Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,571 advisories

Loading
Tornado: StaticFileHandler follows symlinks outside static root (path traversal) High
GHSA-c2m8-h5v5-343r was published for tornado (pip) Sep 30, 2026
Yasha-ops Credited to Yasha-ops and iaohkut-from-NightWolf-Team iaohkut-from-NightWolf-Team iaohkut-from-NightWolf-Team
@xhmikosr/decompress: Path traversal via symlink chain Critical
CVE-2026-101894 was published for @xhmikosr/decompress (npm) Sep 29, 2026
umar0x Credited to umar0x and XhmikosR XhmikosR XhmikosR
oras-go: Arbitrary file write outside file.Store root via symlink-chain bypass in tar extraction (pushDir) High
CVE-2026-85731 was published for oras.land/oras-go/v2 (Go) Sep 17, 2026
An insufficient check allowed for the overwrite of arbitrary files via a symlink. Critical Unreviewed
CVE-2026-68491 was published Sep 15, 2026
ProTip! Advisories are also available from the GraphQL API