GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,575
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,523
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
33 advisories
Filter by severity
consciousness-explorer / sublinear-time-solver MCP export_state has an arbitrary file write
High
CVE-2026-55609
was published
for
consciousness-explorer
(npm)
Aug 25, 2026
NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution
High
GHSA-ghvf-qf6h-g8x5
was published
for
@nocobase/server
(npm)
Aug 20, 2026
claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
High
GHSA-rr55-jp92-8wp2
was published
for
claude-faf-mcp
(npm)
Aug 19, 2026
faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
High
GHSA-j4r7-8ph4-43g3
was published
for
faf-mcp
(npm)
Aug 19, 2026
grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools
High
GHSA-cc2g-gq8c-r332
was published
for
grok-faf-mcp
(npm)
Aug 19, 2026
Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys
High
GHSA-88pr-878c-24wf
was published
for
flowise
(npm)
Aug 4, 2026
n8n: Edit Image Node Format Injection Allows Arbitrary File Write
High
GHSA-xmc9-4f2h-jf9c
was published
for
n8n
(npm)
Jul 22, 2026
pnpm: `patch-remove` could delete project-selected files outside the patches directory
High
GHSA-72r4-9c5j-mj57
was published
for
pnpm
(npm)
Jun 27, 2026
pnpm: Hoisted install imports lockfile alias outside node_modules
High
GHSA-fr4h-3cph-29xv
was published
for
pnpm
(npm)
Jun 27, 2026
pnpm: `stage download` writes outside its destination directory via manifest name/version traversal
High
CVE-2026-55700
was published
for
pnpm
(npm)
Jun 26, 2026
pnpm: Reserved bin name deletes PNPM_HOME during global remove
Moderate
CVE-2026-55699
was published
for
pnpm
(npm)
Jun 26, 2026
Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning
High
GHSA-2fmp-9rvw-hc96
was published
for
network-ai
(npm)
Jun 19, 2026
Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message
High
GHSA-p6gq-j5cr-w38f
was published
for
nodemailer
(npm)
Jun 18, 2026
launch-editor: NTLMv2 hash disclosure via UNC path handling on Windows
Moderate
CVE-2026-53632
was published
for
launch-editor
(npm)
Jun 15, 2026
@evomap/evolver: Path Traversal in `evolver fetch` default-branch `safeId` allows Hub-controlled overwrite of project files (RCE)
High
GHSA-cfcj-hqpf-hccf
was published
for
@evomap/evolver
(npm)
May 5, 2026
i18next-fs-backend: Path traversal via unsanitised lng/ns allows arbitrary file read/overwrite
High
CVE-2026-41693
was published
for
i18next-fs-backend
(npm)
Apr 22, 2026
Duplicate Advisory: OpenClaw: Webchat media embedding enforces local-root containment for tool-result files
Moderate
GHSA-qc5j-2mqx-x83q
was published
for
openclaw
(npm)
Apr 20, 2026
•
withdrawn
OpenClaw: Webchat media embedding enforces local-root containment for tool-result files
Moderate
CVE-2026-41389
was published
for
openclaw
(npm)
Apr 17, 2026
Paperclip: Arbitrary File Read via Agent-Controlled adapterConfig.instructionsFilePath
Moderate
GHSA-3pw3-v88x-xj24
was published
for
@paperclipai/shared
(npm)
Apr 16, 2026
OpenClaw: Shared reply MEDIA - paths are treated as trusted and can trigger cross-channel local file exfiltration
Moderate
CVE-2026-42424
was published
for
openclaw
(npm)
Apr 9, 2026
SillyTavern has a path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directory
High
CVE-2026-34522
was published
for
sillytavern
(npm)
Apr 1, 2026
@tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files
High
CVE-2026-33949
was published
for
@tinacms/graphql
(npm)
Mar 30, 2026
@mobilenext/mobile-mcp alllows arbitrary file write via Path Traversal in mobile screen capture tools
High
CVE-2026-33989
was published
for
@mobilenext/mobile-mcp
(npm)
Mar 27, 2026
OpenClaw hardened the skill download target directory validation
Moderate
CVE-2026-27008
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw has an arbitrary transcript path file write via gateway sessionFile
High
CVE-2026-28459
was published
for
openclaw
(npm)
Feb 17, 2026
ProTip!
Advisories are also available from the
GraphQL API