Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

149 advisories

Loading
consciousness-explorer / sublinear-time-solver MCP export_state has an arbitrary file write High
CVE-2026-55609 was published for consciousness-explorer (npm) Aug 25, 2026
BruceJqs Credited to BruceJqs
3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation High
CVE-2026-55477 was published for github.com/mhsanaei/3x-ui/v2 (Go) Aug 24, 2026
itsamirhn Credited to itsamirhn
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation High
CVE-2026-64679 was published for github.com/runatlantis/atlantis (Go) Aug 21, 2026
shblue21 Credited to shblue21
NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution High
GHSA-ghvf-qf6h-g8x5 was published for @nocobase/server (npm) Aug 20, 2026
lukehebe Credited to lukehebe
claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools High
GHSA-rr55-jp92-8wp2 was published for claude-faf-mcp (npm) Aug 19, 2026
faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools High
GHSA-j4r7-8ph4-43g3 was published for faf-mcp (npm) Aug 19, 2026
grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools High
GHSA-cc2g-gq8c-r332 was published for grok-faf-mcp (npm) Aug 19, 2026
uniget CLI has Path Traversal in Hook Files - Directory Escape Vulnerability Moderate
CVE-2026-55062 was published for gitlab.com/uniget-org/cli (Go) Aug 17, 2026
0x5t4l1n Credited to 0x5t4l1n and Chris35t Chris35t Chris35t
Nadav0077 Credited to Nadav0077 and igorpyan igorpyan igorpyan
tinyb0y Credited to tinyb0y
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout() Moderate
GHSA-hh9p-6wh2-4mfc was published for GitPython (pip) Aug 7, 2026
BarakSrour Credited to BarakSrour
Mirr2 Credited to Mirr2
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules) Critical
CVE-2026-67429 was published for flyto-core (pip) Jul 30, 2026
kaimandalic Credited to kaimandalic
OpenDJ unauthenticated SSRF, local file read and unbounded-read DoS in the DSMLv2 gateway Critical
GHSA-68r5-9hpg-7qw9 was published for org.openidentityplatform.opendj:opendj-dsml-servlet (Maven) Jul 24, 2026
manus-use Credited to manus-use
ImageMagick: Policy Bypass in concatenate operation due to missing checks Moderate
CVE-2026-55628 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
LiteLLM: Local file read via request-supplied OIDC file references Low
CVE-2026-59819 was published for litellm (pip) Jul 22, 2026
n8n: Edit Image Node Format Injection Allows Arbitrary File Write High
GHSA-xmc9-4f2h-jf9c was published for n8n (npm) Jul 22, 2026
simonkoeck Credited to simonkoeck
Gitea: Local File Inclusion via file:// URI in Migration Restore Moderate
CVE-2026-58420 was published for gitea.dev (Go) Jul 21, 2026
isa0-gh Credited to isa0-gh and ibrahmsql ibrahmsql ibrahmsql
Anyquery: Local File Read (LFR) via Unrestricted SQLite Virtual Table Modules in Server Mode High
CVE-2026-54629 was published for github.com/julien040/anyquery (Go) Jul 14, 2026
Metincloup Credited to Metincloup
yutu: Arbitrary File Write via MCP `caption-download` Tool High
CVE-2026-50158 was published for github.com/eat-pray-ai/yutu (Go) Jul 14, 2026
EQSTLab Credited to EQSTLab
Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode Critical
CVE-2026-50006 was published for github.com/julien040/anyquery (Go) Jul 14, 2026
Metincloup Credited to Metincloup
mcp-atlassian: Arbitrary server-side file read via attachment upload High
GHSA-wm45-qh3g-v83f was published for mcp-atlassian (pip) Jul 10, 2026
0xmagic0 Credited to 0xmagic0
ProTip! Advisories are also available from the GraphQL API