GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
156 advisories
Filter by severity
Nuxt dev server vite-node IPC socket is world-connectable on Linux
Moderate
CVE-2026-56301
was published
for
nuxt
(npm)
Jun 16, 2026
Duplicate Advisory: Nuxt dev server vite-node IPC socket is world-connectable on Linux
Moderate
GHSA-2x6f-57hp-86fx
was published
for
nuxt
(npm)
Jun 23, 2026
•
withdrawn
SurrealDB: Full Table Permissions by Default
High
CVE-2023-54366
was published
for
surrealdb
(Rust)
Dec 15, 2023
Duplicate Advisory: Full Table Permissions by Default
High
GHSA-m8pp-qc66-6pgp
was published
for
surrealdb
(Rust)
Jul 18, 2026
•
withdrawn
Duplicate Advisory: SurrealDB has Silent Failure to Overwrite Table Definition of Relation Type
Low
GHSA-vmg6-53r4-jhpw
was published
for
surrealdb
(Rust)
Jul 18, 2026
•
withdrawn
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket
High
CVE-2026-53657
was published
for
github.com/lima-vm/lima/v2
(Go)
Aug 14, 2026
Apache ActiveMQ has an Incorrect Default Permissions vulnerability
High
CVE-2026-49157
was published
for
org.apache.activemq:apache-activemq
(Maven)
Jun 1, 2026
YesWiki vulnerable to unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action
Critical
CVE-2026-52766
was published
for
yeswiki/yeswiki
(Composer)
Jul 9, 2026
turso-cli persists Turso platform JWT with world-readable (0o644) file permissions
Moderate
CVE-2026-48790
was published
for
github.com/tursodatabase/turso-cli
(Go)
Jun 26, 2026
nextflow auth login command has incorrect default permissions
Moderate
CVE-2026-48722
was published
for
io.nextflow:nextflow
(Maven)
Jun 25, 2026
Hermes Agent creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644)
Moderate
CVE-2026-53870
was published
for
hermes-agent
(pip)
Jun 17, 2026
OpenClaw: Config recovery could restore openclaw.json with broad file permissions
Moderate
CVE-2026-53856
was published
for
openclaw
(npm)
Jun 18, 2026
Spring AI: ChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakage
High
CVE-2026-41712
was published
for
org.springframework.ai:spring-ai-advisors-vector-store
(Maven)
May 12, 2026
openclaw-claude-bridge: sandbox is not effective - `--allowed-tools ""` does not restrict available tools
Moderate
CVE-2026-39398
was published
for
openclaw-claude-bridge
(npm)
Apr 8, 2026
OpenClaw session transcript files were created without forced user-only permissions
Moderate
CVE-2026-33572
was published
for
openclaw
(npm)
Mar 16, 2026
Claude SDK for Python has Insecure Default File Permissions in Local Filesystem Memory Tool
Moderate
CVE-2026-34450
was published
for
anthropic
(pip)
Apr 1, 2026
Apache Airflow: Incorrect Default Permissions in audit logs for Ops and Viewers users
Moderate
CVE-2024-26280
was published
for
apache-airflow
(pip)
Mar 1, 2024
operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd
Moderate
CVE-2025-7195
was published
for
github.com/operator-framework/operator-sdk
(Go)
Aug 7, 2025
Capgo CLI: symlink-following local secret writes enable arbitrary file overwrite + world-readable credentials (0600 missing)
High
GHSA-8mpm-q7mh-8fvh
was published
for
@capgo/cli
(npm)
Mar 18, 2026
Liferay Portal and Liferay DXP Allows Templates to be Viewed via the UI or API
Moderate
CVE-2024-25605
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 20, 2024
.NET Elevation of Privilege Vulnerability
High
CVE-2026-26131
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Mar 11, 2026
Duplicate Advisory: Microsoft Security Advisory CVE-2026-26131 – .NET Elevation of Privilege Vulnerability
High
GHSA-387c-qmrw-59qv
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Mar 10, 2026
•
withdrawn
AWS CLI: cli_history database does not restrict file permissions on Unix systems
Moderate
GHSA-747p-wmpv-9c78
was published
for
awscli
(pip)
Feb 27, 2026
AutoGPT is Vulnerable to RCE via Disabled Block Execution
High
CVE-2026-24780
was published
for
agpt
(pip)
Jan 29, 2026
Pepr Has Overly Permissive RBAC ClusterRole in Admin Mode
Low
CVE-2026-23634
was published
for
pepr
(npm)
Jan 15, 2026
ProTip!
Advisories are also available from the
GraphQL API