GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,510
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
34 advisories
Filter by severity
File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)
Moderate
CVE-2026-62843
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 20, 2026
Network-AI: EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment data
Moderate
GHSA-48x2-6pr9-2jjf
was published
for
network-ai
(npm)
Jun 19, 2026
Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory
Moderate
GHSA-jvcm-f35g-w78p
was published
for
network-ai
(npm)
Jun 19, 2026
Canonical MicroCeph: path traversal issue in the remote-import AP
Moderate
CVE-2026-10720
was published
for
github.com/canonical/microceph/microceph
(Go)
Jun 19, 2026
Source controller: Improper path handling allows traversal
Moderate
CVE-2026-47680
was published
for
github.com/fluxcd/source-controller
(Go)
Jun 5, 2026
OpenStack Ironic allows file overwrite via directory traversal during deployment with a crafted ISO image
Moderate
CVE-2026-48681
was published
for
ironic
(pip)
Jun 4, 2026
Duplicate Advisory: Jupyter Server vulnerable to Path Traversal via incorrect root directory boundary check in _get_os_path()
Moderate
CVE-2026-5422
was published
for
jupyter-server
(pip)
Jun 2, 2026
•
withdrawn
OpenC3 COSMOS allows arbitrary writes to plugins directory via path-traversed config filenames
Moderate
CVE-2026-42085
was published
for
openc3
(RubyGems)
Apr 22, 2026
nbconvert has an Arbitrary File Read via Path Traversal in HTMLExporter Image Embedding
Moderate
CVE-2026-39378
was published
for
nbconvert
(pip)
Apr 21, 2026
vlt Mishandles Path Sanitization for tar
Moderate
CVE-2026-24909
was published
for
@vltpkg/tar
(npm)
Jan 28, 2026
pnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip)
Moderate
CVE-2026-23888
was published
for
pnpm
(npm)
Jan 26, 2026
pnpm scoped bin name Path Traversal allows arbitrary file creation outside node_modules/.bin
Moderate
CVE-2026-23890
was published
for
pnpm
(npm)
Jan 26, 2026
PrivateBin's template-switching feature allows arbitrary local file inclusion through path traversal
Moderate
CVE-2025-64714
was published
for
privatebin/privatebin
(Composer)
Nov 14, 2025
Assemblyline 4 service client vulnerable to Arbitrary Write through path traversal in Client code
Moderate
CVE-2025-55013
was published
for
assemblyline-service-client
(pip)
Jul 25, 2025
Filemanager is vulnerable to Relative Path Traversal through filemanager.php
Moderate
CVE-2025-46002
was published
for
simogeo/filemanager
(Composer)
Jul 18, 2025
Kirby vulnerable to path traversal of snippet names in the `snippet()` helper
Moderate
CVE-2025-30159
was published
for
getkirby/kirby
(Composer)
May 13, 2025
Kirby vulnerable to path traversal of collection names during file system lookup
Moderate
CVE-2025-31493
was published
for
getkirby/cms
(Composer)
May 13, 2025
Solon Vulnerable to Path Traversal
Moderate
CVE-2025-2961
was published
for
org.noear:solon-view
(Maven)
Mar 31, 2025
Aim Relative Path Traversal vulnerability
Moderate
CVE-2024-6483
was published
for
aim
(pip)
Mar 20, 2025
Solon Path Traversal
Moderate
CVE-2025-1584
was published
for
org.noear:solon-web-staticfiles
(Maven)
Feb 23, 2025
Apache Solr Relative Path Traversal vulnerability
Moderate
CVE-2024-52012
was published
for
org.apache.solr:solr-core
(Maven)
Jan 27, 2025
Lord of Large Language Models (LoLLMs) path traversal vulnerability in the api open_personality_folder endpoint
Moderate
CVE-2024-6985
was published
for
lollms
(pip)
Oct 11, 2024
path traversal vulnerability was identified in the parisneo/lollms-webui
Moderate
CVE-2024-4330
was published
for
lollms
(pip)
Jun 2, 2024
Oceanic allows unsanitized user input to lead to path traversal in URLs
Moderate
CVE-2024-34712
was published
for
oceanic.js
(npm)
May 14, 2024
Helm dependency management path traversal
Moderate
CVE-2024-25620
was published
for
helm.sh/helm/v3
(Go)
Feb 15, 2024
ProTip!
Advisories are also available from the
GraphQL API