Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

216 advisories

Loading
PraisonAI: Project config can auto-save agent output outside the project root Moderate
CVE-2026-60089 was published for praisonaiagents (pip) Oct 8, 2026
rexpository Credited to rexpository
Docling: Crafted DoclingDocument JSON embeds local image files into converted output Moderate
CVE-2026-105748 was published for docling (pip) Oct 7, 2026
wittjeff Credited to wittjeff
Ghost: Path Traversal via Locale Setting Moderate
CVE-2026-105676 was published for ghost (npm) Oct 7, 2026
DONG2209 Credited to DONG2209 and msegoviag msegoviag msegoviag
Backstage: Improper input validation in Confluence to Markdown scaffolder module Moderate
CVE-2026-106559 was published for @backstage/plugin-scaffolder-backend-module-confluence-to-markdown (npm) Oct 7, 2026
Backstage: Improper input validation in cloud storage URL readers Moderate
CVE-2026-106494 was published for @backstage/backend-defaults (npm) Oct 7, 2026
Quasar Framework: App Vite build cleanup can recursively remove unsafe configured output directories Moderate
CVE-2026-106109 was published for @quasar/app-vite (npm) Oct 7, 2026
hawkeye64 Credited to hawkeye64
Nx: Path traversal in nx migrate package-migrations extraction Moderate
CVE-2026-104853 was published for nx (npm) Oct 5, 2026
arkmarta Credited to arkmarta
GitPython submodule update path traversal can write outside the repository Moderate
GHSA-59cr-6r3x-644w was published for GitPython (pip) Sep 30, 2026
kta1kri Credited to kta1kri
Streamlink: HTTPSession follows HTTP redirects into file:// URLs, reading local files Moderate
CVE-2026-92164 was published for streamlink (pip) Sep 24, 2026
arpitjain099 Credited to arpitjain099 and bastimeyer bastimeyer bastimeyer
Redocly CLI: Path traversal when using `split` command Moderate
CVE-2026-63225 was published for @redocly/cli (npm) Sep 17, 2026
thegr1ffyn Credited to thegr1ffyn
Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the ... Moderate Unreviewed
CVE-2026-92595 was published Sep 17, 2026
Masofgon Credited to Masofgon
ProTip! Advisories are also available from the GraphQL API