Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

243 advisories

Loading
Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability Moderate
CVE-2026-62902 was published for Microsoft.WindowsDesktop.App.Runtime.win-arm64 (NuGet) Aug 11, 2026
Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass) Moderate
GHSA-p5rm-jg5c-8c77 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
gavinbarron Credited to gavinbarron and gn00295120 gn00295120 gn00295120
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info` Critical
CVE-2026-59865 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
Gal3m Credited to Gal3m, mrostamipoor, gavinbarron, baywet, and mohammad228 mrostamipoor mrostamipoor
gavinbarron gavinbarron baywet baywet mohammad228 mohammad228
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF High
CVE-2026-59863 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
Gal3m Credited to Gal3m, mrostamipoor, baywet, and gavinbarron mrostamipoor mrostamipoor
baywet baywet gavinbarron gavinbarron
Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref High
CVE-2026-59867 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
Gal3m Credited to Gal3m, mrostamipoor, baywet, and gavinbarron mrostamipoor mrostamipoor
baywet baywet gavinbarron gavinbarron
Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions Critical
CVE-2026-59864 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
Gal3m Credited to Gal3m, mrostamipoor, jingjingjia-ms, and baywet mrostamipoor mrostamipoor
jingjingjia-ms jingjingjia-ms baywet baywet
OpenClaw's marketplace runtime extension metadata could point at unscanned payloads High
CVE-2026-53810 was published for openclaw (npm) Jul 2, 2026
cantinagen Credited to cantinagen and Ellahinator Ellahinator Ellahinator
ProTip! Advisories are also available from the GraphQL API