GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,509
Maven
5,000+
npm
5,000+
NuGet
1,100
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
139 advisories
Filter by severity
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation
Moderate
CVE-2026-33027
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Mar 30, 2026
@mobilenext/mobile-mcp alllows arbitrary file write via Path Traversal in mobile screen capture tools
High
CVE-2026-33989
was published
for
@mobilenext/mobile-mcp
(npm)
Mar 27, 2026
Siyuan has an Unauthenticated Arbitrary File Read via Path Traversal
High
CVE-2026-33476
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 20, 2026
AVideo has an authenticated arbitrary local file read via `chunkFile` path injection in `aVideoEncoder.json.php`
High
CVE-2026-33354
was published
for
wwbn/avideo
(Composer)
Mar 19, 2026
Langflow has an Arbitrary File Write (RCE) via v2 API
Critical
CVE-2026-33309
was published
for
langflow
(pip)
Mar 19, 2026
SiYuan importSY/importZipMd: path traversal via multipart filename enables arbitrary file write
High
CVE-2026-32749
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 16, 2026
MCP Atlassian has an arbitrary file write leading to arbitrary code execution via unconstrained download_path in confluence_download_attachment
Critical
CVE-2026-27825
was published
for
mcp-atlassian
(pip)
Mar 10, 2026
OpenClaw hardened the skill download target directory validation
Moderate
CVE-2026-27008
was published
for
openclaw
(npm)
Feb 18, 2026
Keras has a Local File Disclosure via HDF5 External Storage During Keras Weight Loading
High
CVE-2026-1669
was published
for
keras
(pip)
Feb 18, 2026
OpenClaw has an arbitrary transcript path file write via gateway sessionFile
High
CVE-2026-28459
was published
for
openclaw
(npm)
Feb 17, 2026
Duplicate Advisory: Keras vulnerable to arbitrary file read in the model loading mechanism (HDF5 integration)
High
GHSA-gfmx-qqqh-f38q
was published
for
keras
(pip)
Feb 12, 2026
•
withdrawn
qdrant has arbitrary file write via `/logger` endpoint
High
CVE-2026-25628
was published
for
qdrant
(Rust)
Feb 5, 2026
survey-pdf Upgraded jsPDF Version Due to Security Vulnerability
Critical
CVE-2026-25630
was published
for
survey-pdf
(npm)
Feb 4, 2026
Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write
Critical
CVE-2025-64712
was published
for
unstructured
(pip)
Feb 3, 2026
H2O has an External Control of File Name or Path vulnerability
Critical
CVE-2024-5986
was published
for
ai.h2o:h2o-core
(Maven)
Feb 2, 2026
LobeHub Vulnerable to Improper Authorization in Presigned Upload
Moderate
CVE-2026-23835
was published
for
@lobehub/chat
(npm)
Feb 1, 2026
jsPDF has Local File Inclusion/Path Traversal vulnerability
Critical
CVE-2025-68428
was published
for
jspdf
(npm)
Jan 5, 2026
External Control of File Name or Path in Langflow
High
CVE-2025-68478
was published
for
langflow
(pip)
Dec 19, 2025
@vitejs/plugin-rsc has an Arbitrary File Read via `/__vite_rsc_findSourceMapURL` Endpoint
High
CVE-2025-68155
was published
for
@vitejs/plugin-rsc
(npm)
Dec 16, 2025
memos lacks file name validation or verification
Moderate
CVE-2025-65799
was published
for
github.com/usememos/memos
(Go)
Dec 8, 2025
Better Auth affected by external request basePath modification DoS
Low
GHSA-569q-mpph-wgww
was published
for
better-auth
(npm)
Dec 1, 2025
OpenStack's Mistral Client has a local file inclusion vulnerability
Moderate
CVE-2021-4472
was published
for
python-mistralclient
(pip)
Nov 26, 2025
PrivateBin's template-switching feature allows arbitrary local file inclusion through path traversal
Moderate
CVE-2025-64714
was published
for
privatebin/privatebin
(Composer)
Nov 14, 2025
aiomysql allows arbitrary access to client files through vulnerability of a malicious MySQL server
High
CVE-2025-62611
was published
for
aiomysql
(pip)
Oct 22, 2025
InvokeAI has External Control of File Name or Path
Critical
CVE-2025-6237
was published
for
invokeai
(pip)
Sep 18, 2025
ProTip!
Advisories are also available from the
GraphQL API