Security: DataDog/guarddog
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Unsanitized human-readable scan output allows terminal escape injection from malicious package contentGHSA-m5p4-gvpx-4mvr published
May 6, 2026 by sobregosoddModerate -
Blind GitHub URL rewrite in remote project scanning causes SSRF and `GH_TOKEN` exfiltrationGHSA-587r-mc96-6f2p published
May 6, 2026 by sobregosoddHigh -
Path Traversal Vulnerability Leads to Arbitrary File Overwrite and RCEGHSA-xg9w-vg3g-6m68 published
Jan 13, 2026 by sobregosoddHigh -
Zip Bomb Vulnerability in safe_extract() Allows DoSGHSA-ffj4-jq7m-9g6v published
Jan 13, 2026 by sobregosoddHigh -
Arbitrary file write when scanning a specially-crafted remote PyPI packageGHSA-78m5-jpmf-ch7v published
Dec 5, 2022 by christophetdModerate -
Arbitrary file write when scanning a specially-crafted local PyPI packageGHSA-rp2v-v467-q9vq published
Nov 29, 2022 by christophetdModerate