Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6,566 advisories

Loading
Shiny for Python has path traversal in bookmark restore Moderate
CVE-2026-108258 was published for shiny (pip) Oct 9, 2026
0xRenSec Credited to 0xRenSec
pacioli: A submit consent marker licensed cancellation of caller-named pre-existing documents Moderate
CVE-2026-107841 was published for pacioli-guard (pip) Oct 9, 2026
prnjlksingh Credited to prnjlksingh
pyLoad: Rate-Limit Bypass and Audit-Log Spoofing via Trusted Client-Controlled `X-Forwarded-For` Header Moderate
GHSA-9q47-3cm2-2rp8 was published for pyload-ng (pip) Oct 9, 2026
nirtem Credited to nirtem
arpitjain099 Credited to arpitjain099
pyLoad: Api.set_user_permission never invalidates the target's session High
GHSA-889w-m37p-88m5 was published for pyload-ng (pip) Oct 9, 2026
FlowOverFail Credited to FlowOverFail
manus-pi Credited to manus-pi and manus-use manus-use manus-use
skeletonsec Credited to skeletonsec
pyLoad has an authentication bypass in API key validation (check_apikey cache) High
GHSA-r44w-v6gf-x3p6 was published for pyload-ng (pip) Oct 9, 2026
nirtem Credited to nirtem
pyLoad: Lack of Input Size Validation Leads to Denial of Service (DoS) and Process Termination Moderate
CVE-2026-48484 was published for pyload-ng (pip) Oct 9, 2026
pevinkumar10 Credited to pevinkumar10
Strawberry legacy graphql-ws retains naturally completed subscription slots Low
CVE-2026-107727 was published for strawberry-graphql (pip) Oct 9, 2026
Hama1cco Credited to Hama1cco
Strawberry GraphQL: Synchronous permission checks can treat an awaitable authorization result as truthy High
CVE-2026-107728 was published for strawberry-graphql (pip) Oct 9, 2026
Hama1cco Credited to Hama1cco and patrick91 patrick91 patrick91
Banks: Symlink traversal and arbitrary file disclosure/overwrite in DirectoryPromptRegistry Moderate
CVE-2026-107716 was published for banks (pip) Oct 8, 2026
jankesec Credited to jankesec
Banks: User-controlled prompt input can be parsed as privileged chat messages Moderate
CVE-2026-107717 was published for banks (pip) Oct 8, 2026
swordmein Credited to swordmein
Indico: Incomplete Server-Side Request Forgery (SSRF) check Moderate
CVE-2026-107394 was published for indico (pip) Oct 8, 2026
Fushuling Credited to Fushuling and RacerZ-fighting RacerZ-fighting RacerZ-fighting
Indico: Missing access check in legacy session export API Moderate
CVE-2026-107395 was published for indico (pip) Oct 8, 2026
arpitjain099 Credited to arpitjain099
Indico: Cross-Site-Scripting in minutes editor Moderate
CVE-2026-107397 was published for indico (pip) Oct 8, 2026
Indico: Cross-Site-Scripting in link fields Moderate
CVE-2026-107396 was published for indico (pip) Oct 8, 2026
rexpository Credited to rexpository
PraisonAI: Shell command allowlist bypass via find -exec built-in action High
CVE-2026-61434 was published for praisonai (pip) Oct 8, 2026
HiyokoSauna37 Credited to HiyokoSauna37
PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool Calls Critical
CVE-2026-61445 was published for praisonai (pip) Oct 8, 2026
anushkavirgaonkar Credited to anushkavirgaonkar
dinhvaren Credited to dinhvaren
PraisonAI: Platform members can rewrite shared labels and owner issue labels without owner/admin authorization Moderate
CVE-2026-61440 was published for praisonai-platform (pip) Oct 8, 2026
rexpository Credited to rexpository
LHMisme420 Credited to LHMisme420
ProTip! Advisories are also available from the GraphQL API