GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,509
Maven
5,000+
npm
5,000+
NuGet
1,100
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
28 advisories
Filter by severity
Directus allows unauthenticated file upload and file modification due to lacking input sanitization
Critical
CVE-2025-55746
was published
for
@directus/api
(npm)
Aug 20, 2025
Mockoon has a Path Traversal and LFI in the static file serving endpoint
High
CVE-2025-59049
was published
for
@mockoon/cli
(npm)
Mar 11, 2025
Better Auth affected by external request basePath modification DoS
Low
GHSA-569q-mpph-wgww
was published
for
better-auth
(npm)
Dec 1, 2025
@vitejs/plugin-rsc has an Arbitrary File Read via `/__vite_rsc_findSourceMapURL` Endpoint
High
CVE-2025-68155
was published
for
@vitejs/plugin-rsc
(npm)
Dec 16, 2025
jsPDF has Local File Inclusion/Path Traversal vulnerability
Critical
CVE-2025-68428
was published
for
jspdf
(npm)
Jan 5, 2026
LobeHub Vulnerable to Improper Authorization in Presigned Upload
Moderate
CVE-2026-23835
was published
for
@lobehub/chat
(npm)
Feb 1, 2026
survey-pdf Upgraded jsPDF Version Due to Security Vulnerability
Critical
CVE-2026-25630
was published
for
survey-pdf
(npm)
Feb 4, 2026
OpenClaw hardened the skill download target directory validation
Moderate
CVE-2026-27008
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw has an arbitrary transcript path file write via gateway sessionFile
High
CVE-2026-28459
was published
for
openclaw
(npm)
Feb 17, 2026
@mobilenext/mobile-mcp alllows arbitrary file write via Path Traversal in mobile screen capture tools
High
CVE-2026-33989
was published
for
@mobilenext/mobile-mcp
(npm)
Mar 27, 2026
@tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files
High
CVE-2026-33949
was published
for
@tinacms/graphql
(npm)
Mar 30, 2026
SillyTavern has a path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directory
High
CVE-2026-34522
was published
for
sillytavern
(npm)
Apr 1, 2026
Paperclip: Arbitrary File Read via Agent-Controlled adapterConfig.instructionsFilePath
Moderate
GHSA-3pw3-v88x-xj24
was published
for
@paperclipai/shared
(npm)
Apr 16, 2026
Duplicate Advisory: OpenClaw: Webchat media embedding enforces local-root containment for tool-result files
Moderate
GHSA-qc5j-2mqx-x83q
was published
for
openclaw
(npm)
Apr 20, 2026
•
withdrawn
@evomap/evolver: Path Traversal in `evolver fetch` default-branch `safeId` allows Hub-controlled overwrite of project files (RCE)
High
GHSA-cfcj-hqpf-hccf
was published
for
@evomap/evolver
(npm)
May 5, 2026
OpenClaw: Shared reply MEDIA - paths are treated as trusted and can trigger cross-channel local file exfiltration
Moderate
CVE-2026-42424
was published
for
openclaw
(npm)
Apr 9, 2026
OpenClaw: Webchat media embedding enforces local-root containment for tool-result files
Moderate
CVE-2026-41389
was published
for
openclaw
(npm)
Apr 17, 2026
i18next-fs-backend: Path traversal via unsanitised lng/ns allows arbitrary file read/overwrite
High
CVE-2026-41693
was published
for
i18next-fs-backend
(npm)
Apr 22, 2026
launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
Moderate
CVE-2026-53632
was published
for
launch-editor
(npm)
Jun 15, 2026
Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message
High
GHSA-p6gq-j5cr-w38f
was published
for
nodemailer
(npm)
Jun 18, 2026
Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning
High
GHSA-2fmp-9rvw-hc96
was published
for
network-ai
(npm)
Jun 19, 2026
pnpm: Reserved bin name deletes PNPM_HOME during global remove
Moderate
CVE-2026-55699
was published
for
pnpm
(npm)
Jun 26, 2026
pnpm: `stage download` writes outside its destination directory via manifest name/version traversal
High
CVE-2026-55700
was published
for
pnpm
(npm)
Jun 26, 2026
pnpm: Hoisted install imports lockfile alias outside node_modules
High
GHSA-fr4h-3cph-29xv
was published
for
pnpm
(npm)
Jun 27, 2026
ProTip!
Advisories are also available from the
GraphQL API