GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
6,566 advisories
Filter by severity
Shiny for Python has path traversal in bookmark restore
Moderate
CVE-2026-108258
was published
for
shiny
(pip)
Oct 9, 2026
pacioli: A submit consent marker licensed cancellation of caller-named pre-existing documents
Moderate
CVE-2026-107841
was published
for
pacioli-guard
(pip)
Oct 9, 2026
pyload-ng: getUserData/get_userdata exposed at Perms.ANY allow any authenticated account to brute-force the administrator password
High
GHSA-68w4-83fh-f2w8
was published
for
pyload-ng
(pip)
Oct 9, 2026
pyLoad: Rate-Limit Bypass and Audit-Log Spoofing via Trusted Client-Controlled `X-Forwarded-For` Header
Moderate
GHSA-9q47-3cm2-2rp8
was published
for
pyload-ng
(pip)
Oct 9, 2026
pyLoad: Privilege revocation and password change through the REST API do not invalidate the user's session
High
GHSA-jq7h-wrvp-3rgx
was published
for
pyload-ng
(pip)
Oct 9, 2026
pyLoad: Api.set_user_permission never invalidates the target's session
High
GHSA-889w-m37p-88m5
was published
for
pyload-ng
(pip)
Oct 9, 2026
pyLoad WindowsPhoneNotify addon: non-admin SETTINGS user triggers SSRF via unguarded http.client notification host
Moderate
GHSA-p3pr-8f3m-4qp8
was published
for
pyload-ng
(pip)
Oct 9, 2026
pyLoad: Tar extraction creates device nodes and FIFOs (member types not filtered; tarfile extractall without filter=)
High
GHSA-fr26-jjhm-638c
was published
for
pyload-ng
(pip)
Oct 9, 2026
pyLoad has an authentication bypass in API key validation (check_apikey cache)
High
GHSA-r44w-v6gf-x3p6
was published
for
pyload-ng
(pip)
Oct 9, 2026
pyLoad: Unauthenticated access to /web/<path:filename> bypasses authentication on sensitive templates and leaks internal error details via exception attribute typo
Moderate
CVE-2026-75597
was published
for
pyload-ng
(pip)
Oct 9, 2026
pyLoad: Lack of Input Size Validation Leads to Denial of Service (DoS) and Process Termination
Moderate
CVE-2026-48484
was published
for
pyload-ng
(pip)
Oct 9, 2026
Strawberry legacy graphql-ws retains naturally completed subscription slots
Low
CVE-2026-107727
was published
for
strawberry-graphql
(pip)
Oct 9, 2026
Strawberry GraphQL: Synchronous permission checks can treat an awaitable authorization result as truthy
High
CVE-2026-107728
was published
for
strawberry-graphql
(pip)
Oct 9, 2026
Banks: Symlink traversal and arbitrary file disclosure/overwrite in DirectoryPromptRegistry
Moderate
CVE-2026-107716
was published
for
banks
(pip)
Oct 8, 2026
Banks: User-controlled prompt input can be parsed as privileged chat messages
Moderate
CVE-2026-107717
was published
for
banks
(pip)
Oct 8, 2026
Indico: Incomplete Server-Side Request Forgery (SSRF) check
Moderate
CVE-2026-107394
was published
for
indico
(pip)
Oct 8, 2026
Indico: Missing access check in legacy session export API
Moderate
CVE-2026-107395
was published
for
indico
(pip)
Oct 8, 2026
Indico: Cross-Site-Scripting in minutes editor
Moderate
CVE-2026-107397
was published
for
indico
(pip)
Oct 8, 2026
Indico: Cross-Site-Scripting in link fields
Moderate
CVE-2026-107396
was published
for
indico
(pip)
Oct 8, 2026
PraisonAI: Platform member PATCH routes allow owner resource rewrites and project lead reassignment delete bypass
High
CVE-2026-61442
was published
for
praisonai-platform
(pip)
Oct 8, 2026
PraisonAI: Shell command allowlist bypass via find -exec built-in action
High
CVE-2026-61434
was published
for
praisonai
(pip)
Oct 8, 2026
PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool Calls
Critical
CVE-2026-61445
was published
for
praisonai
(pip)
Oct 8, 2026
PraisonAI: MCP HTTP-stream transport is unauthenticated by default, exposing tool enumeration and an unvalidated tool-call surface
High
CVE-2026-61427
was published
for
praisonai
(pip)
Oct 8, 2026
PraisonAI: Platform members can rewrite shared labels and owner issue labels without owner/admin authorization
Moderate
CVE-2026-61440
was published
for
praisonai-platform
(pip)
Oct 8, 2026
PraisonAI: SecurityPolicy command/path/import restrictions are completely unenforced by the default SubprocessSandbox backend
High
CVE-2026-60085
was published
for
praisonai
(pip)
Oct 8, 2026
ProTip!
Advisories are also available from the
GraphQL API