GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
104 advisories
Filter by severity
league/commonmark: DisallowedRawHtml bypassed when a disallowed tag name ends the raw-HTML literal
Moderate
GHSA-97jj-33gv-5xf9
was published
for
league/commonmark
(Composer)
Sep 30, 2026
Nuclei: Arbitrary Command Execution via DAST Code Signature Bypass
Moderate
CVE-2026-76802
was published
for
github.com/projectdiscovery/nuclei/v3
(Go)
Sep 22, 2026
NocoBase backup restore schema name allows command injection
Moderate
CVE-2026-55410
was published
for
@nocobase/plugin-backups
(npm)
Aug 20, 2026
LibreNMS Vulnerable to Remote Code Execution via AboutController
Moderate
GHSA-jf24-8g2h-2wg7
was published
for
librenms/librenms
(Composer)
Aug 18, 2026
Electron: DevTools embedder handler executes arbitrary files via shell open
Moderate
CVE-2026-70611
was published
for
electron
(npm)
Aug 5, 2026
OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check
Moderate
CVE-2026-67438
was published
for
github.com/OliveTin/OliveTin
(Go)
Jul 30, 2026
Shescape: Path disclosure on Unix with Zsh
Moderate
CVE-2026-73412
was published
for
shescape
(npm)
Jul 24, 2026
n8n: computer-use Shell Sandbox Not Enforced on Linux and Windows
Moderate
CVE-2026-65590
was published
for
n8n
(npm)
Jul 22, 2026
Duplicate Advisory: computer-use Shell Sandbox Not Enforced on Linux and Windows
Moderate
GHSA-4v35-78jc-648r
was published
for
@n8n/computer-use
(npm)
Jul 22, 2026
•
withdrawn
Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path
Moderate
CVE-2026-55798
was published
for
Pillow
(pip)
Jul 20, 2026
OpenClaw: Bundle MCP loopback could miss its exec denylist on session spawn
Moderate
GHSA-qh2f-99mv-mrcf
was published
for
openclaw
(npm)
Jul 2, 2026
@cyclonedx/cdxgen: Maven project scanning may allow shell command injection through repository-controlled module paths
Moderate
GHSA-5vwr-qchf-q4pf
was published
for
@cyclonedx/cdxgen
(npm)
Jun 26, 2026
ImageMagick: Policy Bypass can read disallowed files via symlink
Moderate
CVE-2026-49219
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Jun 25, 2026
Jenkins Git client Plugin has an OS command injection vulnerability on agents
Moderate
CVE-2026-57282
was published
for
org.jenkins-ci.plugins:git-client
(Maven)
Jun 24, 2026
Mise's local credential_command executes untrusted config
Moderate
CVE-2026-55448
was published
for
mise
(Rust)
Jun 23, 2026
OpenStack Horizon RC file generation does not escape special characters in project names
Moderate
CVE-2026-55748
was published
for
horizon
(pip)
Jun 17, 2026
Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration
Moderate
CVE-2026-47751
was published
for
anthropics/claude-code-action
(GitHub Actions)
Jun 10, 2026
Fission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, allowing the builder pod to invoke arbitrary executables
Moderate
CVE-2026-46618
was published
for
github.com/fission/fission
(Go)
May 21, 2026
Setup PHP: Command Injection in Repository-Derived PHP Version Resolution
Moderate
CVE-2026-46420
was published
for
shivammathur/setup-php
(GitHub Actions)
May 20, 2026
Arcane Backend: OS Command Injection in Volume Browser ListDirectory via path query parameter
Moderate
CVE-2026-45626
was published
for
github.com/getarcaneapp/arcane/backend
(Go)
May 18, 2026
@apostrophecms/cli: Command Injection in apos create via Unsanitized Password Input
Moderate
CVE-2026-42853
was published
for
@apostrophecms/cli
(npm)
May 14, 2026
Fleet vulnerable to OS command injection in software packages
Moderate
CVE-2026-26191
was published
for
github.com/fleetdm/fleet/v4
(Go)
May 14, 2026
GPT-Pilot contains a command injection vulnerability in the Executor.run() method
Moderate
CVE-2026-31246
was published
for
gpt-pilot
(pip)
May 11, 2026
LobeHub has a Cross-Site Scripting issue that escalates to Remote Code Execution
Moderate
CVE-2026-42045
was published
for
@lobehub/lobehub
(npm)
May 5, 2026
Inspektor Gadget: Command Injection via malicious buildOptions manipulation
Moderate
CVE-2026-24905
was published
for
github.com/inspektor-gadget/inspektor-gadget
(Go)
Apr 22, 2026
ProTip!
Advisories are also available from the
GraphQL API