Intelligence Digest
github安全推送
GitHub 安全开源项目与漏洞监控情报推送
来自 GitHub Issues、仓库检索和关键词命中的 CVE / RCE / POC 动态。
popyue/CVE-2025-47812
RCE for WingFTP v4.7.3 | language: Python
SpringMVC nested RouterFunctions are not created properly
Hello!
Currently, I'm migrating over the non-reactive RouterFunctions with Spring Boot 4.0.3 using this code:
```java
@Bean
public RouterFunction<ServerResponse> testEndpoints() {
return RouterFunctions....
Outdated JDK requirement for CLI
Conflicting Java version requirements across the documentation: README.adoc states "You also need JDK 25.", build-plugin documentation states Java 17 is the default compiler level, and the CLI INSTALL says JDK v1.8 or ab...
parameciumzhang/Tell-Me-Root
基于cve-2026-24061 telnet远程认证绕过漏洞的批量检测利用工具 | language: Python
weekevy/SweetRice-CMS-1.5.1-RCE-Exploit
SweetRice CMS 1.5.1 Authenticated RCE Exploit - Python tool exploiting file upload vulnerability in SweetRice CMS 1.5.1 leading to remote code execution. Includes reverse shell automation and full exploitation workflow. ...
dxlerYT/CVE-2026-26331
Proof of Concept for an arbitrary command injection vulnerability in yt-dlp’s --netrc-cmd option (GHSA-g3gw-q23r-pgqm / CVE-2026-26331). Demonstrates shell command execution via maliciously crafted URLs in affected versi...
Add support for auto-configuring ExpressionJwtGrantedAuthoritiesConverter
Currently, the auto-configured `JwtAuthenticationConverter` (defined in `OAuth2ResourceServerJwtConfiguration`) uses a `JwtGrantedAuthoritiesConverter`. It would be nice if an `ExpressionJwtGrantedAuthoritiesConverter` w...
Missing constructor for type after upgrading to Spring Boot 4.0.1
When selecting a record type that is mapped as JSONB (e.g. via Hibernate’s `@Type(JsonBinaryType.class))`, the following error occurs:
```
org.springframework.dao.InvalidDataAccessApiUsageException: org.hibernate.query...
hexissam/CVE-2026-1731
CVE-2026-1731 — BeyondTrust Remote Code Execution Vulnerability | language: Python
dkstar11q/Ashwesker-CVE-2026-20045
CVE-2026-20045
优先展示中文安全团队维护的开源项目,兼顾工具落地场景和最近更新时间。
当前条件下没有命中网安开源项目。