/auth0/nextjs-auth0/security/advisories/GHSA-mr6f-h57v-rpj5"
4242
},
43+
{
44+
"type": "ADVISORY",
45+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-67716"
46+
},
4347
{
4448
"type": "WEB",
4549
"url": "https://github.com/auth0/nextjs-auth0/commit/35eb321de3345ccf23e8c0d6f66c9f2f2f57d26c"
@@ -56,6 +60,6 @@
5660
"severity": "LOW",
5761
"github_reviewed": true,
5862
"github_reviewed_at": "2025-12-10T21:35:58Z",
59-
"nvd_published_at": null
63+
"nvd_published_at": "2025-12-11T01:16:00Z"
6064
}
6165
}

advisories/github-reviewed/2025/12/GHSA-wqv2-4wpg-8hc9/GHSA-wqv2-4wpg-8hc9.json

Lines changed: 9 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-wqv2-4wpg-8hc9",
4-
"modified": "2025-12-10T20:02:32Z",
4+
"modified": "2025-12-11T15:51:11Z",
55
"published": "2025-12-10T17:18:37Z",
66
"aliases": [
77
"CVE-2025-67713"
@@ -10,8 +10,8 @@
1010
"details": "### Summary\n`redirect_url` is treated as safe when `url.Parse(...).IsAbs()` is false. Protocol-relative URLs like `//ikotaslabs.com` have an empty scheme and pass that check, allowing post-login redirects to attacker-controlled sites.\n\n### Details\n- `url.Parse(\"//ikotaslabs.com\")` => empty Scheme, Host=\"ikotaslabs.com\".\n- `IsAbs()` returns false for `//ikotaslabs.com`, so the code treats it as allowed.\n- Browser resolves `//ikotaslabs.com` to current-origin scheme (e.g. `https://ikotaslabs.com`), enabling phishing flows after login.\n\n### PoC\n1. Send or visit: `http://localhost/login?redirect_url=//ikotaslabs.com` \n2. Complete normal login flow. \n3. After login the app redirects to `https://ikotaslabs.com` (or `http://` depending on origin).\n\n### Acknowledgements \nThis vulnerability was discovered using the automated vulnerability analysis tools **VulScribe** and **PwnML**. \nThe research and tool development were conducted with support from the **MITOU Advanced Program (未踏アドバンスト事業)**, \nadministered by the **Information-technology Promotion Agency (IPA), Japan**.",
1111
"severity": [
1212
{
13-
"type": "CVSS_V3",
14-
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N"
13+
"type": "CVSS_V4",
14+
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"
1515
}
1616
],
1717
"affected": [
@@ -43,6 +43,10 @@
4343
"type": "WEB",
4444
"url": "https://github.com/miniflux/v2/security/advisories/GHSA-wqv2-4wpg-8hc9"
4545
},
46+
{
47+
"type": "ADVISORY",
48+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-67713"
49+
},
4650
{
4751
"type": "WEB",
4852
"url": "https://github.com/miniflux/v2/commit/76df99f3a3db234cf6b312be5e771485213d03c7"
@@ -56,9 +60,9 @@
5660
"cwe_ids": [
5761
"CWE-601"
5862
],
59-
"severity": "LOW",
63+
"severity": "MODERATE",
6064
"github_reviewed": true,
6165
"github_reviewed_at": "2025-12-10T17:18:37Z",
62-
"nvd_published_at": null
66+
"nvd_published_at": "2025-12-11T01:16:00Z"
6367
}
6468
}

advisories/github-reviewed/2025/12/GHSA-x93p-w2ch-fg67/GHSA-x93p-w2ch-fg67.json

Lines changed: 6 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-x93p-w2ch-fg67",
4-
"modified": "2025-12-10T20:02:47Z",
4+
"modified": "2025-12-11T15:50:05Z",
55
"published": "2025-12-10T18:20:55Z",
66
"aliases": [
77
"CVE-2025-67719"
@@ -40,6 +40,10 @@
4040
"type": "WEB",
4141
"url": "https://github.com/ibexa/user/security/advisories/GHSA-x93p-w2ch-fg67"
4242
},
43+
{
44+
"type": "ADVISORY",
45+
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-67719"
46+
},
4347
{
4448
"type": "WEB",
4549
"url": "https://github.com/ibexa/user/commit/9d485bf385e6401c9f7ee80287d8ccd00f73dcf4"
@@ -60,6 +64,6 @@
6064
"severity": "CRITICAL",
6165
"github_reviewed": true,
6266
"github_reviewed_at": "2025-12-10T18:20:55Z",
63-
"nvd_published_at": null
67+
"nvd_published_at": "2025-12-11T02:16:18Z"
6468
}
6569
}

0 commit comments

Comments
 (0)