GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,510
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
42 advisories
Filter by severity
FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files
High
CVE-2026-54910
was published
for
github.com/gtsteffaniak/filebrowser/backend
(Go)
Jul 31, 2026
hashi-vault-js has a path traversal and query parameter injection
High
CVE-2026-55100
was published
for
hashi-vault-js
(npm)
Jul 31, 2026
SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read), Incomplete fix of CVE-2026-41894
High
CVE-2026-54066
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Jul 10, 2026
Langroid: Path traversal in the file tools allows read/write outside configured current directory
High
CVE-2026-50181
was published
for
langroid
(pip)
Jul 2, 2026
pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement
High
CVE-2026-50016
was published
for
pnpm
(npm)
Jun 26, 2026
Algernon: Host header path traversal in --domain mode reads files and runs Lua from parent dir
High
CVE-2026-48126
was published
for
github.com/xyproto/algernon
(Go)
Jun 23, 2026
Apache Ignite REST API Has a Relative Path Traversal Vulnerability
High
CVE-2025-48977
was published
for
org.apache.ignite:ignite-core
(Maven)
May 28, 2026
Weblate: Remote code execution during backup restoration
High
CVE-2026-33435
was published
for
weblate
(pip)
Apr 16, 2026
PraisonAI Has Arbitrary File Write (Zip Slip) in Templates Extraction
High
CVE-2026-39307
was published
for
PraisonAI
(pip)
Apr 6, 2026
onnx Vulnerable to Path Traversal via Symlink
High
CVE-2026-27489
was published
for
onnx
(pip)
Mar 31, 2026
pf4j is vulnerable to Path Traversal or Zip Slip attack through improper handling of zip entry names
High
CVE-2025-70952
was published
for
org.pf4j:pf4j
(Maven)
Mar 25, 2026
pyLoad has an Arbitrary File Write via Path Traversal in edit_package()
High
CVE-2026-29778
was published
for
pyload-ng
(pip)
Mar 5, 2026
OpenClaw has an arbitrary transcript path file write via gateway sessionFile
High
CVE-2026-28459
was published
for
openclaw
(npm)
Feb 17, 2026
FUXA Affected by a Path Traversal Sanitization Bypass
High
CVE-2026-25951
was published
for
fuxa-server
(npm)
Feb 10, 2026
apko has a path traversal in apko dirFS which allows filesystem writes outside base
High
CVE-2026-25121
was published
for
chainguard.dev/apko
(Go)
Feb 3, 2026
MindsDB has improper sanitation of filepath that leads to information disclosure and DOS
High
CVE-2025-68472
was published
for
MindsDB
(pip)
Jan 12, 2026
PsiTransfer has Zip Slip Path Traversal via TAR Archive Download
High
GHSA-xphh-5v4r-r3rx
was published
for
psitransfer
(npm)
Dec 30, 2025
RCE via ZipSlip and symbolic links in argoproj/argo-workflows
High
CVE-2025-66626
was published
for
github.com/argoproj/argo-workflows
(Go)
Dec 9, 2025
Apache Tomcat Vulnerable to Relative Path Traversal
High
CVE-2025-55752
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Oct 27, 2025
Argo Workflow has a Zipslip Vulnerability
High
CVE-2025-62156
was published
for
github.com/argoproj/argo-workflows/v3
(Go)
Oct 14, 2025
esm.sh has File Inclusion issue
High
CVE-2025-59341
was published
for
github.com/esm-dev/esm.sh
(Go)
Sep 17, 2025
raspap-webgui has a Directory Traversal vulnerability
High
CVE-2025-44163
was published
for
billz/raspap-webgui
(Composer)
Jun 27, 2025
AstrBot Has Path Traversal Vulnerability in /api/chat/get_file
High
CVE-2025-48957
was published
for
astrbot
(pip)
Jun 4, 2025
Umbraco has a Management API Vulnerability to Path Traversal With Authenticated Users
High
CVE-2025-32017
was published
for
Umbraco.Cms
(NuGet)
Apr 9, 2025
Apache Commons VFS Has Relative Path Traversal Vulnerability
High
CVE-2025-27553
was published
for
org.apache.commons:commons-vfs2
(Maven)
Mar 23, 2025
ProTip!
Advisories are also available from the
GraphQL API