GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,347
Maven
5,000+
npm
5,000+
NuGet
1,042
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
132,034 advisories
Filter by severity
PraisonAI: HTTPApproval dashboard renders tool arguments as raw HTML, allowing approval-page XSS to approve dangerous tools
High
CVE-2026-56840
was published
for
praisonai
(pip)
Jun 18, 2026
PraisonAI Code agent tools fail open without a workspace boundary
High
CVE-2026-56839
was published
for
praisonai
(pip)
Jun 18, 2026
PraisonAI recipe.run_stream skips dangerous-tool policy enforcement
High
CVE-2026-56838
was published
for
praisonai
(pip)
Jun 18, 2026
PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing
High
CVE-2026-56837
was published
for
praisonai
(pip)
Jun 18, 2026
PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard
High
CVE-2026-56836
was published
for
praisonai
(pip)
Jun 18, 2026
PraisonAI Slack app_mention bypasses configured user/channel authorization
High
CVE-2026-56835
was published
for
praisonai
(pip)
Jun 18, 2026
PraisonAI dynamic-context artifact tools read arbitrary host files outside artifact storage
High
CVE-2026-56834
was published
for
praisonai
(pip)
Jun 18, 2026
PraisonAI Dynamic Context history and terminal tools read files outside configured storage via path traversal
High
CVE-2026-56833
was published
for
praisonai
(pip)
Jun 18, 2026
PraisonAI DiscordApproval accepts unrelated channel messages as dangerous-tool approvals
High
CVE-2026-56832
was published
for
praisonai
(pip)
Jun 18, 2026
JLine3 Telnet server: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry
High
CVE-2026-56741
was published
for
org.jline:jline-remote-telnet
(Maven)
Jun 18, 2026
JLine3 Telnet server: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables
High
CVE-2026-56740
was published
for
org.jline:jline-remote-telnet
(Maven)
Jun 18, 2026
jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation
High
CVE-2026-54512
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Jun 23, 2026
jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
High
CVE-2026-54513
was published
for
com.fasterxml.jackson.core:jackson-databind
(Maven)
Jun 23, 2026
js-yaml: YAML merge-key chains can force quadratic CPU consumption
High
CVE-2026-59869
was published
for
js-yaml
(npm)
Jul 20, 2026
NocoDB: Stored Cross-Site Scripting via Form View Redirect URL
High
CVE-2026-47387
was published
for
nocodb
(npm)
Jun 5, 2026
NocoDB: Stored Cross-Site Scripting via Row Comments
High
CVE-2026-47383
was published
for
nocodb
(npm)
Jun 5, 2026
File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup
High
CVE-2026-55667
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 20, 2026
Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim
High
CVE-2026-54560
was published
for
github.com/cloudreve/Cloudreve/v4
(Go)
Jul 20, 2026
Daytona: Cross-org IDOR in organization role update/delete — any org owner can rewrite or destroy another org's roles
High
CVE-2026-54322
was published
for
github.com/daytonaio/daytona
(Go)
Jun 16, 2026
Daytona: Public sandbox previews remain accessible for up to one hour after being made private
High
CVE-2026-54321
was published
for
github.com/daytonaio/daytona
(Go)
Jun 16, 2026
Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization
High
CVE-2026-48020
was published
for
github.com/traefik/traefik/v2
(Go)
Jun 11, 2026
Pillow `GdImageFile._open()`: image dimensions accepted without `_decompression_bomb_check()`
High
CVE-2026-55380
was published
for
pillow
(pip)
Jul 20, 2026
Pillow `BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading
High
CVE-2026-55379
was published
for
pillow
(pip)
Jul 20, 2026
Pi Agent: Predictable temporary extension install paths allow local privilege escalation on shared Linux hosts
High
CVE-2026-54328
was published
for
@earendil-works/pi-coding-agent
(npm)
Jun 17, 2026
Crawl4AI: SSRF via proxy settings in the Docker server bypasses the crawl-URL SSRF check
High
CVE-2026-53755
was published
for
crawl4ai
(pip)
Jun 16, 2026
ProTip!
Advisories are also available from the
GraphQL API