Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6 advisories

Loading
mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable High
CVE-2026-55581 was published for github.com/sonirico/mcp-shell (Go) Aug 25, 2026
EQSTLab Credited to EQSTLab, useworld, and sonirico useworld useworld
sonirico sonirico
mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias High
CVE-2026-55582 was published for github.com/sonirico/mcp-shell (Go) Aug 25, 2026
EQSTLab Credited to EQSTLab and sonirico sonirico sonirico
vouch-proxy has an Unbounded Multipart Cookie Allocation DoS High
CVE-2026-55149 was published for github.com/vouch/vouch-proxy (Go) Aug 20, 2026
EQSTLab Credited to EQSTLab
yutu: Arbitrary File Write via MCP `caption-download` Tool High
CVE-2026-50158 was published for github.com/eat-pray-ai/yutu (Go) Jul 14, 2026
EQSTLab Credited to EQSTLab
MKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` Causes Memory Exhaustion High
CVE-2026-50125 was published for github.com/StacklokLabs/mkp (Go) Jul 14, 2026
EQSTLab Credited to EQSTLab
Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS) High
CVE-2026-54063 was published for github.com/xuri/excelize/v2 (Go) Jul 10, 2026
EQSTLab Credited to EQSTLab
ProTip! Advisories are also available from the GraphQL API