GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,575
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,523
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
50 advisories
Filter by severity
praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location
High
CVE-2026-55527
was published
for
praisonaiagents
(pip)
Aug 25, 2026
GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython
High
GHSA-hmq2-w58f-27jc
was published
for
GitPython
(pip)
Aug 7, 2026
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout()
Moderate
GHSA-hh9p-6wh2-4mfc
was published
for
GitPython
(pip)
Aug 7, 2026
GitPython: Incomplete unsafe_git_archive_options denylist omits --add-file / --add-virtual-file, enabling arbitrary file read via Repo.archive()
Moderate
GHSA-539m-9xh6-q6rr
was published
for
GitPython
(pip)
Aug 3, 2026
GitPython: Unguarded git option forwarding in IndexFile.checkout() and TagReference.create() enables arbitrary file overwrite and arbitrary file read
High
GHSA-3f7w-8rr8-f37f
was published
for
GitPython
(pip)
Aug 3, 2026
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)
Critical
CVE-2026-67429
was published
for
flyto-core
(pip)
Jul 30, 2026
LiteLLM: Local file read via request-supplied OIDC file references
Low
CVE-2026-59819
was published
for
litellm
(pip)
Jul 22, 2026
mcp-atlassian: Arbitrary server-side file read via attachment upload
High
GHSA-wm45-qh3g-v83f
was published
for
mcp-atlassian
(pip)
Jul 10, 2026
psd-tools vulnerable to arbitrary file write via smart-object filename
Moderate
CVE-2026-49836
was published
for
psd-tools
(pip)
Jul 9, 2026
Rattler vulnerable to package cache path traversal via conda package build string
Moderate
CVE-2026-53956
was published
for
py_rattler
(pip)
Jul 9, 2026
Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths
High
GHSA-52vm-mxx8-f227
was published
for
phantom-audio
(pip)
Jul 9, 2026
Recce server has unauthenticated SQL execution that allows local file read/write through DuckDB
High
CVE-2026-49360
was published
for
recce
(pip)
Jul 2, 2026
Keras: HDF5 virtual datasets can disclose local files
Moderate
CVE-2026-12480
was published
for
keras
(pip)
Jul 1, 2026
OctoPrint has possible file exfiltration via query parameters on upload endpoints
High
CVE-2026-54134
was published
for
OctoPrint
(pip)
Jun 23, 2026
BBOT: Arbitrary File Write in postman_download Module
Moderate
CVE-2026-12568
was published
for
bbot
(pip)
Jun 18, 2026
PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion
High
CVE-2026-57113
was published
for
praisonai
(pip)
Jun 18, 2026
Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read
Moderate
CVE-2026-48520
was published
for
langflow
(pip)
Jun 16, 2026
Docling Core: Insufficient validation of image reference URIs
High
CVE-2026-44019
was published
for
docling-core
(pip)
Jun 3, 2026
Docling: Unsafe URI and Path Handling in HTML Backend
High
CVE-2026-47214
was published
for
docling
(pip)
Jun 3, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Moderate
CVE-2026-47425
was published
for
py-rattler
(pip)
Jun 1, 2026
compliance-trestle - jinja has an Arbitrary File Write via Path Traversal
High
CVE-2026-46345
was published
for
compliance-trestle
(pip)
May 28, 2026
compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal
High
CVE-2026-45725
was published
for
compliance-trestle
(pip)
May 27, 2026
Microsoft APM: Windows absolute-path tar member overwrite during legacy-bundle probing in `apm install`
Moderate
CVE-2026-46383
was published
for
apm-cli
(pip)
May 15, 2026
Streamlink has an arbitrary local file read via file:// URI in HLS and DASH
Moderate
CVE-2026-44353
was published
for
streamlink
(pip)
May 11, 2026
Microsoft APM CLI's plugin.json component paths escape plugin root and copy arbitrary host files during install
High
CVE-2026-44641
was published
for
apm-cli
(pip)
May 7, 2026
ProTip!
Advisories are also available from the
GraphQL API