Sanaan Fayaz Wani

Advisories

Every advisory below is published, fixed and credited. Reports still in coordinated disclosure are not listed, named or hinted at until the maintainer ships a fix.

—

Full record

Eleven, published, fixed and credited. Descending by CVSS v3.1 base score. Summaries are keyed to the NR column and set below the table.

Published advisories, 2026-05-14 to 2026-10-02
NR Advisory Package CVSS Severity Weakness CWE Base vector Published
AV AC PR UI S C I A
01 CVE-2026-57516 ray 8.8 High Code injection 94 NLNR UHHH 2026-07-24
02 CVE-2026-45675 open-webui 8.1 High Privilege escalation 269 NHNN UHHH 2026-05-14
03 GHSA-pqxw-g93w-hj9x trigger.dev 8.1 High Improper isolation 653 NHNN UHHH 2026-10-02
04 GHSA-jc26-22qp-cgqj trigger.dev 7.9 High Missing authentication 306 AHLN CHHL 2026-09-14
05 GHSA-3c52-v5v2-3r56 budibase 7.7 High Server side request forgery 918 NLLN CHNN 2026-09-17
06 CVE-2026-59714 open-webui 7.1 High Missing authorization 862 NLLN UNHL 2026-07-24
07 GHSA-8p4j-2mm9-rh78 Tracecat 6.5 Medium Server side request forgery 918 NLLN UHNN 2026-09-20
08 CVE-2026-53577 io.kestra:kestra 6.5 Medium Incorrect authorization 863 NLLN UHNN 2026-06-03
09 CVE-2026-63342 github.com/hatchet-dev/hatchet 6.3 Medium Incorrect authorization 863 NHLN CHNN 2026-09-22
10 GHSA-59h8-w5q6-mfmp trigger.dev 5.3 Medium Missing authentication 306 NLNN UNLN 2026-10-02
11 CVE-2026-73301 @budibase/server 4.3 Medium Missing authorization 862 NLLN ULNN 2026-07-24
12 CVE-2026-59715 open-webui 3.1 Low Missing authentication 306 NHLN UNLN 2026-07-24

Every entry regenerates daily from the GitHub Advisory Database, so this list only ever shows work that is published, fixed and credited.

  1. 01 GHSA-pqxw-g93w-hj9x · trigger.dev Self-hosted deployment: default secrets allow unauthenticated infrastructure compromise.
  2. 02 GHSA-hhrp-gw25-jr43 · ray Arbitrary code execution via the ray.data.read_webdataset default decoder: pickle.loads(value) and torch.load(weights_only=False).
  3. 03 GHSA-h3ww-q6xx-w7x3 · open-webui LDAP and OAuth first-user race condition allows multiple admin accounts.
  4. 04 GHSA-jc26-22qp-cgqj · trigger.dev Supervisor workload API lacks cross-tenant authentication.
  5. 05 GHSA-3c52-v5v2-3r56 · budibase SSRF in AI table generation via uploadUrl: raw fetch without blacklist protection.
  6. 06 GHSA-x2ff-v5v8-m75m · open-webui Cross-channel message overwrite via the chat completion API, in both single-model and multimodel message_ids.
  7. 07 GHSA-r6v3-xxwj-9h42 · io.kestra:kestra Cross-execution file read via the preview endpoint (IDOR).
  8. 08 GHSA-g26x-m427-f48f · hatchet Cross-tenant durable task event log disclosure via a missing authorization check.
  9. 09 GHSA-59h8-w5q6-mfmp · trigger.dev Unauthenticated realtime stream data injection via run friendlyId.
  10. 10 GHSA-4qcj-m5wp-jmf4 · @budibase/server Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings.
  11. 11 GHSA-gmfw-g93r-vg53 · open-webui Unauthenticated WebSocket access to collaborative document handlers, ydoc:awareness:update and ydoc:document:leave.