Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

33 advisories

Loading
SearXNG MCP Server: Unbounded Response Body Read Bypasses URL Size Limit in `web_url_read` High
GHSA-xcqx-9jf5-w339 was published for mcp-searxng (npm) Jun 19, 2026
EQSTLab Credited to EQSTLab
VCR.py: Arbitrary code execution via unsafe YAML deserialization of cassette files High
GHSA-rpj2-4hq8-938g was published for vcrpy (pip) Jun 19, 2026
RamiAltai Credited to RamiAltai and EQSTLab EQSTLab EQSTLab
dbt MCP Server: Unauthenticated OAuth Context Endpoint Leaks dbt Platform Tokens Moderate
CVE-2026-55837 was published for dbt-mcp (pip) Jun 19, 2026
EQSTLab Credited to EQSTLab
Ultimate Sitemap Parser (USP): Gzip Decompression Bomb Bypasses Sitemap Size Limit High
GHSA-8823-qg2x-pv9f was published for ultimate-sitemap-parser (pip) Jun 19, 2026
EQSTLab Credited to EQSTLab
agent-coderag: Gradle Wrapper Execution During Dependency Discovery Enables Arbitrary Code Execution High
GHSA-wg5p-8h9p-3mr7 was published for agent-coderag (pip) Jun 19, 2026
EQSTLab Credited to EQSTLab and 232-323 232-323 232-323
netlicensing-mcp: REST Path Traversal Bypasses Token Redaction Critical
CVE-2026-57496 was published for netlicensing-mcp (pip) Jun 18, 2026
EQSTLab Credited to EQSTLab
Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID High
CVE-2026-54695 was published for pipecat-ai (pip) Jun 18, 2026
EQSTLab Credited to EQSTLab and min8282 min8282 min8282
Pi Agent: Pi loads project-local extensions without approval Moderate
CVE-2026-54325 was published for @earendil-works/pi-coding-agent (npm) Jun 17, 2026
qerogram Credited to qerogram, urianpaul94, EQSTLab, kamalmarhubi, and useworld urianpaul94 urianpaul94
EQSTLab EQSTLab kamalmarhubi kamalmarhubi useworld useworld
ProTip! Advisories are also available from the GraphQL API