GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,509
Maven
5,000+
npm
5,000+
NuGet
1,100
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
139 advisories
Filter by severity
GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython
High
GHSA-hmq2-w58f-27jc
was published
for
GitPython
(pip)
Aug 7, 2026
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
Moderate
GHSA-hh9p-6wh2-4mfc
was published
for
GitPython
(pip)
Aug 7, 2026
Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys
High
GHSA-88pr-878c-24wf
was published
for
flowise
(npm)
Aug 4, 2026
GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()
Moderate
GHSA-539m-9xh6-q6rr
was published
for
GitPython
(pip)
Aug 3, 2026
GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read
High
GHSA-3f7w-8rr8-f37f
was published
for
GitPython
(pip)
Aug 3, 2026
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
Critical
CVE-2026-67429
was published
for
flyto-core
(pip)
Jul 30, 2026
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway
Critical
GHSA-68r5-9hpg-7qw9
was published
for
org.openidentityplatform.opendj:opendj-dsml-servlet
(Maven)
Jul 24, 2026
ImageMagick: Policy Bypass in concatenate operation due to missing checks
Moderate
CVE-2026-55628
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jul 24, 2026
LiteLLM: Local file read via request-supplied OIDC file references
Low
CVE-2026-59819
was published
for
litellm
(pip)
Jul 22, 2026
n8n: Edit Image Node Format Injection Allows Arbitrary File Write
High
GHSA-xmc9-4f2h-jf9c
was published
for
n8n
(npm)
Jul 22, 2026
Gitea: Local File Inclusion via file:// URI in Migration Restore
Moderate
CVE-2026-58420
was published
for
gitea.dev
(Go)
Jul 21, 2026
Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode
High
CVE-2026-54629
was published
for
github.com/julien040/anyquery
(Go)
Jul 14, 2026
yutu: Arbitrary File Write via MCP `caption-download` Tool
High
CVE-2026-50158
was published
for
github.com/eat-pray-ai/yutu
(Go)
Jul 14, 2026
Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode
Critical
CVE-2026-50006
was published
for
github.com/julien040/anyquery
(Go)
Jul 14, 2026
mcp-atlassian: Arbitrary server-side file read via attachment upload
High
GHSA-wm45-qh3g-v83f
was published
for
mcp-atlassian
(pip)
Jul 10, 2026
psd-tools vulnerable to arbitrary file write via smart-object filename
Moderate
CVE-2026-49836
was published
for
psd-tools
(pip)
Jul 9, 2026
Rattler vulnerable to package cache path traversal via conda package build string
Moderate
CVE-2026-53956
was published
for
py_rattler
(pip)
Jul 9, 2026
Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths
High
GHSA-52vm-mxx8-f227
was published
for
phantom-audio
(pip)
Jul 9, 2026
oasdiff does not enforce --allow-external-refs=false on the git-revision load path (SSRF / local file read)
Moderate
CVE-2026-53508
was published
for
github.com/oasdiff/oasdiff
(Go)
Jul 7, 2026
EGroupware Vulnerable to Local File Inclusion via file:// URI in Mail Compose
Moderate
CVE-2026-45016
was published
for
egroupware/egroupware
(Composer)
Jul 7, 2026
Recce server has unauthenticated SQL execution that allows local file read/write through DuckDB
High
CVE-2026-49360
was published
for
recce
(pip)
Jul 2, 2026
Mautic vulnerable to Path Traversal via Campaign Import
Critical
CVE-2026-9559
was published
for
mautic/core
(Composer)
Jul 2, 2026
oras-go has file store write outside workingDir via symlink traversal
Moderate
CVE-2026-50162
was published
for
oras.land/oras-go/v2
(Go)
Jul 1, 2026
Keras: HDF5 virtual datasets can disclose local files
Moderate
CVE-2026-12480
was published
for
keras
(pip)
Jul 1, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components
Moderate
GHSA-2wwr-9x6f-88gp
was published
for
easycorp/easyadmin-bundle
(Composer)
Jul 1, 2026
ProTip!
Advisories are also available from the
GraphQL API