GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,562
Maven
5,000+
npm
5,000+
NuGet
917
pip
4,807
Pub
13
RubyGems
1,038
Rust
1,238
Swift
53
Unreviewed advisories
All unreviewed
5,000+
432 advisories
Filter by severity
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 150.
Moderate
Unreviewed
CVE-2026-6774
was published
Apr 21, 2026
Mitigation bypass in the File Handling component. This vulnerability was fixed in Firefox 150 and...
Moderate
Unreviewed
CVE-2026-6763
was published
Apr 21, 2026
NEMU contains an implementation flaw in its RISC-V Hypervisor CSR handling where henvcfg[7:4] ...
Critical
Unreviewed
CVE-2026-29649
was published
Apr 20, 2026
OpenClaw: Browser interaction routes could pivot into local CDP and regain file reads
Moderate
GHSA-qmwg-qprg-3j38
was published
for
openclaw
(npm)
Apr 17, 2026
October Rain has a Twig Sandbox Bypass via Collection Methods
Moderate
CVE-2026-22692
was published
for
october/rain
(Composer)
Apr 14, 2026
ImageMagick has a heap-use-after-free via XMP profile could result in a crash when printing the values.
Moderate
CVE-2026-40311
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Apr 14, 2026
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a...
High
Unreviewed
CVE-2026-32225
was published
Apr 14, 2026
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing...
Moderate
Unreviewed
CVE-2026-32202
was published
Apr 14, 2026
PraisonAI Vulnerable to Code Injection and Protection Mechanism Failure
High
CVE-2026-40158
was published
for
PraisonAI
(pip)
Apr 10, 2026
Policy bypass in ServiceWorkers in Google Chrome prior to 147.0.7727.55 allowed a remote attacker...
Moderate
Unreviewed
CVE-2026-5911
was published
Apr 9, 2026
Policy bypass in Downloads in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to...
Moderate
Unreviewed
CVE-2026-5900
was published
Apr 9, 2026
Policy bypass in IFrameSandbox in Google Chrome prior to 147.0.7727.55 allowed a remote attacker...
Moderate
Unreviewed
CVE-2026-5903
was published
Apr 9, 2026
Policy bypass in Audio in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who...
Moderate
Unreviewed
CVE-2026-5896
was published
Apr 9, 2026
PraisonAI has sandbox escape via exception frame traversal in `execute_code` (subprocess mode)
Critical
CVE-2026-39888
was published
for
praisonaiagents
(pip)
Apr 8, 2026
Lupa has a Sandbox escape and RCE due to incomplete attribute_filter enforcement in getattr / setattr
High
CVE-2026-34444
was published
for
lupa
(pip)
Apr 7, 2026
Directus: Missing Cross-Origin Opener Policy
High
CVE-2026-35408
was published
for
directus
(npm)
Apr 4, 2026
SandboxJS: Sandbox integrity escape
Critical
CVE-2026-34208
was published
for
@nyariv/sandboxjs
(npm)
Apr 3, 2026
PraisonAI: Python Sandbox Escape via str Subclass startswith() Override in execute_code
Critical
CVE-2026-34938
was published
for
praisonaiagents
(pip)
Apr 1, 2026
Insufficient policy enforcement in WebUSB in Google Chrome prior to 146.0.7680.178 allowed a...
Moderate
Unreviewed
CVE-2026-5276
was published
Apr 1, 2026
vLLM has Hardcoded Trust Override in Model Files Enables RCE Despite Explicit User Opt-Out
High
CVE-2026-27893
was published
for
vllm
(pip)
Mar 27, 2026
OpenClaw has Inconsistent Host Exec Environment Override Sanitization
High
CVE-2026-35650
was published
for
openclaw
(npm)
Mar 26, 2026
@grackle-ai/server has Missing Content-Security-Policy and X-Frame-Options Headers
Moderate
GHSA-3mjm-x6gw-2x42
was published
for
@grackle-ai/server
(npm)
Mar 25, 2026
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS...
High
Unreviewed
CVE-2026-20701
was published
Mar 25, 2026
This issue was addressed through improved state management. This issue is fixed in Safari 26.4,...
Moderate
Unreviewed
CVE-2026-20665
was published
Mar 25, 2026
Scriban: Sandbox escape due to TypedObjectAccessorcache bypassing MemberFilter after TemplateContext reuse
Critical
GHSA-5wr9-m6jw-xx44
was published
for
scriban
(NuGet)
Mar 24, 2026
ProTip!
Advisories are also available from the
GraphQL API