GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
46
Go
3,270
Maven
5,000+
npm
5,000+
NuGet
867
pip
4,517
Pub
12
RubyGems
998
Rust
1,194
Swift
51
Unreviewed advisories
All unreviewed
5,000+
10 advisories
Filter by severity
Zen-AI-Pentest has Shell Injection via untrusted issue title in ZenClaw Discord Integration workflow
Critical
GHSA-f67f-hcr6-94mf
was published
for
SHAdd0WTAka/Zen-Ai-Pentest
(GitHub Actions)
Mar 20, 2026
xygeni-action v5 tag poisoned with C2 backdoor
Critical
CVE-2026-31976
was published
for
xygeni/xygeni-action
(GitHub Actions)
Mar 11, 2026
j178/prek-action vulnerable to arbitrary code injection in composite action
Critical
GHSA-pwf7-47c3-mfhx
was published
for
j178/prek-action
(GitHub Actions)
Sep 29, 2025
m00nl1ght-dev/steam-workshop-deploy: Exposure of Version-Control Repository to an Unauthorized Control Sphere and Insufficiently Protected Credentials
Critical
GHSA-x6gv-2rvh-qmp6
was published
for
BoldestDungeon/steam-workshop-deploy
(GitHub Actions)
Aug 13, 2025
tj-actions/branch-names has a Command Injection Vulnerability
Critical
CVE-2025-54416
was published
for
tj-actions/branch-names
(GitHub Actions)
Jul 25, 2025
Cromwell GitHub Actions Secrets exfiltration via `Issue_comment`
Critical
GHSA-phf6-hm3h-x8qp
was published
for
broadinstitute/cromwell
(GitHub Actions)
May 28, 2025
memory overflow vulnerability in OpenEXR-viewer
Critical
CVE-2023-50245
was published
for
afichet/openexr-viewer
(GitHub Actions)
Dec 12, 2023
tj-actions/branch-names's Improper Sanitization of Branch Name Leads to Arbitrary Code Injection
Critical
CVE-2023-49291
was published
for
tj-actions/branch-names
(GitHub Actions)
Dec 5, 2023
gajira-create GitHub action vulnerable to arbitrary code execution
Critical
CVE-2020-14188
was published
for
atlassian/gajira-create
(GitHub Actions)
Oct 7, 2022
check-spelling workflow vulnerable to token leakage via symlink attack
Critical
CVE-2021-32724
was published
for
check-spelling/check-spelling
(GitHub Actions)
Jul 29, 2022
ProTip!
Advisories are also available from the
GraphQL API