{"advisories":{"phalcon\/cphalcon":[{"advisoryId":"PKSA-n2s8-x5tr-m78t","packageName":"phalcon\/cphalcon","remoteId":"GHSA-hrwp-4hh9-c8r8","title":"Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE)","link":"https:\/\/github.com\/advisories\/GHSA-hrwp-4hh9-c8r8","cve":"CVE-2026-59989","affectedVersions":"\u003C=5.15.0","source":"GitHub","reportedAt":"2026-08-21 20:55:56","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-hrwp-4hh9-c8r8"}]}],"yourls\/yourls":[{"advisoryId":"PKSA-v9p2-y9c7-y991","packageName":"yourls\/yourls","remoteId":"GHSA-5h77-88j3-r659","title":"YOURLS has stored XSS in referrer statistics chart via crafted Referer header","link":"https:\/\/github.com\/advisories\/GHSA-5h77-88j3-r659","cve":"CVE-2026-63135","affectedVersions":"\u003E=1.5.1,\u003C=1.10.3","source":"GitHub","reportedAt":"2026-08-21 20:57:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-5h77-88j3-r659"}]}],"getgrav\/grav":[{"advisoryId":"PKSA-rjzr-vkvg-cvmf","packageName":"getgrav\/grav","remoteId":"GHSA-8hgv-xc77-jmcr","title":"Grav: Page editors can inject arbitrary script into rendered pages via the Twig sandbox\u0027s assets.addJs\/addCss allowlist, escalating to super-admin","link":"https:\/\/github.com\/advisories\/GHSA-8hgv-xc77-jmcr","cve":null,"affectedVersions":"\u003C=2.0.19","source":"GitHub","reportedAt":"2026-08-21 19:14:59","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8hgv-xc77-jmcr"}]},{"advisoryId":"PKSA-wh99-p4gt-7bkp","packageName":"getgrav\/grav","remoteId":"GHSA-vwg3-w8w3-pc79","title":"Grav: .htaccess file extension rules bypass via case variation on case-insensitive filesystems","link":"https:\/\/github.com\/advisories\/GHSA-vwg3-w8w3-pc79","cve":"CVE-2026-62673","affectedVersions":"\u003C2.0.4","source":"GitHub","reportedAt":"2026-08-19 19:32:38","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-vwg3-w8w3-pc79"}]}],"backpack\/crud":[{"advisoryId":"PKSA-1hj4-7f8v-mbzt","packageName":"backpack\/crud","remoteId":"GHSA-42vx-43vc-x6pr","title":"Laravel Backpack CRUD: HasMany\/MorphMany relation fields allow cross-tenant record re-parenting (IDOR) via attachManyRelation","link":"https:\/\/github.com\/advisories\/GHSA-42vx-43vc-x6pr","cve":"CVE-2026-57570","affectedVersions":"\u003E=6.0.0,\u003C6.8.15|\u003E=7.0.0,\u003C7.0.47","source":"GitHub","reportedAt":"2026-08-20 18:42:31","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-42vx-43vc-x6pr"}]},{"advisoryId":"PKSA-x88v-wcq5-j3kt","packageName":"backpack\/crud","remoteId":"GHSA-xpv2-hrfc-hw62","title":"Laravel Backpack CRUD: Unverified password change in MyAccountController via mass assignment","link":"https:\/\/github.com\/advisories\/GHSA-xpv2-hrfc-hw62","cve":"CVE-2026-54175","affectedVersions":"\u003E=7.0.0-alpha.1,\u003C7.0.34|\u003C6.8.11","source":"GitHub","reportedAt":"2026-08-20 18:38:26","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-xpv2-hrfc-hw62"}]},{"advisoryId":"PKSA-wb9h-r8p2-f7xj","packageName":"backpack\/crud","remoteId":"GHSA-9fw9-8c49-qch8","title":"Laravel Backpack CRUD: MyAccountController allows changing the login email without a current-password check","link":"https:\/\/github.com\/advisories\/GHSA-9fw9-8c49-qch8","cve":"CVE-2026-54176","affectedVersions":"\u003E=7.0.0,\u003C7.0.38|\u003E=6.0.0,\u003C6.8.14","source":"GitHub","reportedAt":"2026-08-20 18:38:30","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-9fw9-8c49-qch8"}]},{"advisoryId":"PKSA-4pjj-nc36-rj91","packageName":"backpack\/crud","remoteId":"GHSA-8q2w-pv9p-mjvc","title":"Laravel Backpack CRUD: HasUploadFields keeps the attacker-supplied file extension \u2014 public-disk uploads of `shell.php` reach the webserver","link":"https:\/\/github.com\/advisories\/GHSA-8q2w-pv9p-mjvc","cve":"CVE-2026-54177","affectedVersions":"\u003E=7.0.0,\u003C7.0.38|\u003E=6.0.0,\u003C6.8.14","source":"GitHub","reportedAt":"2026-08-20 18:38:34","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8q2w-pv9p-mjvc"}]},{"advisoryId":"PKSA-kbc2-vykn-d61h","packageName":"backpack\/crud","remoteId":"GHSA-8xjm-wqrp-2f25","title":"Laravel Backpack CRUD: Arbitrary file deletion via attacker-controlled clear_\u003Cattr\u003E[] in HasUploadFields::uploadMultipleFilesToDisk","link":"https:\/\/github.com\/advisories\/GHSA-8xjm-wqrp-2f25","cve":"CVE-2026-54178","affectedVersions":"\u003E=7.0.0,\u003C7.0.35|\u003E=6.0.0,\u003C6.8.12|\u003E=5.0.0,\u003C6.0.0","source":"GitHub","reportedAt":"2026-08-20 18:38:39","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8xjm-wqrp-2f25"}]},{"advisoryId":"PKSA-gr8y-xsj7-jw48","packageName":"backpack\/crud","remoteId":"GHSA-8hw4-7qjr-3wxg","title":"Laravel Backpack CRUD: SingleBase64Image accepts any base64 payload behind a `data:image` prefix \u2014 SVG-with-script lands on the public disk","link":"https:\/\/github.com\/advisories\/GHSA-8hw4-7qjr-3wxg","cve":"CVE-2026-54179","affectedVersions":"\u003E=7.0.0,\u003C7.0.38|\u003E=6.0.0,\u003C6.8.14","source":"GitHub","reportedAt":"2026-08-20 18:38:43","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-8hw4-7qjr-3wxg"}]},{"advisoryId":"PKSA-s7xs-gg49-zwxc","packageName":"backpack\/crud","remoteId":"GHSA-vgmv-8xjc-6rch","title":"Laravel Backpack CRUD: CRUD panel query scopes are not enforced on Update, Delete, and Reorder (cross-tenant IDOR)","link":"https:\/\/github.com\/advisories\/GHSA-vgmv-8xjc-6rch","cve":"CVE-2026-54180","affectedVersions":"\u003E=7.0.0,\u003C7.0.38|\u003E=6.0.0,\u003C6.8.14","source":"GitHub","reportedAt":"2026-08-20 18:38:46","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-vgmv-8xjc-6rch"}]},{"advisoryId":"PKSA-5phc-pmxf-y81y","packageName":"backpack\/crud","remoteId":"GHSA-mmg4-322v-6jvc","title":"Laravel Backpack CRUD: Stored XSS in the color column \u2014 the `@if($column[\u0027escaped\u0027])` branches are inverted","link":"https:\/\/github.com\/advisories\/GHSA-mmg4-322v-6jvc","cve":"CVE-2026-54181","affectedVersions":"\u003E=7.0.0,\u003C7.0.38|\u003E=6.0.0,\u003C6.8.14","source":"GitHub","reportedAt":"2026-08-20 18:38:50","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mmg4-322v-6jvc"}]},{"advisoryId":"PKSA-qrrt-7bj6-f81q","packageName":"backpack\/crud","remoteId":"GHSA-mrc5-3mm3-45c5","title":"Laravel Backpack CRUD: OS command injection in Stats::makeCurlRequest via attacker-controlled Host header (pre-auth)","link":"https:\/\/github.com\/advisories\/GHSA-mrc5-3mm3-45c5","cve":"CVE-2026-54182","affectedVersions":"\u003E=7.0.0,\u003C7.0.36|\u003E=6.0.0,\u003C6.8.13|\u003E=5.0.0,\u003C5.6.2|\u003E=4.1.0,\u003C4.1.72","source":"GitHub","reportedAt":"2026-08-20 18:38:55","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-mrc5-3mm3-45c5"}]}],"winter\/wn-system-module":[{"advisoryId":"PKSA-xv7p-39zk-tqqd","packageName":"winter\/wn-system-module","remoteId":"GHSA-2223-f22x-24cq","title":"Winter: Local File Inclusion through =include directives in JavaScript asset compilation","link":"https:\/\/github.com\/advisories\/GHSA-2223-f22x-24cq","cve":null,"affectedVersions":"\u003C1.2.13","source":"GitHub","reportedAt":"2026-08-20 18:44:17","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-2223-f22x-24cq"}]},{"advisoryId":"PKSA-wtw3-z7vh-tcrk","packageName":"winter\/wn-system-module","remoteId":"GHSA-8cfw-pcwh-v63w","title":"Winter: Authenticated Twig sandbox escape in CMS SecurityPolicy (bypass of CVE-2024-54149)","link":"https:\/\/github.com\/advisories\/GHSA-8cfw-pcwh-v63w","cve":null,"affectedVersions":"\u003E=1.2.7,\u003C1.2.13","source":"GitHub","reportedAt":"2026-08-20 18:44:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-8cfw-pcwh-v63w"}]}],"winter\/wn-backend-module":[{"advisoryId":"PKSA-54hz-1x12-hy82","packageName":"winter\/wn-backend-module","remoteId":"GHSA-58fp-mcx6-7qf9","title":"Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assets","link":"https:\/\/github.com\/advisories\/GHSA-58fp-mcx6-7qf9","cve":"CVE-2026-63179","affectedVersions":"\u003C=1.2.12","source":"GitHub","reportedAt":"2026-08-20 18:43:33","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-58fp-mcx6-7qf9"}]},{"advisoryId":"PKSA-b1tx-fpj9-bp5n","packageName":"winter\/wn-backend-module","remoteId":"GHSA-7mpf-4465-7fc2","title":"Winter: Stored XSS through Backend List widget image columns","link":"https:\/\/github.com\/advisories\/GHSA-7mpf-4465-7fc2","cve":null,"affectedVersions":"\u003E=1.1.0,\u003C1.2.14","source":"GitHub","reportedAt":"2026-08-20 18:44:41","composerRepository":"https:\/\/packagist.org","severity":"low","sources":[{"name":"GitHub","remoteId":"GHSA-7mpf-4465-7fc2"}]},{"advisoryId":"PKSA-g4kv-c5yp-h2rm","packageName":"winter\/wn-backend-module","remoteId":"GHSA-mpmw-f6h6-3g26","title":"Winter: My Account preview exposes another backend user\u0027s profile by record ID","link":"https:\/\/github.com\/advisories\/GHSA-mpmw-f6h6-3g26","cve":null,"affectedVersions":"=1.2.13","source":"GitHub","reportedAt":"2026-08-20 18:44:45","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-mpmw-f6h6-3g26"}]},{"advisoryId":"PKSA-kk7w-bn2w-32z8","packageName":"winter\/wn-backend-module","remoteId":"GHSA-fm29-4mq3-phg6","title":"Winter: ImportExportController AJAX handlers bypass granular import\/export permission gate","link":"https:\/\/github.com\/advisories\/GHSA-fm29-4mq3-phg6","cve":null,"affectedVersions":"\u003C=1.2.13","source":"GitHub","reportedAt":"2026-08-20 18:44:50","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-fm29-4mq3-phg6"}]},{"advisoryId":"PKSA-qr5m-g14w-86df","packageName":"winter\/wn-backend-module","remoteId":"GHSA-5cwr-5jxg-pcf6","title":"Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles","link":"https:\/\/github.com\/advisories\/GHSA-5cwr-5jxg-pcf6","cve":null,"affectedVersions":"\u003C=1.2.13","source":"GitHub","reportedAt":"2026-08-20 18:44:54","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5cwr-5jxg-pcf6"}]},{"advisoryId":"PKSA-r35b-91gt-bn2p","packageName":"winter\/wn-backend-module","remoteId":"GHSA-p2ch-c2c3-4xm5","title":"Winter: CSRF through AJAX handler names reachable as backend page actions","link":"https:\/\/github.com\/advisories\/GHSA-p2ch-c2c3-4xm5","cve":null,"affectedVersions":"\u003E=1.0.319,\u003C1.2.14","source":"GitHub","reportedAt":"2026-08-20 18:44:59","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-p2ch-c2c3-4xm5"}]},{"advisoryId":"PKSA-5ts5-4cbq-8ssk","packageName":"winter\/wn-backend-module","remoteId":"GHSA-hq84-x37p-j6q5","title":"Winter: Reflected XSS through the search query parameter in the backend Table widget","link":"https:\/\/github.com\/advisories\/GHSA-hq84-x37p-j6q5","cve":null,"affectedVersions":"\u003E=1.0.420,\u003C=1.2.13","source":"GitHub","reportedAt":"2026-08-20 18:45:04","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-hq84-x37p-j6q5"}]},{"advisoryId":"PKSA-dbvq-twhc-nj83","packageName":"winter\/wn-backend-module","remoteId":"GHSA-3277-h8g9-qj5f","title":"Winter: Authenticated IDOR in backend FileUpload widget allows cross-user access to attachment metadata","link":"https:\/\/github.com\/advisories\/GHSA-3277-h8g9-qj5f","cve":"CVE-2026-54256","affectedVersions":"\u003C=1.2.12","source":"GitHub","reportedAt":"2026-08-20 18:39:56","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-3277-h8g9-qj5f"}]}],"snipe\/snipe-it":[{"advisoryId":"PKSA-9n96-zyz7-nxh9","packageName":"snipe\/snipe-it","remoteId":"GHSA-3hgv-jr5j-cg9x","title":"Snipe-IT: Chained Information Disclosure and IDOR Leads to Full EULA File Takeover","link":"https:\/\/github.com\/advisories\/GHSA-3hgv-jr5j-cg9x","cve":"CVE-2026-55694","affectedVersions":"\u003C8.6.3","source":"GitHub","reportedAt":"2026-08-19 19:32:18","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-3hgv-jr5j-cg9x"}]},{"advisoryId":"PKSA-2v9y-4jt3-bxpm","packageName":"snipe\/snipe-it","remoteId":"GHSA-r9r3-g9fp-3q4q","title":"Snipe-IT: Maintenance Record Disclosure via Missing Authorization on GET","link":"https:\/\/github.com\/advisories\/GHSA-r9r3-g9fp-3q4q","cve":"CVE-2026-55703","affectedVersions":"\u003C8.6.3","source":"GitHub","reportedAt":"2026-08-19 19:32:25","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-r9r3-g9fp-3q4q"}]},{"advisoryId":"PKSA-9ywr-ywdr-gcrt","packageName":"snipe\/snipe-it","remoteId":"GHSA-c8qc-wf67-342w","title":"Snipe-IT: Stored DOM XSS via table selected-count IDs","link":"https:\/\/github.com\/advisories\/GHSA-c8qc-wf67-342w","cve":"CVE-2026-61807","affectedVersions":"\u003C8.6.2","source":"GitHub","reportedAt":"2026-08-19 19:32:32","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-c8qc-wf67-342w"}]}],"librenms\/librenms":[{"advisoryId":"PKSA-m3bp-hsvq-mjs5","packageName":"librenms\/librenms","remoteId":"GHSA-jf24-8g2h-2wg7","title":"LibreNMS Vulnerable to Remote Code Execution via AboutController","link":"https:\/\/github.com\/advisories\/GHSA-jf24-8g2h-2wg7","cve":null,"affectedVersions":"\u003C26.5.0","source":"GitHub","reportedAt":"2026-08-18 21:17:11","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-jf24-8g2h-2wg7"}]},{"advisoryId":"PKSA-jmpz-3j3j-881p","packageName":"librenms\/librenms","remoteId":"GHSA-7cj5-v4pp-v632","title":"LibreNMS: Stored XSS via graph_descr admin config settings echoed without escaping to all authenticated users","link":"https:\/\/github.com\/advisories\/GHSA-7cj5-v4pp-v632","cve":null,"affectedVersions":"\u003C26.7.0","source":"GitHub","reportedAt":"2026-08-18 21:17:20","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-7cj5-v4pp-v632"}]},{"advisoryId":"PKSA-9d1b-7dzj-kkfs","packageName":"librenms\/librenms","remoteId":"GHSA-7gww-x7fh-jf9j","title":"LibreNMS: SSRF-driven stored XSS via Oxidized API response fields in device showconfig page","link":"https:\/\/github.com\/advisories\/GHSA-7gww-x7fh-jf9j","cve":null,"affectedVersions":"\u003C26.7.0","source":"GitHub","reportedAt":"2026-08-18 21:17:23","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7gww-x7fh-jf9j"}]},{"advisoryId":"PKSA-8dtq-rfyc-264h","packageName":"librenms\/librenms","remoteId":"GHSA-c9fv-cgmm-2wg7","title":"LibreNMS Vulnerable to Remote Code Execution by Signal Alert Transportation module","link":"https:\/\/github.com\/advisories\/GHSA-c9fv-cgmm-2wg7","cve":"CVE-2026-55182","affectedVersions":"\u003E=21.6.0,\u003C26.5.0","source":"GitHub","reportedAt":"2026-08-18 17:59:56","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-c9fv-cgmm-2wg7"}]}],"mineadmin\/mineadmin":[{"advisoryId":"PKSA-56hm-hvjp-d16p","packageName":"mineadmin\/mineadmin","remoteId":"GHSA-59xm-4m8c-g3xj","title":"MineAdmin Vulnerable to Path Traversal via Unsanitized identifier in Plugin Install\/Uninstall","link":"https:\/\/github.com\/advisories\/GHSA-59xm-4m8c-g3xj","cve":"CVE-2026-55224","affectedVersions":"\u003C3.2.0-alpha.2","source":"GitHub","reportedAt":"2026-08-18 20:40:37","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-59xm-4m8c-g3xj"}]}],"froxlor\/froxlor":[{"advisoryId":"PKSA-nrnn-2mjw-x29c","packageName":"froxlor\/froxlor","remoteId":"GHSA-43gm-9rr3-cx7g","title":"Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover","link":"https:\/\/github.com\/advisories\/GHSA-43gm-9rr3-cx7g","cve":"CVE-2026-54347","affectedVersions":"\u003C=2.3.7","source":"GitHub","reportedAt":"2026-08-18 20:47:53","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-43gm-9rr3-cx7g"}]},{"advisoryId":"PKSA-tbmy-ntqq-5hz6","packageName":"froxlor\/froxlor","remoteId":"GHSA-w27m-rmmf-g5w4","title":"Froxlor: Second-Order SQL Injection via `Admins.add` `ipaddress` Parameter Allows Full Database Exfiltration","link":"https:\/\/github.com\/advisories\/GHSA-w27m-rmmf-g5w4","cve":"CVE-2026-54348","affectedVersions":"\u003C2.3.8","source":"GitHub","reportedAt":"2026-08-18 20:47:59","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-w27m-rmmf-g5w4"}]},{"advisoryId":"PKSA-prvy-3kk5-2fyv","packageName":"froxlor\/froxlor","remoteId":"GHSA-5rw4-4665-cvwf","title":"Froxlor DomainZones.add allows DNS zone-file RR injection via record\/type fields","link":"https:\/\/github.com\/advisories\/GHSA-5rw4-4665-cvwf","cve":"CVE-2026-54543","affectedVersions":"\u003C=2.3.7","source":"GitHub","reportedAt":"2026-08-18 20:48:04","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-5rw4-4665-cvwf"}]},{"advisoryId":"PKSA-2y9n-tpcf-96wh","packageName":"froxlor\/froxlor","remoteId":"GHSA-xpr4-8vp6-c87j","title":"Froxlor has CSRF Vulnerability in AJAX Endpoint \u2014 Missing Cross-Site Request Forgery Protection","link":"https:\/\/github.com\/advisories\/GHSA-xpr4-8vp6-c87j","cve":"CVE-2026-55593","affectedVersions":"\u003C=2.3.7","source":"GitHub","reportedAt":"2026-08-18 20:48:30","composerRepository":"https:\/\/packagist.org","severity":"medium","sources":[{"name":"GitHub","remoteId":"GHSA-xpr4-8vp6-c87j"}]},{"advisoryId":"PKSA-bk7h-s9s3-p5rt","packageName":"froxlor\/froxlor","remoteId":"GHSA-7788-ghfq-c6mh","title":"Froxlor: Credential and 2FA secret disclosure via Froxlor API endpoints","link":"https:\/\/github.com\/advisories\/GHSA-7788-ghfq-c6mh","cve":"CVE-2026-62988","affectedVersions":"\u003C2.3.8","source":"GitHub","reportedAt":"2026-08-18 20:48:35","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-7788-ghfq-c6mh"}]}],"paragonie\/sodium_compat":[{"advisoryId":"PKSA-32g2-byr9-drtw","packageName":"paragonie\/sodium_compat","remoteId":"paragonie\/sodium_compat\/2026-08-18.yaml","title":"Incorrect Ed25519 public key validation","link":"https:\/\/github.com\/paragonie\/sodium_compat\/pull\/206","cve":null,"affectedVersions":"\u003E=2,\u003C2.5.1|\u003C1.24.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-18 00:00:00","composerRepository":"https:\/\/packagist.org","severity":null,"sources":[{"name":"FriendsOfPHP\/security-advisories","remoteId":"paragonie\/sodium_compat\/2026-08-18.yaml"}]}],"mcp\/sdk":[{"advisoryId":"PKSA-p9gd-j6gr-6f9t","packageName":"mcp\/sdk","remoteId":"mcp\/sdk\/CVE-2026-53965.yaml","title":"Client HttpTransport SSE buffer grows unbounded when server withholds the event delimiter","link":"https:\/\/github.com\/modelcontextprotocol\/php-sdk\/security\/advisories\/GHSA-7m52-jw36-44r3","cve":"CVE-2026-53965","affectedVersions":"\u003E=0.5.0,\u003C0.7.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-08-14 06:19:00","composerRepository":"https:\/\/packagist.org","severity":"high","sources":[{"name":"GitHub","remoteId":"GHSA-7m52-jw36-44r3"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"mcp\/sdk\/CVE-2026-53965.yaml"}]}],"mtdowling\/jmespath.php":[{"advisoryId":"PKSA-mnyp-475s-ywph","packageName":"mtdowling\/jmespath.php","remoteId":"mtdowling\/jmespath.php\/CVE-2026-54133.yaml","title":"CompilerRuntime code injection via unescaped function names","link":"https:\/\/github.com\/jmespath\/jmespath.php\/security\/advisories\/GHSA-pcw8-m77r-2528","cve":"CVE-2026-54133","affectedVersions":"\u003C2.9.1","source":"FriendsOfPHP\/security-advisories","reportedAt":"2026-06-11 10:41:50","composerRepository":"https:\/\/packagist.org","severity":"critical","sources":[{"name":"GitHub","remoteId":"GHSA-pcw8-m77r-2528"},{"name":"FriendsOfPHP\/security-advisories","remoteId":"mtdowling\/jmespath.php\/CVE-2026-54133.yaml"}]}]}}