
OSV.dev · 实时热榜
- 01MAL-2026-12055 · Malicious code in @zzzgenesis00/docker-api-client (npm)
Malicious code in @zzzgenesis00/docker-api-client (npm) Affected packages: npm/@zzzgenesis00/docker-api-client Attributes: No fix available
最高第 3 名11:25 达到11:25 首次观测上榜15:25 观测离榜累计约4小时 - 02MAL-2026-12056 · Malicious code in @zzzgenesis00/mnemonic-to-key (npm)
Malicious code in @zzzgenesis00/mnemonic-to-key (npm) Affected packages: npm/@zzzgenesis00/mnemonic-to-key Attributes: No fix available
最高第 1 名11:25 达到11:25 首次观测上榜15:25 观测离榜累计约4小时 - 03MAL-2026-12059 · Malicious code in bcore-bravo-eslint-config (npm)
Malicious code in bcore-bravo-eslint-config (npm) Affected packages: npm/bcore-bravo-eslint-config Attributes: No fix available
最高第 8 名11:25 达到11:25 首次观测上榜15:25 观测离榜累计约4小时 - 04MAL-2026-12060 · Malicious code in beaver-ui-card-large (npm)
Malicious code in beaver-ui-card-large (npm) Affected packages: npm/beaver-ui-card-large Attributes: No fix available
最高第 4 名11:25 达到11:25 首次观测上榜15:25 观测离榜累计约4小时 - 05MAL-2026-12064 · Malicious code in ckcc-protocol (npm)
Malicious code in ckcc-protocol (npm) Affected packages: npm/ckcc-protocol Attributes: No fix available
最高第 7 名11:25 达到11:25 首次观测上榜15:25 观测离榜累计约4小时 - 06MAL-2026-12067 · Malicious code in hwi-lib (npm)
Malicious code in hwi-lib (npm) Affected packages: npm/hwi-lib Attributes: No fix available
最高第 6 名11:25 达到11:25 首次观测上榜15:25 观测离榜累计约4小时 - 07MAL-2026-12068 · Malicious code in ledger-lib (npm)
Malicious code in ledger-lib (npm) Affected packages: npm/ledger-lib Attributes: No fix available
最高第 9 名11:25 达到11:25 首次观测上榜15:25 观测离榜累计约4小时 - 08MAL-2026-12073 · Malicious code in sso-tramvai-module-context-auth (npm)
Malicious code in sso-tramvai-module-context-auth (npm) Affected packages: npm/sso-tramvai-module-context-auth Attributes: No fix available
最高第 10 名11:25 达到11:25 首次观测上榜15:25 观测离榜累计约4小时 - 09MAL-2026-12078 · Malicious code in trezor-lib (npm)
Malicious code in trezor-lib (npm) Affected packages: npm/trezor-lib Attributes: No fix available
最高第 5 名11:25 达到11:25 首次观测上榜15:25 观测离榜累计约4小时 - 10MAL-2026-12079 · Malicious code in volna-boxy-di-test (npm)
Malicious code in volna-boxy-di-test (npm) Affected packages: npm/volna-boxy-di-test Attributes: No fix available
最高第 2 名11:25 达到11:25 首次观测上榜15:25 观测离榜累计约4小时 - 11GHSA-6vh2-wg4h-4vwj · Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated ` overrideConfig ` Spread in Prediction API
Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated ` overrideConfig ` Spread in Prediction API Affected packages: npm/flowise Attributes: Fix available、Severity - 8.8 (High)
最高第 1 名00:07 达到00:07 首次观测上榜03:35 观测离榜累计约3小时28分 - 12GHSA-c6xh-wv4j-ppv5 · Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses Affected packages: npm/flowise Attributes: Fix available、Severity - 7.6 (High)
最高第 2 名00:07 达到00:07 首次观测上榜03:35 观测离榜累计约3小时28分 - 13GHSA-x3hf-7cj6-3r4m · Flowise RCE via SQLite Record Manager Node
Flowise RCE via SQLite Record Manager Node Affected packages: npm/flowise、npm/flowise-components Attributes: Fix available、Severity - 9.4 (Critical)
最高第 1 名00:23 达到00:23 首次观测上榜03:35 观测离榜累计约3小时12分 - 14MAL-2026-12057 · Malicious code in @zzzgenesis00/playwrite (npm)
Malicious code in @zzzgenesis00/playwrite (npm) Affected packages: npm/@zzzgenesis00/playwrite Attributes: No fix available
最高第 12 名11:25 达到11:25 首次观测上榜14:37 观测离榜累计约3小时12分 - 15MAL-2026-12062 · Malicious code in boardwalk-js-tests (npm)
Malicious code in boardwalk-js-tests (npm) Affected packages: npm/boardwalk-js-tests Attributes: No fix available
最高第 11 名11:25 达到11:25 首次观测上榜14:37 观测离榜累计约3小时12分 - 16MAL-2026-12063 · Malicious code in checkout-create-pos-order-am (npm)
Malicious code in checkout-create-pos-order-am (npm) Affected packages: npm/checkout-create-pos-order-am Attributes: No fix available
最高第 13 名11:25 达到11:25 首次观测上榜14:37 观测离榜累计约3小时12分 - 17MAL-2026-12066 · Malicious code in hubert-appointment-v2-task-create-am (npm)
Malicious code in hubert-appointment-v2-task-create-am (npm) Affected packages: npm/hubert-appointment-v2-task-create-am Attributes: No fix available
最高第 14 名11:25 达到11:25 首次观测上榜14:37 观测离榜累计约3小时12分 - 18MAL-2026-12061 · Malicious code in bigops-eslint (npm)
Malicious code in bigops-eslint (npm) Affected packages: npm/bigops-eslint Attributes: No fix available
最高第 15 名11:25 达到11:25 首次观测上榜14:05 观测离榜累计约2小时40分 - 19MAL-2026-12065 · Malicious code in greatcall-customers-commandapi (npm)
Malicious code in greatcall-customers-commandapi (npm) Affected packages: npm/greatcall-customers-commandapi Attributes: No fix available
最高第 16 名11:25 达到11:25 首次观测上榜14:05 观测离榜累计约2小时40分 - 20GHSA-p5w8-m249-4r4v · Flowise: ` DELETE /api/v1/chatflows/:id ` does not validate resource type, allowing ` agentflows:delete ` and ` chatflows:delete ` to delete each other’s flow type
Flowise: ` DELETE /api/v1/chatflows/:id ` does not validate resource type, allowing ` agentflows:delete ` and ` chatflows:delete ` to delete each other’s flow type Affected packages: npm/flowise Attributes: Fix available、Severity - 7.1 (High)
最高第 1 名01:11 达到01:11 首次观测上榜03:51 观测离榜累计约2小时40分 - 21GHSA-x6vm-w76m-8j7g · Flowise: Remote Code Execution Vulnerability in CSVAgent
Flowise: Remote Code Execution Vulnerability in CSVAgent Affected packages: npm/flowise、npm/flowise-components Attributes: Fix available、Severity - 9.4 (Critical)
最高第 3 名00:07 达到00:07 首次观测上榜02:31 观测离榜累计约2小时24分 - 22MGASA-2026-0321 · Updated acl attr packages fix security vulnerabilities
Updated acl attr packages fix security vulnerabilities Affected packages: Mageia:10/acl、Mageia:10/attr、Mageia:9/acl、Mageia:9/attr Attributes: Fix available
最高第 1 名01:43 达到01:43 首次观测上榜04:07 观测离榜累计约2小时24分 - 23GHSA-xc48-889x-5qmw · Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE) Affected packages: npm/flowise、npm/flowise-components Attributes: Fix available、Severity - 8.7 (High)
最高第 1 名01:27 达到01:27 首次观测上榜03:51 观测离榜累计约2小时24分 - 24GHSA-vmv7-4m6c-3cg5 · Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified Affected packages: npm/flowise、npm/flowise-components Attributes: Fix available、Severity - 9.2 (Critical)
最高第 1 名00:00 达到当日首次采集时已在榜02:15 观测离榜累计约2小时16分 - 25MINI-6hhw-ww2x-gh6w · MinimOS/nextflow-26.04
Affected packages: MinimOS/nextflow-26.04 Attributes: No fix available
最高第 3 名00:00 达到当日首次采集时已在榜02:15 观测离榜累计约2小时16分 - 26MINI-c44m-f6gj-8f2h · MinimOS/nextflow-fips-25.10
Affected packages: MinimOS/nextflow-fips-25.10 Attributes: No fix available
最高第 2 名00:00 达到当日首次采集时已在榜02:15 观测离榜累计约2小时16分 - 27MINI-4823-mj8p-656r · MinimOS/nextflow-25.10
Affected packages: MinimOS/nextflow-25.10 Attributes: No fix available
最高第 7 名00:07 达到00:07 首次观测上榜02:15 观测离榜累计约2小时8分 - 28MINI-cp45-mgmj-5m2w · MinimOS/nextflow-fips-25.10
Affected packages: MinimOS/nextflow-fips-25.10 Attributes: No fix available
最高第 5 名00:07 达到00:07 首次观测上榜02:15 观测离榜累计约2小时8分 - 29MINI-j668-xgfg-62g6 · MinimOS/nextflow-25.10
Affected packages: MinimOS/nextflow-25.10 Attributes: No fix available
最高第 6 名00:07 达到00:07 首次观测上榜02:15 观测离榜累计约2小时8分 - 30MINI-r24f-fggx-hmcx · MinimOS/nextflow-fips-25.10
Affected packages: MinimOS/nextflow-fips-25.10 Attributes: No fix available
最高第 8 名00:07 达到00:07 首次观测上榜02:15 观测离榜累计约2小时8分 - 31MGASA-2026-0322 · Updated php packages fix security vulnerabilities
Updated php packages fix security vulnerabilities Affected packages: Mageia:9/php Attributes: Fix available
最高第 2 名01:43 达到01:43 首次观测上榜03:51 观测离榜累计约2小时8分 - 32GHSA-52fh-8v99-63c2 · Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE Affected packages: npm/flowise、npm/flowise-components Attributes: Fix available、Severity - 9.5 (Critical)
最高第 1 名01:59 达到01:59 首次观测上榜04:07 观测离榜累计约2小时8分 - 33GHSA-3769-jgqc-cxm7 · Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override Affected packages: npm/flowise、npm/flowise-components Attributes: Fix available、Severity - 9.4 (Critical)
最高第 4 名00:00 达到当日首次采集时已在榜01:59 观测离榜累计约2小时 - 34RHSA-2026:50691 · Red Hat Security Advisory: gstreamer1-plugins-ugly-free security update
Red Hat Security Advisory: gstreamer1-plugins-ugly-free security update Affected packages: Red Hat:rhel_eus:9.6::appstream/gstreamer1-plugins-ugly-free、Red Hat:rhel_eus:9.6::appstream/gstreamer1-plugins-ugly-free-debuginfo、Red Hat:rhel_eus:9.6::appstream/gstreamer1-plugins-ugly-free-debugsource Attributes: Fix available、Severity - 7.1 (High)
最高第 3 名18:53 达到18:53 首次观测上榜20:45 观测离榜累计约1小时52分 - 35RHSA-2026:7876 · Red Hat Security Advisory: go-toolset:rhel8 security update
Red Hat Security Advisory: go-toolset:rhel8 security update Affected packages: Red Hat:rhel_aus:8.6::appstream/delve、Red Hat:rhel_aus:8.6::appstream/delve-debuginfo、Red Hat:rhel_aus:8.6::appstream/delve-debugsource、Red Hat:rhel_aus:8.6::appstream/go-toolset、Red Hat:rhel_aus:8.6::appstream/golang、... 28 more Attributes: Fix available、Severity - 8.6 (High)
最高第 2 名18:53 达到18:53 首次观测上榜20:45 观测离榜累计约1小时52分 - 36RHSA-2026:9098 · Red Hat Security Advisory: skopeo security update
Red Hat Security Advisory: skopeo security update Affected packages: Red Hat:rhel_eus:9.6::appstream/skopeo、Red Hat:rhel_eus:9.6::appstream/skopeo-debuginfo、Red Hat:rhel_eus:9.6::appstream/skopeo-debugsource、Red Hat:rhel_eus:9.6::appstream/skopeo-tests Attributes: Fix available、Severity - 7.5 (High)
最高第 1 名18:53 达到18:53 首次观测上榜20:45 观测离榜累计约1小时52分 - 37GHSA-4j8x-x6v7-w9rq · Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation Affected packages: npm/flowise、npm/flowise-components Attributes: Fix available、Severity - 9.4 (Critical)
最高第 5 名02:15 达到02:15 首次观测上榜04:07 观测离榜累计约1小时52分 - 38GHSA-88pr-878c-24wf · Flowise: Authenticated arbitrary file write in the ` S3 Directory ` document loader via unsanitized S3 object keys
Flowise: Authenticated arbitrary file write in the ` S3 Directory ` document loader via unsanitized S3 object keys Affected packages: npm/flowise、npm/flowise-components Attributes: Fix available、Severity - 7.2 (High)
最高第 6 名02:15 达到02:15 首次观测上榜04:07 观测离榜累计约1小时52分 - 39GHSA-8r8h-6vcc-xhrv · Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure
Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure Affected packages: npm/flowise Attributes: Fix available、Severity - 7.1 (High)
最高第 7 名02:15 达到02:15 首次观测上榜04:07 观测离榜累计约1小时52分 - 40GHSA-chm3-vqcf-52rx · Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store
Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store Affected packages: npm/flowise Attributes: Fix available、Severity - 7.1 (High)
最高第 4 名02:15 达到02:15 首次观测上榜04:07 观测离榜累计约1小时52分 - 41GHSA-fr6g-7cq8-fg82 · Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history
Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history Affected packages: npm/flowise Attributes: Fix available、Severity - 8.3 (High)
最高第 3 名02:15 达到02:15 首次观测上榜04:07 观测离榜累计约1小时52分 - 42GHSA-rwrp-9823-p2xq · Flowise: Incomplete Credential Redaction Exposes Secrets via API
Flowise: Incomplete Credential Redaction Exposes Secrets via API Affected packages: npm/flowise Attributes: Fix available、Severity - 6.5 (Medium)
最高第 2 名02:15 达到02:15 首次观测上榜04:07 观测离榜累计约1小时52分 - 43GHSA-wch5-xp77-fxg4 · Flowise: Cross-Workspace OAuth2 Credential Metadata Leak
Flowise: Cross-Workspace OAuth2 Credential Metadata Leak Affected packages: npm/flowise Attributes: Fix available、Severity - 7.6 (High)
最高第 1 名02:15 达到02:15 首次观测上榜04:07 观测离榜累计约1小时52分 - 44RXSA-2026:49870 · Low: kernel security, bug fix, and enhancement update
Low: kernel security, bug fix, and enhancement update Affected packages: Rocky Linux:9/kernel Attributes: Fix available、Severity - 5.5 (Medium)
最高第 1 名02:31 达到02:31 首次观测上榜04:23 观测离榜累计约1小时52分 - 45MINI-cjr3-jj73-c6mm · MinimOS/nextflow-26.04
Affected packages: MinimOS/nextflow-26.04 Attributes: No fix available
最高第 5 名00:00 达到当日首次采集时已在榜01:43 观测离榜累计约1小时44分 - 46MINI-g4jx-jfh8-fgpc · MinimOS/nextflow-25.10
Affected packages: MinimOS/nextflow-25.10 Attributes: No fix available
最高第 6 名00:00 达到当日首次采集时已在榜01:43 观测离榜累计约1小时44分 - 47GHSA-ch52-px8q-f22j · Ghost: Server-side request forgery via DNS rebinding in external request handling
Ghost: Server-side request forgery via DNS rebinding in external request handling Affected packages: npm/ghost Attributes: Fix available、Severity - 4.0 (Medium)
最高第 2 名05:43 达到05:43 首次观测上榜07:19 观测离榜累计约1小时36分 - 48GHSA-g366-23fw-ggp6 · Ghost: Mobiledoc image-size fetch SSRF
Ghost: Mobiledoc image-size fetch SSRF Affected packages: npm/ghost Attributes: Fix available、Severity - 5.4 (Medium)
最高第 1 名05:43 达到05:43 首次观测上榜07:19 观测离榜累计约1小时36分 - 49GHSA-wvp2-4qqp-4h3r · Ghost: Private IP filtering bypass to make server-side requests to internal services
Ghost: Private IP filtering bypass to make server-side requests to internal services Affected packages: npm/ghost Attributes: Fix available、Severity - 5.8 (Medium)
最高第 3 名05:43 达到05:43 首次观测上榜07:19 观测离榜累计约1小时36分 - 50MAL-2026-11529 · Malicious code in @zzzgenesis00/crypto-config (npm)
Malicious code in @zzzgenesis00/crypto-config (npm) Affected packages: npm/@zzzgenesis00/crypto-config Attributes: No fix available
最高第 2 名07:19 达到07:19 首次观测上榜08:55 观测离榜累计约1小时36分


































































































