Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
0xmrma/CVE-2026-46558
Plane’s V2 asset subsystem trusted workspace slugs and asset UUIDs without enforcing the right membership checks, which let one authenticated user read, copy, delete, and overwrite assets in other workspaces.
0xmrma/CVE-2026-45806
Penpot's remote image import let an authenticated file editor turn a normal media convenience feature into backend-origin SSRF because attacker-controlled URLs crossed into a redirect-following server fetch path without ...
0xmrma/CVE-2026-42089
A local package installation helper trusted caller-supplied package names too much. In yeoman-environment, missing generators could be installed without user confirmation, turning attacker-controlled project metadata int...
0xmrma/CVE-2026-34207
The SSRF filter checked hostname text, but the actual destination was decided later by DNS. That gap let attacker-controlled Webhook URLs reach loopback, metadata, and private network targets.
0xmrma/CVE-2026-34213
A low-privileged Docmost user could supply a victim attachmentId to the generic upload endpoint and overwrite another page's stored attachment inside the same workspace.
0xmrma/CVE-2026-34212
Docmost accepted a javascript: URL inside an attachment node, preserved it through storage and rendering, and turned it back into a clickable anchor in the Docmost origin.
0xmrma/CVE-2026-33146
A public share looked clean in the page tree, but the search endpoint told a different story. In Docmost, restricted child pages hidden from public share viewers could still leak through public share search results.
izxci/CVE-2026-54807
CVE-2026-54807 WooCommerce Privilege Escalation ║ ║ Unauthenticated Admin Role Assignment via Reg. Form | language: Shell
pawpic/CVE-2026-38526-POC
Proof of Concept of CVE-2026-38526 in Krayin CRM <= v2.2.x. Arbitrary File Upload leading to Remote Code Execution | language: Python
pateldhyeyit/CVE-2026-37149
CVE-2026-37149 - SQL Injection vulnerability in the scost parameter of search_products.php in GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0.
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
harshdattani23/Sovereign-DFIR
language: JavaScript | stars: 0 | forks: 0 | updated 2026-03-19T00:02:34Z | pushed 2026-03-19T00:02:30Z
NathanCavalcanti/pouchnexus
A multi-agent SOC/DFIR assistant powered by LangChain, LangGraph, and OpenAI models. Automates IOC extraction, MITRE ATT&CK mapping, CVE correlation, investigation planning, and report generation for cybersecurity incide...
deAlgorithm/DFIR_30DaysChallenge_SOC_Homelab
stars: 0 | forks: 0 | updated 2026-03-19T01:56:45Z | pushed 2026-03-19T01:56:42Z
gabrielbelli/claude-dfir-iris-plugin
language: Python | stars: 0 | forks: 0 | updated 2026-03-19T02:05:23Z | pushed 2026-03-19T02:05:20Z
rajiraman1224/BIT4644-DFIR
BIT4644-DigitalForensics | stars: 0 | forks: 0 | updated 2026-03-19T04:05:16Z | pushed 2026-03-19T04:05:12Z
zach115th/DFIR-IRIS-Templates
Templates and modules for DFIR-IRIS | topics: dfir-iris, misp | stars: 0 | forks: 0 | updated 2026-03-21T01:06:29Z | pushed 2026-03-21T01:06:26Z
zavetsec/Invoke-ZavetSecTriage
Zero-dependency DFIR triage script for Windows systems. PowerShell 5.1, no external tools required. | topics: blue-team, dfir, forensics, forensics-tools, incident-response, ir-tools, live-forensics, mitre-attack, powers...
HusteDev/wizsec
Python SDK for Wiz Cloud Security Tool | language: Python | stars: 0 | forks: 0 | updated 2026-03-19T03:25:24Z | pushed 2026-03-19T03:32:40Z
iosec-shekhar/awesome-ai-security
A curated list of the latest AI-powered security tools — offensive, defensive, and research-focused. Updated regularly. Contributions welcome. | stars: 1 | forks: 0 | updated 2026-03-19T04:59:30Z | pushed 2026-03-19T04:5...
sjkim1127/Nexuscore_MCP
AI-powered MCP server for dynamic malware analysis with Frida instrumentation, session-based debugging, and 46+ security tools | topics: ai-security, dynamic-analysis, frida, malware-analysis, mcp, mcp-server, reverse-en...