Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

675 advisories

Loading
Backstage: Bypass of MkDocs configuration sanitizer in TechDocs backend High
CVE-2026-106505 was published for @backstage/plugin-techdocs-node (npm) Oct 7, 2026
OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS High
CVE-2026-81192 was published for OpenTelemetry.Resources.Host (NuGet) Sep 16, 2026
martincostello Credited to martincostello and lachmatt lachmatt lachmatt
NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary High
CVE-2026-78680 was published for nltk (pip) Sep 1, 2026
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code High
CVE-2026-55522 was published for PraisonAI (pip) Aug 25, 2026
rexpository Credited to rexpository
Duplicate Advisory: Uncontrolled search path when invoking the Graphviz 'dot' binary (CWE-426/CWE-427) High
GHSA-54xp-3ww7-6wjg was published for nltk (pip) Aug 25, 2026 • withdrawn
ProTip! Advisories are also available from the GraphQL API