Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

626 advisories

Loading
datamodel-code-generator: Protobuf weak-import path traversal allows files to be written outside the temporary directory High
CVE-2026-107377 was published for datamodel-code-generator (pip) Oct 8, 2026
alex131125 Credited to alex131125
PraisonAI: Project config can auto-save agent output outside the project root Moderate
CVE-2026-60089 was published for praisonaiagents (pip) Oct 8, 2026
rexpository Credited to rexpository
wittjeff Credited to wittjeff, hoanggxyuuki, Smavl, 3m4n5, and Jiayang-Lai hoanggxyuuki hoanggxyuuki
Smavl Smavl 3m4n5 3m4n5 Jiayang-Lai Jiayang-Lai
Docling: Crafted DoclingDocument JSON embeds local image files into converted output Moderate
CVE-2026-105748 was published for docling (pip) Oct 7, 2026
wittjeff Credited to wittjeff
Payload: Incomplete validation during the upload file lifecycle High
CVE-2026-105865 was published for payload (npm) Oct 7, 2026
EchoSkorJjj Credited to EchoSkorJjj
Ghost: Path Traversal via Locale Setting Moderate
CVE-2026-105676 was published for ghost (npm) Oct 7, 2026
DONG2209 Credited to DONG2209 and msegoviag msegoviag msegoviag
Backstage: Improper input validation in Confluence to Markdown scaffolder module Moderate
CVE-2026-106559 was published for @backstage/plugin-scaffolder-backend-module-confluence-to-markdown (npm) Oct 7, 2026
Backstage: Improper input validation in cloud storage URL readers Moderate
CVE-2026-106494 was published for @backstage/backend-defaults (npm) Oct 7, 2026
Quasar Framework: App Vite build cleanup can recursively remove unsafe configured output directories Moderate
CVE-2026-106109 was published for @quasar/app-vite (npm) Oct 7, 2026
hawkeye64 Credited to hawkeye64
Quasar Framework: Path Traversal / Arbitrary File Write via crafted Icon Genie profile High
CVE-2026-106103 was published for @quasar/icongenie (npm) Oct 7, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
Nx: Path traversal in nx migrate package-migrations extraction Moderate
CVE-2026-104853 was published for nx (npm) Oct 5, 2026
arkmarta Credited to arkmarta
ProTip! Advisories are also available from the GraphQL API