Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

211 advisories

Loading
yii2-mcp-server has a Command Injection Issue Low
CVE-2026-7600 was published for yii2-mcp-server (npm) May 2, 2026
mcp-server-semgrep has a Command Injection issue Moderate
CVE-2026-7446 was published for mcp-server-semgrep (npm) Apr 30, 2026
electerm has Command Injection via runLinux funtion Critical
CVE-2026-41501 was published for electerm (npm) Apr 24, 2026
Yuremin Credited to Yuremin and FORIMOC FORIMOC FORIMOC
Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses Critical
GHSA-wpqr-6v78-jr5g was published for @google/gemini-cli (GitHub Actions) Apr 24, 2026
DanusMinimus Credited to DanusMinimus and EladMeged-Novee EladMeged-Novee EladMeged-Novee
Claude Code: Trust Dialog Bypass via Git Worktree Spoofing Allows Arbitrary Code Execution High
CVE-2026-40068 was published for @anthropic-ai/claude-code (npm) Apr 24, 2026
Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability Critical
CVE-2026-41265 was published for flowise (npm) Apr 18, 2026
zdi-disclosures Credited to zdi-disclosures
Paperclip: Malicious skills able to exfiltrate and destroy all user data High
GHSA-w8hx-hqjv-vjcq was published for @paperclipai/server (npm) Apr 16, 2026
electerm: electerm_install_script_CommandInjection Vulnerability Report Critical
CVE-2026-41500 was published for electerm (npm) Apr 16, 2026
Yuremin Credited to Yuremin and FORIMOC FORIMOC FORIMOC
Agions taskflow-ai vulnerable to os command injection in src/mcp/server/handlers.ts Moderate
CVE-2026-5831 was published for taskflow-ai (npm) Apr 9, 2026
@nor2/heim-mcp vulnerable to command injection Low
CVE-2026-5602 was published for @nor2/heim-mcp (npm) Apr 6, 2026
@elgentos/magento2-dev-mcp vulnerable to command injection Low
CVE-2026-5603 was published for @elgentos/magento2-dev-mcp (npm) Apr 6, 2026
OpenClaw: Arbitrary code execution via unvalidated WebView JavascriptInterface High
CVE-2026-35643 was published for openclaw (npm) Mar 26, 2026
cyjhhh Credited to cyjhhh
@siteboon/claude-code-ui is Vulnerable to Command Injection via Multiple Parameters Critical
CVE-2026-31862 was published for @siteboon/claudecodeui (npm) Mar 11, 2026
toufik-airane Credited to toufik-airane and neo-ai-engineer neo-ai-engineer neo-ai-engineer
@budibase/server: Command Injection in PostgreSQL Dump Command High
CVE-2026-25041 was published for @budibase/server (npm) Mar 9, 2026
omkarparth Credited to omkarparth
tdjackey Credited to tdjackey
MCP NMAP Server has an Injection vulnerability Moderate
CVE-2026-3484 was published for mcp-nmap-server (npm) Mar 3, 2026
OpenClaw: Unsanitized CWD path injection into LLM prompts High
CVE-2026-27001 was published for openclaw (npm) Feb 18, 2026
aether-ai-agent Credited to aether-ai-agent
xcode-mcp-server vulnerable to Command Injection Low
CVE-2026-2178 was published for xcode-mcp-server (npm) Feb 8, 2026
mcp-maigret vulnerable to command injection Moderate
CVE-2026-2130 was published for mcp-maigret (npm) Feb 8, 2026
BrowserStack Local vulnerable to Command Injection through logfile variable Moderate
CVE-2025-57283 was published for browserstack-local (npm) Jan 28, 2026
mgol Credited to mgol
Saltcorn's Reflected XSS and Command Injection vulnerabilities can be chained for 1-click-RCE Critical
GHSA-cr3w-cw5w-h3fj was published for @saltcorn/server (npm) Jan 26, 2026
Mathis-Z Credited to Mathis-Z
Orval Mock Generation Code Injection via const High
CVE-2026-24132 was published for @orval/mock (npm) Jan 22, 2026
k14uz Credited to k14uz
Orval has a code injection via unsanitized x-enum-descriptions in enum generation Critical
CVE-2026-23947 was published for @orval/core (npm) Jan 21, 2026
k14uz Credited to k14uz and ZipJo ZipJo ZipJo
Renovate vulnerable to arbitrary command injection via helmv3 manager and malicious Chart.yaml file Moderate
GHSA-3f44-xw83-3pmg was published for renovate (npm) Jan 13, 2026
astellingwerf Credited to astellingwerf
ProTip! Advisories are also available from the GraphQL API