Jul 29 GHSA-pmwx-rm49-xv39 (activerecord-tenanted): ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal posted in •
Jul 29 CVE-2026-66066 (activestorage): Possible arbitrary file read and remote code execution in Active Storage variant processing posted in •
Jul 28 GHSA-r827-6rm4-59pg (alchemy_cms): Stored XSS via unsanitized SVG attachment replacement posted in •
Jul 28 CVE-2026-54659 (pagy): Pagy I18n locale option is not validated before being used in a file path posted in •
Jul 25 GHSA-r766-3v88-pfcf (where_is_waldo): where_is_waldo authenticates ActionCable connections from a client-supplied subject_id when no authenticate_proc is configured posted in •
Jul 22 GHSA-pm72-wq9v-wvfh (alchemy_cms): Stored XSS in PictureView figcaption via html_safe on User Caption posted in •
Jul 22 GHSA-7m8w-vg9p-qjr6 (alchemy_cms): Stored XSS in SelectView via Missing Server-Side Option Validation posted in •
Jul 20 GHSA-4825-p4xm-pcf2 (spree_api): Broken Access Control in `PATCH /api/v3/store/carts/:id/associate` (IDOR) posted in •