GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
77 advisories
Filter by severity
PraisonAI: Platform member PATCH routes allow owner resource rewrites and project lead reassignment delete bypass
High
CVE-2026-61442
was published
for
praisonai-platform
(pip)
Oct 8, 2026
PraisonAI: Platform members can rewrite shared labels and owner issue labels without owner/admin authorization
Moderate
CVE-2026-61440
was published
for
praisonai-platform
(pip)
Oct 8, 2026
PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source
High
CVE-2026-61433
was published
for
praisonai
(pip)
Oct 8, 2026
PraisonAI: Call API localhost-only authentication bypass via spoofed Host header
High
CVE-2026-61435
was published
for
praisonai
(pip)
Oct 8, 2026
PraisonAI: ContextGatherer include resolution permits absolute and traversal reads outside the workspace
Moderate
CVE-2026-61431
was published
for
praisonai
(pip)
Oct 8, 2026
PraisonAI: Project custom command templates can read outside-workspace files into model prompts
Moderate
CVE-2026-60088
was published
for
praisonai
(pip)
Oct 8, 2026
PraisonAI: PGVector and Cassandra knowledge stores interpolate vector dimensions into DDL
Moderate
CVE-2026-60090
was published
for
praisonai
(pip)
Oct 8, 2026
PraisonAI: FastContext path resolution permits absolute and traversal reads outside the workspace
Moderate
CVE-2026-61432
was published
for
praisonaiagents
(pip)
Oct 8, 2026
PraisonAI: Project config can auto-save agent output outside the project root
Moderate
CVE-2026-60089
was published
for
praisonaiagents
(pip)
Oct 8, 2026
PraisonAI: Platform members can delete owner issue dependencies through member-owned related issues
Moderate
CVE-2026-62179
was published
for
praisonai-platform
(pip)
Oct 7, 2026
PraisonAI: AgentMail webhook mode accepts forged unsigned message.received events and invokes agents
High
CVE-2026-61436
was published
for
praisonai
(pip)
Oct 7, 2026
vm2: NodeVM custom resolution bypasses external path boundaries
Critical
CVE-2026-100721
was published
for
vm2
(npm)
Oct 5, 2026
vm2: Host Promise rejection from an exposed constructor can terminate the vm2 host process
High
CVE-2026-100722
was published
for
vm2
(npm)
Oct 5, 2026
vm2: NodeVM zlib Buffers expose pooled host memory across the VM boundary
Moderate
CVE-2026-100723
was published
for
vm2
(npm)
Oct 5, 2026
vm2: Host-returned Promise rejection can bypass vm2's unhandled-rejection hardening and terminate the host process
Critical
CVE-2026-92954
was published
for
vm2
(npm)
Oct 5, 2026
vm2: Default VM can mutate host TypedArray and ArrayBuffer intrinsics after the host-prototype pollution fix
Critical
CVE-2026-92953
was published
for
vm2
(npm)
Oct 5, 2026
vm2: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks
Moderate
CVE-2026-92952
was published
for
vm2
(npm)
Oct 1, 2026
vm2: NodeVM builtin denylist bypass via fs/promises despite -fs, allowing host filesystem writes
High
CVE-2026-92958
was published
for
vm2
(npm)
Oct 1, 2026
JupyterLab: Argument injection in JupyterLab extension uninstall exposes server-readable files and internal URLs
Moderate
CVE-2026-102904
was published
for
jupyterlab
(pip)
Oct 1, 2026
JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard
High
CVE-2026-102831
was published
for
jupyterlab
(pip)
Oct 1, 2026
vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation
Moderate
CVE-2026-69147
was published
for
vllm
(pip)
Sep 17, 2026
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
Moderate
CVE-2026-71486
was published
for
vllm
(pip)
Sep 4, 2026
OpenClaw Feishu permission tools could ignore per-account disablement
High
GHSA-w8wf-3qvj-6xqf
was published
for
@openclaw/feishu
(npm)
Sep 3, 2026
OpenClaw Feishu tools could ignore per-account disablement
High
GHSA-2q7j-2vhx-56g8
was published
for
@openclaw/feishu
(npm)
Sep 3, 2026
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection
High
CVE-2026-67445
was published
for
github.com/axllent/mailpit
(Go)
Sep 2, 2026
ProTip!
Advisories are also available from the
GraphQL API