Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

139 advisories

Loading
tinyb0y Credited to tinyb0y
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout() Moderate
GHSA-hh9p-6wh2-4mfc was published for GitPython (pip) Aug 7, 2026
BarakSrour Credited to BarakSrour
Mirr2 Credited to Mirr2
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules) Critical
CVE-2026-67429 was published for flyto-core (pip) Jul 30, 2026
kaimandalic Credited to kaimandalic
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway Critical
GHSA-68r5-9hpg-7qw9 was published for org.openidentityplatform.opendj:opendj-dsml-servlet (Maven) Jul 24, 2026
manus-use Credited to manus-use
ImageMagick: Policy Bypass in concatenate operation due to missing checks Moderate
CVE-2026-55628 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
LiteLLM: Local file read via request-supplied OIDC file references Low
CVE-2026-59819 was published for litellm (pip) Jul 22, 2026
n8n: Edit Image Node Format Injection Allows Arbitrary File Write High
GHSA-xmc9-4f2h-jf9c was published for n8n (npm) Jul 22, 2026
simonkoeck Credited to simonkoeck
Gitea: Local File Inclusion via file:// URI in Migration Restore Moderate
CVE-2026-58420 was published for gitea.dev (Go) Jul 21, 2026
isa0-gh Credited to isa0-gh and ibrahmsql ibrahmsql ibrahmsql
Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode High
CVE-2026-54629 was published for github.com/julien040/anyquery (Go) Jul 14, 2026
Metincloup Credited to Metincloup
yutu: Arbitrary File Write via MCP `caption-download` Tool High
CVE-2026-50158 was published for github.com/eat-pray-ai/yutu (Go) Jul 14, 2026
EQSTLab Credited to EQSTLab
Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode Critical
CVE-2026-50006 was published for github.com/julien040/anyquery (Go) Jul 14, 2026
Metincloup Credited to Metincloup
mcp-atlassian: Arbitrary server-side file read via attachment upload High
GHSA-wm45-qh3g-v83f was published for mcp-atlassian (pip) Jul 10, 2026
0xmagic0 Credited to 0xmagic0
psd-tools vulnerable to arbitrary file write via smart-object filename Moderate
CVE-2026-49836 was published for psd-tools (pip) Jul 9, 2026
seankohjs Credited to seankohjs and yueyueL yueyueL yueyueL
Rattler vulnerable to package cache path traversal via conda package build string Moderate
CVE-2026-53956 was published for py_rattler (pip) Jul 9, 2026
Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths High
GHSA-52vm-mxx8-f227 was published for phantom-audio (pip) Jul 9, 2026
leesaenz Credited to leesaenz
oasdiff does not enforce --allow-external-refs=false on the git-revision load path (SSRF / local file read) Moderate
CVE-2026-53508 was published for github.com/oasdiff/oasdiff (Go) Jul 7, 2026
EGroupware Vulnerable to Local File Inclusion via file:// URI in Mail Compose Moderate
CVE-2026-45016 was published for egroupware/egroupware (Composer) Jul 7, 2026
smitocaru Credited to smitocaru
Mautic vulnerable to Path Traversal via Campaign Import Critical
CVE-2026-9559 was published for mautic/core (Composer) Jul 2, 2026
nglong05 Credited to nglong05, f3nrir77, escopecz, patrykgruszka, and LeuchtfeuerDigitalMarketing f3nrir77 f3nrir77
escopecz escopecz patrykgruszka patrykgruszka LeuchtfeuerDigitalMarketing LeuchtfeuerDigitalMarketing
oras-go has file store write outside workingDir via symlink traversal Moderate
CVE-2026-50162 was published for oras.land/oras-go/v2 (Go) Jul 1, 2026
1seal Credited to 1seal
Keras: HDF5 virtual datasets can disclose local files Moderate
CVE-2026-12480 was published for keras (pip) Jul 1, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components Moderate
GHSA-2wwr-9x6f-88gp was published for easycorp/easyadmin-bundle (Composer) Jul 1, 2026
ProTip! Advisories are also available from the GraphQL API