GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
216 advisories
Filter by severity
LobsterAI 2026.5.27 through 2026.9.23 contains an external control of file path vulnerability in...
Moderate
Unreviewed
CVE-2026-108156
was published
Oct 9, 2026
PraisonAI: Project config can auto-save agent output outside the project root
Moderate
CVE-2026-60089
was published
for
praisonaiagents
(pip)
Oct 8, 2026
Docling: Crafted DoclingDocument JSON embeds local image files into converted output
Moderate
CVE-2026-105748
was published
for
docling
(pip)
Oct 7, 2026
Ghost: Path Traversal via Locale Setting
Moderate
CVE-2026-105676
was published
for
ghost
(npm)
Oct 7, 2026
Backstage: Improper input validation in Confluence to Markdown scaffolder module
Moderate
CVE-2026-106559
was published
for
@backstage/plugin-scaffolder-backend-module-confluence-to-markdown
(npm)
Oct 7, 2026
Backstage: Improper input validation in cloud storage URL readers
Moderate
CVE-2026-106494
was published
for
@backstage/backend-defaults
(npm)
Oct 7, 2026
Quasar Framework: App Vite build cleanup can recursively remove unsafe configured output directories
Moderate
CVE-2026-106109
was published
for
@quasar/app-vite
(npm)
Oct 7, 2026
An arbitrary file write vulnerability in the ClearPass Policy Manager OnGuard agent could allow...
Moderate
Unreviewed
CVE-2026-79814
was published
Oct 6, 2026
In JetBrains TeamCity before 2026.2.1 missing validation of Git submodule URLs allowed reading...
Moderate
Unreviewed
CVE-2026-106219
was published
Oct 6, 2026
Nx: Path traversal in nx migrate package-migrations extraction
Moderate
CVE-2026-104853
was published
for
nx
(npm)
Oct 5, 2026
Perforce P4 Search prior to 2026.4.2 does not validate file names supplied to its extension...
Moderate
Unreviewed
CVE-2026-103511
was published
Oct 5, 2026
- External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows -...
Moderate
Unreviewed
CVE-2026-71453
was published
Oct 2, 2026
GitPython submodule update path traversal can write outside the repository
Moderate
GHSA-59cr-6r3x-644w
was published
for
GitPython
(pip)
Sep 30, 2026
Cato Windows SDP Client before version 6.12.6 contains an arbitrary file disclosure vulnerability...
Moderate
Unreviewed
CVE-2026-10726
was published
Sep 30, 2026
The EWWW Image Optimizer WordPress plugin before 8.8.0 does not confine a WebP-derivative file...
Moderate
Unreviewed
CVE-2026-91072
was published
Sep 30, 2026
Streamlink: HTTPSession follows HTTP redirects into file:// URLs, reading local files
Moderate
CVE-2026-92164
was published
for
streamlink
(pip)
Sep 24, 2026
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause...
Moderate
Unreviewed
CVE-2026-65125
was published
Sep 22, 2026
rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerability in the `rclone serve...
Moderate
Unreviewed
CVE-2026-93987
was published
Sep 19, 2026
The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.3 does not...
Moderate
Unreviewed
CVE-2026-19860
was published
Sep 19, 2026
Redocly CLI: Path traversal when using `split` command
Moderate
CVE-2026-63225
was published
for
@redocly/cli
(npm)
Sep 17, 2026
Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the ...
Moderate
Unreviewed
CVE-2026-92595
was published
Sep 17, 2026
The WP Import Export Lite WordPress plugin before 3.9.33 does not validate a path taken from...
Moderate
Unreviewed
CVE-2026-76553
was published
Sep 16, 2026
The LoadImageAsPngBase64 endpoint of the Newell Brands DYMO Connect Desktop local web service...
Moderate
Unreviewed
CVE-2026-76796
was published
Sep 15, 2026
n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
Moderate
CVE-2026-86995
was published
for
n8n
(npm)
Sep 10, 2026
The Okta Access Gateway Kerberos configuration handler does not validate file paths specified in...
Moderate
Unreviewed
CVE-2026-78620
was published
Sep 8, 2026
ProTip!
Advisories are also available from the
GraphQL API