Public CVE and GitHub Security Advisory credits.
-
GHSA-rh53-xvx2-j327 ·
CRITICAL
cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation · reporter · 2026-07-27 -
GHSA-52gf-6rpq-fgmx ·
HIGH
Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs endpoints · reporter · 2026-07-27 -
GHSA-6xj8-qv9j-xcjq ·
HIGH
Oh My Posh: Arbitrary command execution via template injection in the path segment · reporter · 2026-07-24 -
GHSA-c5f6-2rm9-2w8g ·
MEDIUM
Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass) · reporter · 2026-07-27 -
GHSA-fwjx-9p69-h25h ·
MEDIUM
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data · reporter · 2026-07-24




