Aug 18 CVE-2026-55107 (kobako): kobako Sandbox Escape - guest eval reaches host RCE via method_missing → public_send (any bound Service) posted in •
Aug 12 CVE-2026-73330 (camaleon_cms): CamaleonCMS 2.9.1 Server-Side Template Injection via test_email Action posted in •
Aug 11 GHSA-mwm8-39rw-8826 (sqlite3): Use-After-Free in SQLite Aggregate Arguments in Heap-Allocated Argument Array posted in •
Aug 07 CVE-2026-71847 (json): Ruby JSON - JSON::ResumableParser#partial_value dereferences a freed input buffer and crashes on truncated duplicate-key streams posted in •
Jul 31 CVE-2026-66748 (camaleon_cms): Camaleon CMS (2.1.1 to 2.9.1) contains an authenticated RCE vulnerability posted in •
Jul 29 GHSA-pmwx-rm49-xv39 (activerecord-tenanted): ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal posted in •
Jul 29 CVE-2026-66066 (activestorage): Possible arbitrary file read and remote code execution in Active Storage variant processing posted in •
Jul 28 GHSA-wppq-8h64-w78r (alchemy_cms): Unauthenticated navigation-tree disclosure via GET /api/nodes (missing authorization) posted in •
Jul 28 GHSA-r827-6rm4-59pg (alchemy_cms): Stored XSS via unsanitized SVG attachment replacement posted in •
Jul 28 CVE-2026-54659 (pagy): Pagy I18n locale option is not validated before being used in a file path posted in •