GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,506
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
81 advisories
Filter by severity
Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages
High
CVE-2026-70492
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-origin
High
CVE-2026-70486
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Stored web worker XSS via Pyodide
High
CVE-2026-59214
was published
for
open-webui
(pip)
Jul 24, 2026
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
High
GHSA-pppj-hq3g-57pj
was published
for
jupyterlab
(pip)
Jul 22, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
High
GHSA-gx64-gj6p-pc4c
was published
for
jupyterlab
(pip)
Jul 22, 2026
`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes
High
CVE-2026-49825
was published
for
lxml_html_clean
(pip)
Jul 8, 2026
Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages
High
CVE-2026-26193
was published
for
open-webui
(pip)
Jul 7, 2026
Open WebUI vulnerable to Stored XSS via iFrame in citations model
High
CVE-2026-26192
was published
for
open-webui
(pip)
Jul 7, 2026
Open WebUI vulnerable to stored XSS via unescaped markdown token in MarkdownTokens.svelte leading to full account takeover and RCE via functions
High
CVE-2025-46719
was published
for
open-webui
(pip)
Jul 7, 2026
jupyterlab-git extension: Stored XSS leading to RCE
High
CVE-2026-54527
was published
for
@jupyterlab/git
(npm)
Jun 19, 2026
PraisonAI: HTTPApproval dashboard renders tool arguments as raw HTML, allowing approval-page XSS to approve dangerous tools
High
CVE-2026-56840
was published
for
praisonai
(pip)
Jun 18, 2026
Open WebUI: Stored XSS to Account Takeover via Model Profile Images
High
CVE-2026-54013
was published
for
open-webui
(pip)
Jun 17, 2026
Open WebUI: Stored XSS in Mermaid Markdown Preview
High
CVE-2026-54011
was published
for
open-webui
(pip)
Jun 17, 2026
Litestar has HTML Injection Through its CSRF Token
High
CVE-2026-48060
was published
for
litestar
(pip)
Jun 10, 2026
Open WebUI vulnerable to stored XSS via OAuth picture claim stored as SVG data URI in profile_image_url
High
GHSA-3wgj-c2hg-vm6q
was published
for
open-webui
(pip)
May 14, 2026
pyLoad is vulnerable to stored XSS in Downloads view via unsanitized link URL in packages.js template literal
High
CVE-2026-45348
was published
for
pyload-ng
(pip)
May 14, 2026
Open WebUI has stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions
High
CVE-2026-45315
was published
for
open-webui
(pip)
May 14, 2026
Open WebUI has stored XSS via the HTML renedering view
High
CVE-2026-45303
was published
for
open-webui
(pip)
May 14, 2026
ethyca-fides has a DOM-based XSS vulnerability in fides.js via fides_description override
High
CVE-2026-44541
was published
for
ethyca-fides
(pip)
May 14, 2026
Open WebUI has stored XSS in Excel file preview
High
CVE-2026-44549
was published
for
open-webui
(pip)
May 8, 2026
open-webui Vulnerable to Stored XSS via Model Description
High
CVE-2026-44721
was published
for
open-webui
(npm)
May 8, 2026
netbox-data-flows has stored XSS in ObjectAlias names rendered inside DataFlow tables
High
GHSA-v7qw-hx66-4w9x
was published
for
netbox-data-flows
(pip)
May 7, 2026
JupyterLab's command linker attributes in HTML enable one-click command execution from untrusted content
High
CVE-2026-42557
was published
for
jupyterlab
(pip)
May 6, 2026
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS
High
CVE-2026-40171
was published
for
@jupyter-notebook/help-extension
(npm)
Apr 30, 2026
ProTip!
Advisories are also available from the
GraphQL API