GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
86
GitHub Actions
54
Go
4,175
Maven
5,000+
npm
5,000+
NuGet
1,019
pip
5,000+
Pub
13
RubyGems
1,102
Rust
1,421
Swift
61
Unreviewed advisories
All unreviewed
5,000+
573 advisories
Filter by severity
@anthropic-ai/claude-code has an Insecure Temporary File in /copy Command that Enables Response Disclosure and Symlink-Based File Write
Moderate
CVE-2026-46406
was published
for
@anthropic-ai/claude-code
(npm)
Jun 25, 2026
NanoClaw before 2.1.17 contains a symlink following vulnerability in forwardAttachedFiles that...
Moderate
Unreviewed
CVE-2026-56692
was published
Jun 23, 2026
Capgo CLI before 12.128.2 contains arbitrary file overwrite vulnerabilities in login and build...
Moderate
Unreviewed
CVE-2026-56236
was published
Jun 21, 2026
pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size
Moderate
GHSA-4xgf-cpjx-pc3j
was published
for
pydantic-settings
(pip)
Jun 19, 2026
Network-AI: EnvironmentManager.backup() follows symlinked directories and copies files outside the environment root into backups
Moderate
GHSA-6x2m-p4xp-wg22
was published
for
network-ai
(npm)
Jun 19, 2026
go.qbee.io/transport: Symlink-chain path traversal in tar extraction (one level outside destination)
Moderate
CVE-2026-55828
was published
for
go.qbee.io/transport
(Go)
Jun 19, 2026
Hugo: Symlink confinement bypass in os.ReadFile
Moderate
GHSA-c3wq-j5vh-68rc
was published
for
github.com/gohugoio/hugo
(Go)
Jun 19, 2026
setupBpmLogs follows symlink for bpm.log open and chown — container-to-host privilege escalation...
Moderate
Unreviewed
CVE-2026-47833
was published
Jun 18, 2026
Podman: WORKDIR symlink traversal vulnerability
Moderate
CVE-2026-55686
was published
for
github.com/containers/podman/v3
(Go)
Jun 18, 2026
Chrome DevTools for agents: daemon.pid write follows symlinks in /tmp fallback runtime directory
Moderate
CVE-2026-53765
was published
for
chrome-devtools-mcp
(npm)
Jun 17, 2026
Hugo: Symlink confinement bypass in resources.Get
Moderate
CVE-2026-50135
was published
for
github.com/gohugoio/hugo
(Go)
Jun 16, 2026
LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders
Moderate
GHSA-gr75-jv2w-4656
was published
for
langchain
(pip)
Jun 16, 2026
Microsoft Security Advisory CVE-2026-45491 – .NET Tampering Vulnerability
Moderate
CVE-2026-45491
was published
for
Microsoft.NETCore.App.Runtime.linux-x64
(NuGet)
Jun 16, 2026
File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope
Moderate
CVE-2026-54094
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 12, 2026
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia...
Moderate
Unreviewed
CVE-2025-46293
was published
Jun 11, 2026
Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution....
Moderate
Unreviewed
CVE-2026-11853
was published
Jun 10, 2026
Dell/Alienware Purchased Apps, versions prior to 1.1.32.0, contain an Improper Link Resolution...
Moderate
Unreviewed
CVE-2026-44275
was published
Jun 9, 2026
Dell iDRAC Tools, versions prior to 11.4.1.0, contains an Improper Link Resolution Before File...
Moderate
Unreviewed
CVE-2026-28262
was published
Jun 9, 2026
A Dag author could either (a) create a symlink under their task's log directory pointing to an...
Moderate
Unreviewed
CVE-2026-40861
was published
Jun 1, 2026
Sparkle: Binary delta apply intermediate-symlink traversal in malicious .delta
Moderate
CVE-2026-47121
was published
for
github.com/sparkle-project/Sparkle
(Swift)
May 29, 2026
Improper handling of symbolic links in the installer of CUPS Printer Driver for macOS(*) may...
Moderate
Unreviewed
CVE-2026-6892
was published
May 29, 2026
Improper handling of symbolic links in the installer of My Image Garden for macOS Version 3.6.8...
Moderate
Unreviewed
CVE-2026-6891
was published
May 29, 2026
FastNetMon Community Edition through 1.2.9 is vulnerable to a local symlink attack via...
Moderate
Unreviewed
CVE-2026-48693
was published
May 26, 2026
An issue was discovered in the Portrait Dell Color Management application before 3.7.0 for Dell...
Moderate
Unreviewed
CVE-2026-34883
was published
May 19, 2026
HashiCorp Nomad vulnerable to symlink attack
Moderate
CVE-2026-6959
was published
for
github.com/hashicorp/nomad
(Go)
May 12, 2026
ProTip!
Advisories are also available from the
GraphQL API