Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

50 advisories

Loading
tinyb0y Credited to tinyb0y
GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout() Moderate
GHSA-hh9p-6wh2-4mfc was published for GitPython (pip) Aug 7, 2026
BarakSrour Credited to BarakSrour
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules) Critical
CVE-2026-67429 was published for flyto-core (pip) Jul 30, 2026
kaimandalic Credited to kaimandalic
LiteLLM: Local file read via request-supplied OIDC file references Low
CVE-2026-59819 was published for litellm (pip) Jul 22, 2026
mcp-atlassian: Arbitrary server-side file read via attachment upload High
GHSA-wm45-qh3g-v83f was published for mcp-atlassian (pip) Jul 10, 2026
0xmagic0 Credited to 0xmagic0
psd-tools vulnerable to arbitrary file write via smart-object filename Moderate
CVE-2026-49836 was published for psd-tools (pip) Jul 9, 2026
seankohjs Credited to seankohjs and yueyueL yueyueL yueyueL
Rattler vulnerable to package cache path traversal via conda package build string Moderate
CVE-2026-53956 was published for py_rattler (pip) Jul 9, 2026
Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths High
GHSA-52vm-mxx8-f227 was published for phantom-audio (pip) Jul 9, 2026
leesaenz Credited to leesaenz
Keras: HDF5 virtual datasets can disclose local files Moderate
CVE-2026-12480 was published for keras (pip) Jul 1, 2026
OctoPrint has possible file exfiltration via query parameters on upload endpoints High
CVE-2026-54134 was published for OctoPrint (pip) Jun 23, 2026
seankohjs Credited to seankohjs, jacopotediosi, and cookesan jacopotediosi jacopotediosi
cookesan cookesan
BBOT: Arbitrary File Write in postman_download Module Moderate
CVE-2026-12568 was published for bbot (pip) Jun 18, 2026
nedlir Credited to nedlir
rexpository Credited to rexpository
Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read Moderate
CVE-2026-48520 was published for langflow (pip) Jun 16, 2026
vbCrLf Credited to vbCrLf, keval718, and andifilhohub keval718 keval718
andifilhohub andifilhohub
Docling Core: Insufficient validation of image reference URIs High
CVE-2026-44019 was published for docling-core (pip) Jun 3, 2026
brodmart Credited to brodmart
Docling: Unsafe URI and Path Handling in HTML Backend High
CVE-2026-47214 was published for docling (pip) Jun 3, 2026
AnistoMejin Credited to AnistoMejin and brodmart brodmart brodmart
rattler has an entry-point path traversal in noarch:python install (arbitrary file write) Moderate
CVE-2026-47425 was published for py-rattler (pip) Jun 1, 2026
berkant-koc Credited to berkant-koc
compliance-trestle - jinja has an Arbitrary File Write via Path Traversal High
CVE-2026-46345 was published for compliance-trestle (pip) May 28, 2026
l3tchupkt Credited to l3tchupkt
compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal High
CVE-2026-45725 was published for compliance-trestle (pip) May 27, 2026
AnistoMejin Credited to AnistoMejin and yantongggg yantongggg yantongggg
0xmrma Credited to 0xmrma
Streamlink has an arbitrary local file read via file:// URI in HLS and DASH Moderate
CVE-2026-44353 was published for streamlink (pip) May 11, 2026
4tkD0g Credited to 4tkD0g and bastimeyer bastimeyer bastimeyer
0xmrma Credited to 0xmrma
ProTip! Advisories are also available from the GraphQL API