Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

122 advisories

Loading
sour-exploit Credited to sour-exploit
Lemur has an authorization bypass in StrictRolePermission / AuthorityCreatorPermission High
CVE-2026-48508 was published for lemur (pip) Jun 25, 2026
hits313 Credited to hits313
LangGraph SDK has unsafe URL path construction Moderate
CVE-2026-48776 was published for langgraph-sdk (pip) Jun 25, 2026
pucagit Credited to pucagit
stigmem-node: decay sweep expires and counts facts across all tenants (cross-tenant BOLA) High
GHSA-6gqw-jqv7-v88m was published for stigmem-node (pip) Jun 19, 2026
Duplicate Advisory: PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands Moderate
GHSA-x44p-gg67-52fc was published for praisonai (pip) Jun 19, 2026 withdrawn
rexpository Credited to rexpository
PraisonAI Code agent tools fail open without a workspace boundary High
GHSA-gcq3-mfvh-3x25 was published for praisonai (pip) Jun 18, 2026
rexpository Credited to rexpository
PraisonAI: Unauthenticated RCE via Jobs API + Approval Bypass Critical
GHSA-4869-x4pr-q22x was published for praisonai (pip) Jun 18, 2026
lc13n Credited to lc13n
PraisonAI: Compute-bridged file tools allow shell command injection High
GHSA-w6h2-fr4q-xvxv was published for praisonai (pip) Jun 18, 2026
rexpository Credited to rexpository
PraisonAI recipe.run_stream skips dangerous-tool policy enforcement High
GHSA-v847-hxxw-3pxg was published for praisonai (pip) Jun 18, 2026
rexpository Credited to rexpository
PraisonAI Slack app_mention bypasses configured user/channel authorization High
GHSA-qvpf-j64c-jmhr was published for praisonai (pip) Jun 18, 2026
rexpository Credited to rexpository
PraisonAI DiscordApproval accepts unrelated channel messages as dangerous-tool approvals High
GHSA-8579-rgg5-ph2m was published for praisonai (pip) Jun 18, 2026
rexpository Credited to rexpository
Open WebUI: Any authenticated user can read other users' private notes via Socket.IO Moderate
CVE-2026-54022 was published for open-webui (pip) Jun 17, 2026
johnatzeropath Credited to johnatzeropath and LeftenantZero LeftenantZero LeftenantZero
brodmart Credited to brodmart and Classic298 Classic298 Classic298
PraisonAI Platform has a cross-workspace IDOR + member-role privilege escalation Critical
CVE-2026-47407 was published for praisonai-platform (pip) May 29, 2026
spbavarva Credited to spbavarva
LiteLLM allows a user to modify their own user_role via the /user/update endpoint High
CVE-2026-47102 was published for litellm (pip) May 21, 2026
wger: cross-tenant account deletion / deactivation / activation by gym.manage_gym + gym=None High
GHSA-mw8f-w6p8-xrf4 was published for wger (pip) May 20, 2026
HiyokoSauna37 Credited to HiyokoSauna37
aliceQWAS Credited to aliceQWAS
aliceQWAS Credited to aliceQWAS and Classic298 Classic298 Classic298
qi-scape Credited to qi-scape and Classic298 Classic298 Classic298
Authlib OIDC Implicit/Hybrid Authorization Vulnerable to Open Redirect Moderate
CVE-2026-44681 was published for authlib (pip) May 13, 2026
y011d4 Credited to y011d4
Open WebUI: Deactivated Channel Members Retain Full Access to Group/DM Channels Moderate
CVE-2026-44561 was published for open-webui (pip) May 8, 2026
Classic298 Credited to Classic298
ProTip! Advisories are also available from the GraphQL API