Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

8 advisories

Loading
SearXNG MCP Server: DNS-resolved Private Hostname SSRF in `web_url_read` High
GHSA-mrvx-jmjw-vggc was published for mcp-searxng (npm) Jun 19, 2026
EQSTLab Credited to EQSTLab and useworld useworld useworld
Cortex has Untrusted Project Bootstrap Code Execution via `CLAUDE_PROJECT_DIR` High
CVE-2026-49986 was published for neuro-cortex-memory (pip) Jul 1, 2026
EQSTLab Credited to EQSTLab and useworld useworld useworld
EQSTLab Credited to EQSTLab and useworld useworld useworld
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install` High
CVE-2026-55071 was published for stata-mcp (pip) Aug 12, 2026
EQSTLab Credited to EQSTLab and useworld useworld useworld
mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable High
CVE-2026-55581 was published for github.com/sonirico/mcp-shell (Go) Aug 25, 2026
EQSTLab Credited to EQSTLab, useworld, and sonirico useworld useworld
sonirico sonirico
@openhop/server: Path Traversal in Flow ID File Operations High
CVE-2026-59179 was published for @openhop/server (npm) Sep 9, 2026
EQSTLab Credited to EQSTLab and useworld useworld useworld
Cline: Cross-Origin WebSocket Hijacking in Cline Hub Dashboard (`/browser` endpoint) High
CVE-2026-59723 was published for cline (npm) Sep 24, 2026
EQSTLab Credited to EQSTLab and useworld useworld useworld
GraphQL Tools: TLS Certificate Validation Disabled in Legacy GraphQL WebSocket Executor High
CVE-2026-103921 was published for @graphql-tools/executor-legacy-ws (npm) Oct 5, 2026
EQSTLab Credited to EQSTLab and useworld useworld useworld
ProTip! Advisories are also available from the GraphQL API