GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,509
Maven
5,000+
npm
5,000+
NuGet
1,100
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
139 advisories
Filter by severity
CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations
Moderate
CVE-2026-45139
was published
for
ci4-cms-erp/ci4ms
(Composer)
May 18, 2026
Duplicate Advisory: phpMyFAQ: Path traversal in Client::deleteClientFolder enables arbitrary directory deletion by non-super-admin admins
High
GHSA-rmqr-h98c-qg2m
was published
for
phpMyFAQ/phpMyFAQ
(Composer)
May 15, 2026
•
withdrawn
Microsoft APM: Windows absolute-path tar member overwrite during legacy-bundle probing in `apm install`
Moderate
CVE-2026-46383
was published
for
apm-cli
(pip)
May 15, 2026
Dalfox Server Mode has an Unauthenticated Arbitrary File Create/Append via `output` Option
High
CVE-2026-45089
was published
for
github.com/hahwul/dalfox/v2
(Go)
May 12, 2026
Dalfox Server Mode has an Unauthenticated Arbitrary File Read with Out-of-Band Exfiltration via `custom-payload-file`
High
CVE-2026-45088
was published
for
github.com/hahwul/dalfox/v2
(Go)
May 12, 2026
Streamlink has an arbitrary local file read via file:// URI in HLS and DASH
Moderate
CVE-2026-44353
was published
for
streamlink
(pip)
May 11, 2026
Microsoft APM CLI's plugin.json component paths escape plugin root and copy arbitrary host files during install
High
CVE-2026-44641
was published
for
apm-cli
(pip)
May 7, 2026
Gotenberg allows Chromium URL conversion routes to read arbitrary files under /tmp via file:// scheme
Moderate
CVE-2026-42597
was published
for
github.com/gotenberg/gotenberg/v7
(Go)
May 7, 2026
Gotenberg has arbitrary PDF read via stampExpression and watermarkExpression in merge, split, and convert routes
Moderate
CVE-2026-42593
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
May 7, 2026
Grav Form Plugin has an Anonymous Page Content Overwrite via Form File Upload filename Override
High
CVE-2026-42845
was published
for
getgrav/grav-plugin-form
(Composer)
May 6, 2026
changedetection.io has an Arbitrary Local File Read via a crafted backup restore
High
CVE-2026-43891
was published
for
changedetection.io
(pip)
May 5, 2026
@evomap/evolver: Path Traversal in `evolver fetch` default-branch `safeId` allows Hub-controlled overwrite of project files (RCE)
High
GHSA-cfcj-hqpf-hccf
was published
for
@evomap/evolver
(npm)
May 5, 2026
Gotenberg has an ExifTool Dangerous Tag Blocklist Bypass via Group-Prefixed Tag Names that Allows Arbitrary File Rename and Move
High
CVE-2026-40893
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
May 4, 2026
i18next-fs-backend: Path traversal via unsanitised lng/ns allows arbitrary file read/overwrite
High
CVE-2026-41693
was published
for
i18next-fs-backend
(npm)
Apr 22, 2026
nbconvert has an Arbitrary File Write via Path Traversal in Cell Attachment Filenames
Moderate
CVE-2026-39377
was published
for
nbconvert
(pip)
Apr 21, 2026
Duplicate Advisory: OpenClaw: Webchat media embedding enforces local-root containment for tool-result files
Moderate
GHSA-qc5j-2mqx-x83q
was published
for
openclaw
(npm)
Apr 20, 2026
•
withdrawn
OpenClaw: Webchat media embedding enforces local-root containment for tool-result files
Moderate
CVE-2026-41389
was published
for
openclaw
(npm)
Apr 17, 2026
Paperclip: Arbitrary File Read via Agent-Controlled adapterConfig.instructionsFilePath
Moderate
GHSA-3pw3-v88x-xj24
was published
for
@paperclipai/shared
(npm)
Apr 16, 2026
Rembg has a Path Traversal via Custom Model Loading
Moderate
CVE-2026-40086
was published
for
rembg
(pip)
Apr 10, 2026
OpenClaw: Shared reply MEDIA - paths are treated as trusted and can trigger cross-channel local file exfiltration
Moderate
CVE-2026-42424
was published
for
openclaw
(npm)
Apr 9, 2026
Gotenberg has incomplete fix for ExifTool arbitrary file write: case-insensitive bypass and missing HardLink/SymLink tags
High
GHSA-qmwh-9m9c-h36m
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
Apr 7, 2026
Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites
High
CVE-2026-34783
was published
for
github.com/MontFerret/ferret
(Go)
Apr 1, 2026
SillyTavern has a path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directory
High
CVE-2026-34522
was published
for
sillytavern
(npm)
Apr 1, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
High
CVE-2026-30940
was published
for
baserproject/basercms
(Composer)
Mar 31, 2026
@tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files
High
CVE-2026-33949
was published
for
@tinacms/graphql
(npm)
Mar 30, 2026
ProTip!
Advisories are also available from the
GraphQL API