Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

51 advisories

Loading
uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability Moderate
CVE-2026-55062 was published for gitlab.com/uniget-org/cli (Go) Aug 17, 2026
0x5t4l1n Credited to 0x5t4l1n, Chris35t, and harriiinnii Chris35t Chris35t
harriiinnii harriiinnii
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout() Moderate
GHSA-hh9p-6wh2-4mfc was published for GitPython (pip) Aug 7, 2026
BarakSrour Credited to BarakSrour
ImageMagick: Policy Bypass in concatenate operation due to missing checks Moderate
CVE-2026-55628 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
Gitea: Local File Inclusion via file:// URI in Migration Restore Moderate
CVE-2026-58420 was published for gitea.dev (Go) Jul 21, 2026
isa0-gh Credited to isa0-gh and ibrahmsql ibrahmsql ibrahmsql
psd-tools vulnerable to arbitrary file write via smart-object filename Moderate
CVE-2026-49836 was published for psd-tools (pip) Jul 9, 2026
seankohjs Credited to seankohjs and yueyueL yueyueL yueyueL
Rattler vulnerable to package cache path traversal via conda package build string Moderate
CVE-2026-53956 was published for py_rattler (pip) Jul 9, 2026
oasdiff does not enforce --allow-external-refs=false on the git-revision load path (SSRF / local file read) Moderate
CVE-2026-53508 was published for github.com/oasdiff/oasdiff (Go) Jul 7, 2026
EGroupware Vulnerable to Local File Inclusion via file:// URI in Mail Compose Moderate
CVE-2026-45016 was published for egroupware/egroupware (Composer) Jul 7, 2026
smitocaru Credited to smitocaru
oras-go has file store write outside workingDir via symlink traversal Moderate
CVE-2026-50162 was published for oras.land/oras-go/v2 (Go) Jul 1, 2026
1seal Credited to 1seal
Keras: HDF5 virtual datasets can disclose local files Moderate
CVE-2026-12480 was published for keras (pip) Jul 1, 2026
EasyAdminBundle has path traversal and reflected XSS in Flag and Icon Twig components Moderate
GHSA-2wwr-9x6f-88gp was published for easycorp/easyadmin-bundle (Composer) Jul 1, 2026
pnpm: Reserved bin name deletes PNPM_HOME during global remove Moderate
CVE-2026-55699 was published for pnpm (npm) Jun 26, 2026
Entire CLI: Path traversal in checkpoint session metadata allows arbitrary file write during resume/rewind Moderate
GHSA-2h46-9x5w-4wf7 was published for github.com/entireio/cli (Go) Jun 19, 2026
nskath Credited to nskath
Armeria: External Control of File Name or Path in xDS SDS DataSource Moderate
CVE-2026-11752 was published for com.linecorp.armeria:armeria-xds (Maven) Jun 18, 2026
zzoru Credited to zzoru
BBOT: Arbitrary File Write in postman_download Module Moderate
CVE-2026-12568 was published for bbot (pip) Jun 18, 2026
nedlir Credited to nedlir
Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read Moderate
CVE-2026-48520 was published for langflow (pip) Jun 16, 2026
vbCrLf Credited to vbCrLf, keval718, and andifilhohub keval718 keval718
andifilhohub andifilhohub
launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows Moderate
CVE-2026-53632 was published for launch-editor (npm) Jun 15, 2026
RubenHoms Credited to RubenHoms, toxyl, and bluwy toxyl toxyl
bluwy bluwy
rattler has an entry-point path traversal in noarch:python install (arbitrary file write) Moderate
CVE-2026-47425 was published for py-rattler (pip) Jun 1, 2026
berkant-koc Credited to berkant-koc
offset Credited to offset
0xmrma Credited to 0xmrma
Streamlink has an arbitrary local file read via file:// URI in HLS and DASH Moderate
CVE-2026-44353 was published for streamlink (pip) May 11, 2026
4tkD0g Credited to 4tkD0g and bastimeyer bastimeyer bastimeyer
Gotenberg allows Chromium URL conversion routes to read arbitrary files under /tmp via file:// scheme Moderate
CVE-2026-42597 was published for github.com/gotenberg/gotenberg/v7 (Go) May 7, 2026
adrgs Credited to adrgs and aisafe-bot aisafe-bot aisafe-bot
Gotenberg has arbitrary PDF read via stampExpression and watermarkExpression in merge, split, and convert routes Moderate
CVE-2026-42593 was published for github.com/gotenberg/gotenberg/v8 (Go) May 7, 2026
adrgs Credited to adrgs and aisafe-bot aisafe-bot aisafe-bot
nbconvert has an Arbitrary File Write via Path Traversal in Cell Attachment Filenames Moderate
CVE-2026-39377 was published for nbconvert (pip) Apr 21, 2026
g0blinResearch Credited to g0blinResearch
ProTip! Advisories are also available from the GraphQL API