Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

773 advisories

Loading
PraisonAI: Jobs API is unauthenticated by default and allows attacker-controlled webhook SSRF High
CVE-2026-60091 was published for praisonai (pip) Oct 8, 2026
dinhvaren Credited to dinhvaren
PraisonAI: DNS rebinding bypass in `web_crawl` SSRF protection allows internal response disclosure High
CVE-2026-61430 was published for praisonaiagents (pip) Oct 8, 2026
dinhvaren Credited to dinhvaren
DavidCarliez Credited to DavidCarliez and adelzaitri adelzaitri adelzaitri
Ghost: Server-Side Request Forgery in Bookmark Fetching Moderate
CVE-2026-105647 was published for ghost (npm) Oct 7, 2026
nhattanhh Credited to nhattanhh
PraisonAI: Crawl4AI/Chromium backend is also affected by the `web_crawl` SSRF validation bypass High
CVE-2026-61429 was published for praisonaiagents (pip) Oct 7, 2026
dinhvaren Credited to dinhvaren
LaraDashboard from 1.4.0 before 1.4.8 contains a race condition vulnerability in... Moderate Unreviewed
CVE-2026-105130 was published Oct 4, 2026
Electron: Local race condition in Squirrel.Mac update installation on macOS Moderate
CVE-2026-102672 was published for electron (npm) Sep 29, 2026
sgretas Credited to sgretas
9router: Image prefetch DNS rebinding allows SSRF to internal services High
CVE-2026-56676 was published for 9router (npm) Sep 23, 2026
dinhvaren Credited to dinhvaren
ProTip! Advisories are also available from the GraphQL API