Skip to content

Commit b675468

Browse files
committed
Update Security Policy
1 parent 4750087 commit b675468

1 file changed

Lines changed: 1 addition & 0 deletions

File tree

SECURITY.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -54,6 +54,7 @@ We aim to acknowledge reports within **10 business days** and provide updates th
5454
### 2026
5555
| CVE ID | Title | Severity (CVSS 3.1) | Affected Versions | Status | Advisory Link | Researcher |
5656
|--------|-------|---------------------|------------------|--------|---------------|------------|
57+
| CVE-2026-28789 | Arbitrary internal service access via /v1/sys/proxy when Cloudflare Tunnel is enabled on ZimaOS | 9.1 High | ZimaOS ≤ v1.5.0 | Fixed | [View Advisory](https://github.com/IceWhaleTech/ZimaOS/security/advisories/GHSA-vqqj-f979-8c8m) | DrDark1999 |
5758
| CVE-2026-28442 | ZimaOS v1.5.2-beta3 - Arbitrary Deletion of Internal System Files via API Path Manipulation | 8.6 High | ZimaOS ≤ v1.5.3 | Fixed | [View Advisory](https://github.com/IceWhaleTech/ZimaOS/security/advisories/GHSA-q5hp-59wm-9xq3) | Rushi9 |
5859
| CVE-2026-28286 | ZimaOS v1.5.2-beta3 - Unauthorized Creation of Files/Folders in Restricted System Directories via API | 8.6 High | ZimaOS ≤ v1.5.3 | Fixed | [View Advisory](https://github.com/IceWhaleTech/ZimaOS/security/advisories/GHSA-65mg-9gw5-vr7g) | Rushi9 |
5960
| CVE-2026-21891 | Authentication Bypass via System-Level Username | 9.4 High | ZimaOS ≤ v1.5.2 | Fixed | [View Advisory](https://github.com/IceWhaleTech/ZimaOS/security/advisories/GHSA-xj93-qw9p-jxq4) | captain-noob |

0 commit comments

Comments
 (0)