github.com/xyproto/algernon
Activity
- Latest release
- 1mo ago
- Total releases
- 20
- Cadence
- ~2 months
- Last 12 months
- 7
Reach
- Stars
- —
Details
- First release
- Aug 04, 2022
| Version | Released | |
|---|---|---|
v1.17.11
patch
|
v1.17.11
patch
Dependencies (53)
+ 45 more |
|
v1.17.10
patch
|
v1.17.10
patch
Dependencies (53)
+ 45 more |
|
v1.17.9
patch
|
v1.17.9
patch
Dependencies (53)
+ 45 more |
|
v1.17.8
patch
1 CVE
CVE-2026-52792
GO-2026-5903
GHSA-mm6c-5j6x-hq8m
Jul 07, 2026
Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Fixed in
1.17.9
Updated Jul 07, 2026 · Source: OSV.dev |
v1.17.8
patch
Dependencies (53)
+ 45 more |
|
v1.17.7
patch
2 CVEs
CVE-2026-52792
GO-2026-5903
GHSA-mm6c-5j6x-hq8m
Jul 07, 2026
Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Fixed in
1.17.9
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-48126
GO-2026-5460
GHSA-jc3j-x6pg-4hmv
Jun 25, 2026
Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Fixed in
1.17.8
References Updated Jun 25, 2026 · Source: OSV.dev |
v1.17.7
patch
Dependencies (52)
+ 44 more |
|
v1.17.6
patch
7 CVEs
CVE-2026-52792
GO-2026-5903
GHSA-mm6c-5j6x-hq8m
Jul 07, 2026
Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Fixed in
1.17.9
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-45721
GO-2026-5772
GHSA-xwcr-wm99-g9jc
Jun 25, 2026
Algernon: handler.lua discovery walks parent directories above the server root in github.com/xyproto/algernon Algernon: handler.lua discovery walks parent directories above the server root in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46431
GO-2026-5440
GHSA-hw27-4v2q-5qff
Jun 25, 2026
Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * in github.com/xyproto/algernon Fixed in
1.17.7
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46430
GO-2026-5401
GHSA-gj84-924c-48fx
Jun 25, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-48126
GO-2026-5460
GHSA-jc3j-x6pg-4hmv
Jun 25, 2026
Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Fixed in
1.17.8
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5300
GHSA-9v4j-7g44-qcqw
Jun 25, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45728
GO-2026-5385
GHSA-fwqx-8365-9983
Jun 25, 2026
Algernon: Single-file mode unconditionally enables debug mode in github.com/xyproto/algernon Algernon: Single-file mode unconditionally enables debug mode in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev |
v1.17.6
patch
Dependencies (51)
+ 43 more |
|
v1.17.5
patch
7 CVEs
CVE-2026-52792
GO-2026-5903
GHSA-mm6c-5j6x-hq8m
Jul 07, 2026
Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Fixed in
1.17.9
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-45721
GO-2026-5772
GHSA-xwcr-wm99-g9jc
Jun 25, 2026
Algernon: handler.lua discovery walks parent directories above the server root in github.com/xyproto/algernon Algernon: handler.lua discovery walks parent directories above the server root in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46431
GO-2026-5440
GHSA-hw27-4v2q-5qff
Jun 25, 2026
Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * in github.com/xyproto/algernon Fixed in
1.17.7
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46430
GO-2026-5401
GHSA-gj84-924c-48fx
Jun 25, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-48126
GO-2026-5460
GHSA-jc3j-x6pg-4hmv
Jun 25, 2026
Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Fixed in
1.17.8
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5300
GHSA-9v4j-7g44-qcqw
Jun 25, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45728
GO-2026-5385
GHSA-fwqx-8365-9983
Jun 25, 2026
Algernon: Single-file mode unconditionally enables debug mode in github.com/xyproto/algernon Algernon: Single-file mode unconditionally enables debug mode in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev |
v1.17.5
patch
Dependencies (51)
+ 43 more |
|
v1.17.4
patch
8 CVEs
CVE-2026-52792
GO-2026-5903
GHSA-mm6c-5j6x-hq8m
Jul 07, 2026
Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Fixed in
1.17.9
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-45721
GO-2026-5772
GHSA-xwcr-wm99-g9jc
Jun 25, 2026
Algernon: handler.lua discovery walks parent directories above the server root in github.com/xyproto/algernon Algernon: handler.lua discovery walks parent directories above the server root in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46431
GO-2026-5440
GHSA-hw27-4v2q-5qff
Jun 25, 2026
Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * in github.com/xyproto/algernon Fixed in
1.17.7
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46430
GO-2026-5401
GHSA-gj84-924c-48fx
Jun 25, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-48126
GO-2026-5460
GHSA-jc3j-x6pg-4hmv
Jun 25, 2026
Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Fixed in
1.17.8
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5300
GHSA-9v4j-7g44-qcqw
Jun 25, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45728
GO-2026-5385
GHSA-fwqx-8365-9983
Jun 25, 2026
Algernon: Single-file mode unconditionally enables debug mode in github.com/xyproto/algernon Algernon: Single-file mode unconditionally enables debug mode in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-65754
GO-2025-4228
GHSA-8jqm-8qm3-qgqm
Dec 15, 2025
Algernon Cross-Site Scripting vulnerability in github.com/xyproto/algernon Algernon Cross-Site Scripting vulnerability in github.com/xyproto/algernon Fixed in
1.17.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.17.4
patch
Dependencies (50)
+ 42 more |
|
v1.17.3
patch
8 CVEs
CVE-2026-52792
GO-2026-5903
GHSA-mm6c-5j6x-hq8m
Jul 07, 2026
Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Fixed in
1.17.9
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-45721
GO-2026-5772
GHSA-xwcr-wm99-g9jc
Jun 25, 2026
Algernon: handler.lua discovery walks parent directories above the server root in github.com/xyproto/algernon Algernon: handler.lua discovery walks parent directories above the server root in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46431
GO-2026-5440
GHSA-hw27-4v2q-5qff
Jun 25, 2026
Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * in github.com/xyproto/algernon Fixed in
1.17.7
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46430
GO-2026-5401
GHSA-gj84-924c-48fx
Jun 25, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-48126
GO-2026-5460
GHSA-jc3j-x6pg-4hmv
Jun 25, 2026
Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Fixed in
1.17.8
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5300
GHSA-9v4j-7g44-qcqw
Jun 25, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45728
GO-2026-5385
GHSA-fwqx-8365-9983
Jun 25, 2026
Algernon: Single-file mode unconditionally enables debug mode in github.com/xyproto/algernon Algernon: Single-file mode unconditionally enables debug mode in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-65754
GO-2025-4228
GHSA-8jqm-8qm3-qgqm
Dec 15, 2025
Algernon Cross-Site Scripting vulnerability in github.com/xyproto/algernon Algernon Cross-Site Scripting vulnerability in github.com/xyproto/algernon Fixed in
1.17.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.17.3
patch
Dependencies (50)
+ 42 more |
|
v1.17.2
patch
8 CVEs
CVE-2026-52792
GO-2026-5903
GHSA-mm6c-5j6x-hq8m
Jul 07, 2026
Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Fixed in
1.17.9
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-45721
GO-2026-5772
GHSA-xwcr-wm99-g9jc
Jun 25, 2026
Algernon: handler.lua discovery walks parent directories above the server root in github.com/xyproto/algernon Algernon: handler.lua discovery walks parent directories above the server root in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46431
GO-2026-5440
GHSA-hw27-4v2q-5qff
Jun 25, 2026
Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * in github.com/xyproto/algernon Fixed in
1.17.7
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46430
GO-2026-5401
GHSA-gj84-924c-48fx
Jun 25, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-48126
GO-2026-5460
GHSA-jc3j-x6pg-4hmv
Jun 25, 2026
Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Fixed in
1.17.8
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5300
GHSA-9v4j-7g44-qcqw
Jun 25, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45728
GO-2026-5385
GHSA-fwqx-8365-9983
Jun 25, 2026
Algernon: Single-file mode unconditionally enables debug mode in github.com/xyproto/algernon Algernon: Single-file mode unconditionally enables debug mode in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-65754
GO-2025-4228
GHSA-8jqm-8qm3-qgqm
Dec 15, 2025
Algernon Cross-Site Scripting vulnerability in github.com/xyproto/algernon Algernon Cross-Site Scripting vulnerability in github.com/xyproto/algernon Fixed in
1.17.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.17.2
patch
Dependencies (50)
+ 42 more |
|
v1.17.1
patch
8 CVEs
CVE-2026-52792
GO-2026-5903
GHSA-mm6c-5j6x-hq8m
Jul 07, 2026
Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Fixed in
1.17.9
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-45721
GO-2026-5772
GHSA-xwcr-wm99-g9jc
Jun 25, 2026
Algernon: handler.lua discovery walks parent directories above the server root in github.com/xyproto/algernon Algernon: handler.lua discovery walks parent directories above the server root in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46431
GO-2026-5440
GHSA-hw27-4v2q-5qff
Jun 25, 2026
Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * in github.com/xyproto/algernon Fixed in
1.17.7
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46430
GO-2026-5401
GHSA-gj84-924c-48fx
Jun 25, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-48126
GO-2026-5460
GHSA-jc3j-x6pg-4hmv
Jun 25, 2026
Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Fixed in
1.17.8
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5300
GHSA-9v4j-7g44-qcqw
Jun 25, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45728
GO-2026-5385
GHSA-fwqx-8365-9983
Jun 25, 2026
Algernon: Single-file mode unconditionally enables debug mode in github.com/xyproto/algernon Algernon: Single-file mode unconditionally enables debug mode in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-65754
GO-2025-4228
GHSA-8jqm-8qm3-qgqm
Dec 15, 2025
Algernon Cross-Site Scripting vulnerability in github.com/xyproto/algernon Algernon Cross-Site Scripting vulnerability in github.com/xyproto/algernon Fixed in
1.17.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.17.1
patch
Dependencies (50)
+ 42 more |
|
v1.17.0
minor
8 CVEs
CVE-2026-52792
GO-2026-5903
GHSA-mm6c-5j6x-hq8m
Jul 07, 2026
Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Fixed in
1.17.9
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-45721
GO-2026-5772
GHSA-xwcr-wm99-g9jc
Jun 25, 2026
Algernon: handler.lua discovery walks parent directories above the server root in github.com/xyproto/algernon Algernon: handler.lua discovery walks parent directories above the server root in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46431
GO-2026-5440
GHSA-hw27-4v2q-5qff
Jun 25, 2026
Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * in github.com/xyproto/algernon Fixed in
1.17.7
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46430
GO-2026-5401
GHSA-gj84-924c-48fx
Jun 25, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-48126
GO-2026-5460
GHSA-jc3j-x6pg-4hmv
Jun 25, 2026
Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Fixed in
1.17.8
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5300
GHSA-9v4j-7g44-qcqw
Jun 25, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45728
GO-2026-5385
GHSA-fwqx-8365-9983
Jun 25, 2026
Algernon: Single-file mode unconditionally enables debug mode in github.com/xyproto/algernon Algernon: Single-file mode unconditionally enables debug mode in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-65754
GO-2025-4228
GHSA-8jqm-8qm3-qgqm
Dec 15, 2025
Algernon Cross-Site Scripting vulnerability in github.com/xyproto/algernon Algernon Cross-Site Scripting vulnerability in github.com/xyproto/algernon Fixed in
1.17.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.17.0
minor
Dependencies (50)
+ 42 more |
|
v1.16.0
minor
8 CVEs
CVE-2026-52792
GO-2026-5903
GHSA-mm6c-5j6x-hq8m
Jul 07, 2026
Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Fixed in
1.17.9
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-45721
GO-2026-5772
GHSA-xwcr-wm99-g9jc
Jun 25, 2026
Algernon: handler.lua discovery walks parent directories above the server root in github.com/xyproto/algernon Algernon: handler.lua discovery walks parent directories above the server root in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46431
GO-2026-5440
GHSA-hw27-4v2q-5qff
Jun 25, 2026
Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * in github.com/xyproto/algernon Fixed in
1.17.7
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46430
GO-2026-5401
GHSA-gj84-924c-48fx
Jun 25, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-48126
GO-2026-5460
GHSA-jc3j-x6pg-4hmv
Jun 25, 2026
Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Fixed in
1.17.8
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5300
GHSA-9v4j-7g44-qcqw
Jun 25, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45728
GO-2026-5385
GHSA-fwqx-8365-9983
Jun 25, 2026
Algernon: Single-file mode unconditionally enables debug mode in github.com/xyproto/algernon Algernon: Single-file mode unconditionally enables debug mode in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-65754
GO-2025-4228
GHSA-8jqm-8qm3-qgqm
Dec 15, 2025
Algernon Cross-Site Scripting vulnerability in github.com/xyproto/algernon Algernon Cross-Site Scripting vulnerability in github.com/xyproto/algernon Fixed in
1.17.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.16.0
minor
Dependencies (47)
+ 39 more |
|
v1.15.5
patch
8 CVEs
CVE-2026-52792
GO-2026-5903
GHSA-mm6c-5j6x-hq8m
Jul 07, 2026
Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Fixed in
1.17.9
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-45721
GO-2026-5772
GHSA-xwcr-wm99-g9jc
Jun 25, 2026
Algernon: handler.lua discovery walks parent directories above the server root in github.com/xyproto/algernon Algernon: handler.lua discovery walks parent directories above the server root in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46431
GO-2026-5440
GHSA-hw27-4v2q-5qff
Jun 25, 2026
Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * in github.com/xyproto/algernon Fixed in
1.17.7
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46430
GO-2026-5401
GHSA-gj84-924c-48fx
Jun 25, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-48126
GO-2026-5460
GHSA-jc3j-x6pg-4hmv
Jun 25, 2026
Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Fixed in
1.17.8
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5300
GHSA-9v4j-7g44-qcqw
Jun 25, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45728
GO-2026-5385
GHSA-fwqx-8365-9983
Jun 25, 2026
Algernon: Single-file mode unconditionally enables debug mode in github.com/xyproto/algernon Algernon: Single-file mode unconditionally enables debug mode in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-65754
GO-2025-4228
GHSA-8jqm-8qm3-qgqm
Dec 15, 2025
Algernon Cross-Site Scripting vulnerability in github.com/xyproto/algernon Algernon Cross-Site Scripting vulnerability in github.com/xyproto/algernon Fixed in
1.17.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.15.5
patch
Dependencies (45)
+ 37 more |
|
v1.15.4
patch
8 CVEs
CVE-2026-52792
GO-2026-5903
GHSA-mm6c-5j6x-hq8m
Jul 07, 2026
Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Fixed in
1.17.9
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-45721
GO-2026-5772
GHSA-xwcr-wm99-g9jc
Jun 25, 2026
Algernon: handler.lua discovery walks parent directories above the server root in github.com/xyproto/algernon Algernon: handler.lua discovery walks parent directories above the server root in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46431
GO-2026-5440
GHSA-hw27-4v2q-5qff
Jun 25, 2026
Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * in github.com/xyproto/algernon Fixed in
1.17.7
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46430
GO-2026-5401
GHSA-gj84-924c-48fx
Jun 25, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-48126
GO-2026-5460
GHSA-jc3j-x6pg-4hmv
Jun 25, 2026
Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Fixed in
1.17.8
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5300
GHSA-9v4j-7g44-qcqw
Jun 25, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45728
GO-2026-5385
GHSA-fwqx-8365-9983
Jun 25, 2026
Algernon: Single-file mode unconditionally enables debug mode in github.com/xyproto/algernon Algernon: Single-file mode unconditionally enables debug mode in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-65754
GO-2025-4228
GHSA-8jqm-8qm3-qgqm
Dec 15, 2025
Algernon Cross-Site Scripting vulnerability in github.com/xyproto/algernon Algernon Cross-Site Scripting vulnerability in github.com/xyproto/algernon Fixed in
1.17.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.15.4
patch
Dependencies (45)
+ 37 more |
|
v1.15.3
patch
8 CVEs
CVE-2026-52792
GO-2026-5903
GHSA-mm6c-5j6x-hq8m
Jul 07, 2026
Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Fixed in
1.17.9
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-45721
GO-2026-5772
GHSA-xwcr-wm99-g9jc
Jun 25, 2026
Algernon: handler.lua discovery walks parent directories above the server root in github.com/xyproto/algernon Algernon: handler.lua discovery walks parent directories above the server root in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46431
GO-2026-5440
GHSA-hw27-4v2q-5qff
Jun 25, 2026
Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * in github.com/xyproto/algernon Fixed in
1.17.7
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46430
GO-2026-5401
GHSA-gj84-924c-48fx
Jun 25, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-48126
GO-2026-5460
GHSA-jc3j-x6pg-4hmv
Jun 25, 2026
Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Fixed in
1.17.8
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5300
GHSA-9v4j-7g44-qcqw
Jun 25, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45728
GO-2026-5385
GHSA-fwqx-8365-9983
Jun 25, 2026
Algernon: Single-file mode unconditionally enables debug mode in github.com/xyproto/algernon Algernon: Single-file mode unconditionally enables debug mode in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-65754
GO-2025-4228
GHSA-8jqm-8qm3-qgqm
Dec 15, 2025
Algernon Cross-Site Scripting vulnerability in github.com/xyproto/algernon Algernon Cross-Site Scripting vulnerability in github.com/xyproto/algernon Fixed in
1.17.5
References Updated Mar 03, 2026 · Source: OSV.dev |
v1.15.3
patch
Dependencies (44)
+ 36 more |
|
v1.15.2
patch
9 CVEs
CVE-2026-52792
GO-2026-5903
GHSA-mm6c-5j6x-hq8m
Jul 07, 2026
Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Fixed in
1.17.9
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-45721
GO-2026-5772
GHSA-xwcr-wm99-g9jc
Jun 25, 2026
Algernon: handler.lua discovery walks parent directories above the server root in github.com/xyproto/algernon Algernon: handler.lua discovery walks parent directories above the server root in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46431
GO-2026-5440
GHSA-hw27-4v2q-5qff
Jun 25, 2026
Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * in github.com/xyproto/algernon Fixed in
1.17.7
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46430
GO-2026-5401
GHSA-gj84-924c-48fx
Jun 25, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-48126
GO-2026-5460
GHSA-jc3j-x6pg-4hmv
Jun 25, 2026
Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Fixed in
1.17.8
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5300
GHSA-9v4j-7g44-qcqw
Jun 25, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45728
GO-2026-5385
GHSA-fwqx-8365-9983
Jun 25, 2026
Algernon: Single-file mode unconditionally enables debug mode in github.com/xyproto/algernon Algernon: Single-file mode unconditionally enables debug mode in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-65754
GO-2025-4228
GHSA-8jqm-8qm3-qgqm
Dec 15, 2025
Algernon Cross-Site Scripting vulnerability in github.com/xyproto/algernon Algernon Cross-Site Scripting vulnerability in github.com/xyproto/algernon Fixed in
1.17.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-26131
GHSA-g47h-fgcw-g4ph
May 31, 2023
Algernon engine and themes vulnerable to Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
All versions of the package github.com/xyproto/algernon/engine; all versions of the package github.com/xyproto/algernon/themes are vulnerable to Cross-site Scripting (XSS) via the References
Updated Nov 08, 2023 · Source: OSV.dev |
v1.15.2
patch
Dependencies (44)
+ 36 more |
|
v1.15.1
patch
9 CVEs
CVE-2026-52792
GO-2026-5903
GHSA-mm6c-5j6x-hq8m
Jul 07, 2026
Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Fixed in
1.17.9
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-45721
GO-2026-5772
GHSA-xwcr-wm99-g9jc
Jun 25, 2026
Algernon: handler.lua discovery walks parent directories above the server root in github.com/xyproto/algernon Algernon: handler.lua discovery walks parent directories above the server root in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46431
GO-2026-5440
GHSA-hw27-4v2q-5qff
Jun 25, 2026
Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * in github.com/xyproto/algernon Fixed in
1.17.7
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46430
GO-2026-5401
GHSA-gj84-924c-48fx
Jun 25, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-48126
GO-2026-5460
GHSA-jc3j-x6pg-4hmv
Jun 25, 2026
Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Fixed in
1.17.8
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5300
GHSA-9v4j-7g44-qcqw
Jun 25, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45728
GO-2026-5385
GHSA-fwqx-8365-9983
Jun 25, 2026
Algernon: Single-file mode unconditionally enables debug mode in github.com/xyproto/algernon Algernon: Single-file mode unconditionally enables debug mode in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-65754
GO-2025-4228
GHSA-8jqm-8qm3-qgqm
Dec 15, 2025
Algernon Cross-Site Scripting vulnerability in github.com/xyproto/algernon Algernon Cross-Site Scripting vulnerability in github.com/xyproto/algernon Fixed in
1.17.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-26131
GHSA-g47h-fgcw-g4ph
May 31, 2023
Algernon engine and themes vulnerable to Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
All versions of the package github.com/xyproto/algernon/engine; all versions of the package github.com/xyproto/algernon/themes are vulnerable to Cross-site Scripting (XSS) via the References
Updated Nov 08, 2023 · Source: OSV.dev |
v1.15.1
patch
Dependencies (44)
+ 36 more |
|
v1.15.0
minor
9 CVEs
CVE-2026-52792
GO-2026-5903
GHSA-mm6c-5j6x-hq8m
Jul 07, 2026
Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Fixed in
1.17.9
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-45721
GO-2026-5772
GHSA-xwcr-wm99-g9jc
Jun 25, 2026
Algernon: handler.lua discovery walks parent directories above the server root in github.com/xyproto/algernon Algernon: handler.lua discovery walks parent directories above the server root in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46431
GO-2026-5440
GHSA-hw27-4v2q-5qff
Jun 25, 2026
Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * in github.com/xyproto/algernon Fixed in
1.17.7
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46430
GO-2026-5401
GHSA-gj84-924c-48fx
Jun 25, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-48126
GO-2026-5460
GHSA-jc3j-x6pg-4hmv
Jun 25, 2026
Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Fixed in
1.17.8
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5300
GHSA-9v4j-7g44-qcqw
Jun 25, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45728
GO-2026-5385
GHSA-fwqx-8365-9983
Jun 25, 2026
Algernon: Single-file mode unconditionally enables debug mode in github.com/xyproto/algernon Algernon: Single-file mode unconditionally enables debug mode in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-65754
GO-2025-4228
GHSA-8jqm-8qm3-qgqm
Dec 15, 2025
Algernon Cross-Site Scripting vulnerability in github.com/xyproto/algernon Algernon Cross-Site Scripting vulnerability in github.com/xyproto/algernon Fixed in
1.17.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-26131
GHSA-g47h-fgcw-g4ph
May 31, 2023
Algernon engine and themes vulnerable to Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
All versions of the package github.com/xyproto/algernon/engine; all versions of the package github.com/xyproto/algernon/themes are vulnerable to Cross-site Scripting (XSS) via the References
Updated Nov 08, 2023 · Source: OSV.dev |
v1.15.0
minor
Dependencies (44)
+ 36 more |
|
v1.14.0
initial
9 CVEs
CVE-2026-52792
GO-2026-5903
GHSA-mm6c-5j6x-hq8m
Jul 07, 2026
Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Algernon vulnerable to server-side script source disclosure on Windows via NTFS filename in github.com/xyproto/algernon Fixed in
1.17.9
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-45721
GO-2026-5772
GHSA-xwcr-wm99-g9jc
Jun 25, 2026
Algernon: handler.lua discovery walks parent directories above the server root in github.com/xyproto/algernon Algernon: handler.lua discovery walks parent directories above the server root in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46431
GO-2026-5440
GHSA-hw27-4v2q-5qff
Jun 25, 2026
Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server sets Access-Control-Allow-Origin: * in github.com/xyproto/algernon Fixed in
1.17.7
References Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-46430
GO-2026-5401
GHSA-gj84-924c-48fx
Jun 25, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOS in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-48126
GO-2026-5460
GHSA-jc3j-x6pg-4hmv
Jun 25, 2026
Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir in github.com/xyproto/algernon Fixed in
1.17.8
References Updated Jun 25, 2026 · Source: OSV.dev
GO-2026-5300
GHSA-9v4j-7g44-qcqw
Jun 25, 2026
Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication in github.com/xyproto/algernon Algernon: Auto-refresh SSE event server binds to all interfaces with Access-Control-Allow-Origin: * and no authentication in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2026-45728
GO-2026-5385
GHSA-fwqx-8365-9983
Jun 25, 2026
Algernon: Single-file mode unconditionally enables debug mode in github.com/xyproto/algernon Algernon: Single-file mode unconditionally enables debug mode in github.com/xyproto/algernon Fixed in
1.17.7
Updated Jun 25, 2026 · Source: OSV.dev
CVE-2025-65754
GO-2025-4228
GHSA-8jqm-8qm3-qgqm
Dec 15, 2025
Algernon Cross-Site Scripting vulnerability in github.com/xyproto/algernon Algernon Cross-Site Scripting vulnerability in github.com/xyproto/algernon Fixed in
1.17.5
References Updated Mar 03, 2026 · Source: OSV.dev
CVE-2023-26131
GHSA-g47h-fgcw-g4ph
May 31, 2023
Algernon engine and themes vulnerable to Cross-site Scripting
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
All versions of the package github.com/xyproto/algernon/engine; all versions of the package github.com/xyproto/algernon/themes are vulnerable to Cross-site Scripting (XSS) via the References
Updated Nov 08, 2023 · Source: OSV.dev |
v1.14.0
initial
Dependencies (42)
+ 34 more |