Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

89 advisories

Loading
oran-s Credited to oran-s
XlabAITeam Credited to XlabAITeam, keenanwgn, and liangjs keenanwgn keenanwgn
liangjs liangjs
functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import High
CVE-2026-59176 was published for functype-mcp-server (npm) Sep 9, 2026
EQSTLab Credited to EQSTLab
Joker linter executed project-local .jokerd/linter.* files during linting High
CVE-2026-59172 was published for github.com/candid82/joker (Go) Sep 9, 2026
Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref High
CVE-2026-62680 was published for orval (npm) Sep 2, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code High
CVE-2026-55522 was published for PraisonAI (pip) Aug 25, 2026
rexpository Credited to rexpository
NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution High
GHSA-ghvf-qf6h-g8x5 was published for @nocobase/server (npm) Aug 20, 2026
lukehebe Credited to lukehebe
Microsoft Security Advisory CVE-2026-62902 – .NET Information Disclosure Vulnerability Moderate
CVE-2026-62902 was published for Microsoft.WindowsDesktop.App.Runtime.win-arm64 (NuGet) Aug 11, 2026
Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass) Moderate
CVE-2026-73851 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
gavinbarron Credited to gavinbarron, gn00295120, and BarakSrour gn00295120 gn00295120
BarakSrour BarakSrour
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info` Critical
CVE-2026-59865 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
Gal3m Credited to Gal3m, mrostamipoor, gavinbarron, baywet, and mohammad228 mrostamipoor mrostamipoor
gavinbarron gavinbarron baywet baywet mohammad228 mohammad228
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF High
CVE-2026-59863 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
Gal3m Credited to Gal3m, mrostamipoor, baywet, and gavinbarron mrostamipoor mrostamipoor
baywet baywet gavinbarron gavinbarron
Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref High
CVE-2026-59867 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
Gal3m Credited to Gal3m, mrostamipoor, baywet, and gavinbarron mrostamipoor mrostamipoor
baywet baywet gavinbarron gavinbarron
Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions Critical
CVE-2026-59864 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
Gal3m Credited to Gal3m, mrostamipoor, jingjingjia-ms, and baywet mrostamipoor mrostamipoor
jingjingjia-ms jingjingjia-ms baywet baywet
OpenClaw's marketplace runtime extension metadata could point at unscanned payloads High
CVE-2026-53810 was published for openclaw (npm) Jul 2, 2026
cantinagen Credited to cantinagen and Ellahinator Ellahinator Ellahinator
Cortex has Untrusted Project Bootstrap Code Execution via `CLAUDE_PROJECT_DIR` High
CVE-2026-49986 was published for neuro-cortex-memory (pip) Jul 1, 2026
EQSTLab Credited to EQSTLab and useworld useworld useworld
pnpm: Repository-controlled configDependencies can select a pacquet native install engine High
CVE-2026-55697 was published for pnpm (npm) Jun 26, 2026
massif-01 Credited to massif-01, G-Rath, and gabe-gfm G-Rath G-Rath
gabe-gfm gabe-gfm
pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle High
CVE-2026-55487 was published for pnpm (npm) Jun 26, 2026
containerd: CRI checkpoint import allows local image tag poisoning Moderate
CVE-2026-50195 was published for github.com/containerd/containerd/v2 (Go) Jun 19, 2026
hbeberman Credited to hbeberman and robertprast robertprast robertprast
[Eclipse Theia] Indirect Prompt Injection via Auto-Loaded Workspace Prompt Template Files in AI Chat High
CVE-2026-46580 was published for @theia/ai-chat (npm) Jun 18, 2026
[Eclipse Theia] Arbitrary Command Execution via Untrusted Workspace Task Definitions High
CVE-2026-44691 was published for @theia/debug (npm) Jun 18, 2026
[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat High
CVE-2026-44688 was published for @theia/ai-chat (npm) Jun 18, 2026
Pi Agent: Pi loads project-local extensions without approval Moderate
CVE-2026-54325 was published for @earendil-works/pi-coding-agent (npm) Jun 17, 2026
qerogram Credited to qerogram, urianpaul94, EQSTLab, kamalmarhubi, and useworld urianpaul94 urianpaul94
EQSTLab EQSTLab kamalmarhubi kamalmarhubi useworld useworld
SnailSploit Credited to SnailSploit
ProTip! Advisories are also available from the GraphQL API