WhisperX tag archive

#GHSA

This page collects WhisperX intelligence signals tagged #GHSA. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (5)

The Lab · 2026-04-01 10:26:55 · GitHub Issues

1. Next.js 15.x/16.x Security Update: Critical React Vulnerability Patched in v15.5.14

A critical security vulnerability in React 19 has triggered an urgent dependency update for Next.js, forcing developers to patch to version 15.5.14. The flaw, tracked as GHSA-9qr9-h5gf-34mp, directly impacts Next.js 15.x and 16.x applications using the App Router, stemming from upstream packages. This is not a routine ...

The Lab · 2026-04-19 11:22:32 · GitHub Issues

2. PHPUnit Security Flaw: GHSA-qrr6-mg7r-m243 Exposes Systems to Command Injection via INI Parsing

A critical security vulnerability in PHPUnit, the widely-used testing framework for PHP, exposes systems to potential command injection. The flaw, tracked as GHSA-qrr6-mg7r-m243, stems from how PHPUnit forwards PHP INI settings to child processes during isolated test execution. The framework passes these settings as `-...

The Lab · 2026-04-26 18:54:07 · GitHub Issues

3. Appsmith Patches Critical Authorization Bypass in App Viewer Datasource Import Feature

A critical authorization bypass vulnerability in Appsmith's App Viewer allowed datasource configurations to potentially leak through the import helper function, according to a recently disclosed GitHub Security Advisory (GHSA-93mf-9h52-gfxp). The flaw stemmed from a null permission check that effectively disabled acces...

The Lab · 2026-05-11 06:10:32 · GitHub Issues

4. Appsmith Patches Critical Path Traversal Vulnerability in FileOperationscev2Impl Affecting Git Operations

Appsmith has released a security fix addressing a path traversal vulnerability (GHSA-m4hv-9p7g-56vm) that exposed git file read and delete operations to directory escape attacks. The flaw, tracked as APP-15180, stemmed from incomplete path validation coverage in the `FileUtilsCEImpl` class, which originally enforced bo...

The Lab · 2026-05-14 09:48:25 · GitHub Issues

5. Critical Vulnerability in fast-xml-parser Allows Comment and CDATA Injection via Unescaped Delimiters

A security vulnerability has been identified in fast-xml-parser, a widely-used XML parsing library, enabling attackers to inject XML comments and CDATA sections through unescaped delimiters. Tracked as CVE-2026-41650 and GHSA-gh4j-gqv2-49f6, the flaw resides specifically in the XMLBuilder component of the parser. The v...