Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

104 advisories

Loading
league/commonmark: DisallowedRawHtml bypassed when a disallowed tag name ends the raw-HTML literal Moderate
GHSA-97jj-33gv-5xf9 was published for league/commonmark (Composer) Sep 30, 2026
4n86rakam1 Credited to 4n86rakam1
Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass Moderate
CVE-2026-76802 was published for github.com/projectdiscovery/nuclei/v3 (Go) Sep 22, 2026
daffainfo Credited to daffainfo
NocoBase backup restore schema name allows command injection Moderate
CVE-2026-55410 was published for @nocobase/plugin-backups (npm) Aug 20, 2026
sondt99 Credited to sondt99
LibreNMS Vulnerable to Remote Code Execution via AboutController Moderate
GHSA-jf24-8g2h-2wg7 was published for librenms/librenms (Composer) Aug 18, 2026
tCu0n9 Credited to tCu0n9
Electron: DevTools embedder handler executes arbitrary files via shell open Moderate
CVE-2026-70611 was published for electron (npm) Aug 5, 2026
OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check Moderate
CVE-2026-67438 was published for github.com/OliveTin/OliveTin (Go) Jul 30, 2026
Ayantaker Credited to Ayantaker
Shescape: Path disclosure on Unix with Zsh Moderate
CVE-2026-73412 was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
n8n: computer-use Shell Sandbox Not Enforced on Linux and Windows Moderate
CVE-2026-65590 was published for n8n (npm) Jul 22, 2026
Duplicate Advisory: computer-use Shell Sandbox Not Enforced on Linux and Windows Moderate
GHSA-4v35-78jc-648r was published for @n8n/computer-use (npm) Jul 22, 2026 • withdrawn
Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path Moderate
CVE-2026-55798 was published for Pillow (pip) Jul 20, 2026
1121984919 Credited to 1121984919 and radarhere radarhere radarhere
OpenClaw: Bundle MCP loopback could miss its exec denylist on session spawn Moderate
GHSA-qh2f-99mv-mrcf was published for openclaw (npm) Jul 2, 2026
cantinagen Credited to cantinagen and Ellahinator Ellahinator Ellahinator
@cyclonedx/cdxgen: Maven project scanning may allow shell command injection through repository-controlled module paths Moderate
GHSA-5vwr-qchf-q4pf was published for @cyclonedx/cdxgen (npm) Jun 26, 2026
aleff-github Credited to aleff-github
ImageMagick: Policy Bypass can read disallowed files via symlink Moderate
CVE-2026-49219 was published for Magick.NET-Q16-AnyCPU (NuGet) Jun 25, 2026
GameZoneHacker Credited to GameZoneHacker
Jenkins Git client Plugin has an OS command injection vulnerability on agents Moderate
CVE-2026-57282 was published for org.jenkins-ci.plugins:git-client (Maven) Jun 24, 2026
Mise's local credential_command executes untrusted config Moderate
CVE-2026-55448 was published for mise (Rust) Jun 23, 2026
kq5y Credited to kq5y
OpenStack Horizon RC file generation does not escape special characters in project names Moderate
CVE-2026-55748 was published for horizon (pip) Jun 17, 2026
Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration Moderate
CVE-2026-47751 was published for anthropics/claude-code-action (GitHub Actions) Jun 10, 2026
antonisloukis Credited to antonisloukis
b0b0haha Credited to b0b0haha, j311yl0v3u, and sanketsudake j311yl0v3u j311yl0v3u
sanketsudake sanketsudake
Setup PHP: Command Injection in Repository-Derived PHP Version Resolution Moderate
CVE-2026-46420 was published for shivammathur/setup-php (GitHub Actions) May 20, 2026
Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter Moderate
CVE-2026-45626 was published for github.com/getarcaneapp/arcane/backend (Go) May 18, 2026
offset Credited to offset
@apostrophecms/cli: Command Injection in apos create via Unsanitized Password Input Moderate
CVE-2026-42853 was published for @apostrophecms/cli (npm) May 14, 2026
VadlaReddySai Credited to VadlaReddySai and Chittu13 Chittu13 Chittu13
Fleet vulnerable to OS command injection in software packages Moderate
CVE-2026-26191 was published for github.com/fleetdm/fleet/v4 (Go) May 14, 2026
GPT-Pilot contains a command injection vulnerability in the Executor.run() method Moderate
CVE-2026-31246 was published for gpt-pilot (pip) May 11, 2026
LobeHub has a Cross-Site Scripting issue that escalates to Remote Code Execution Moderate
CVE-2026-42045 was published for @lobehub/lobehub (npm) May 5, 2026
Hpd0ger Credited to Hpd0ger and aftern00n aftern00n aftern00n
Inspektor Gadget: Command Injection via malicious buildOptions manipulation Moderate
CVE-2026-24905 was published for github.com/inspektor-gadget/inspektor-gadget (Go) Apr 22, 2026
ndaprela Credited to ndaprela, suidpit, eiffel-fl, and burak-ok suidpit suidpit
eiffel-fl eiffel-fl burak-ok burak-ok
ProTip! Advisories are also available from the GraphQL API