Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

46 advisories

Loading
hoanggxyuuki Credited to hoanggxyuuki and NguyenHuyTrung NguyenHuyTrung NguyenHuyTrung
Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any client High
CVE-2026-70482 was published for open-webui (pip) Aug 4, 2026
Classic298 Credited to Classic298
pytonapi has a Webhook Custom Path Authentication Bypass High
CVE-2026-54635 was published for pytonapi (pip) Jul 28, 2026
EQSTLab Credited to EQSTLab
smoke-wolf Credited to smoke-wolf, rexpository, and Classic298 rexpository rexpository
Classic298 Classic298
LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback High
CVE-2026-59822 was published for litellm (pip) Jul 22, 2026
yaaras Credited to yaaras
meta-ads-mcp: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token High
CVE-2026-54547 was published for meta-ads-mcp (pip) Jul 17, 2026
EQSTLab Credited to EQSTLab
tonghuaroot Credited to tonghuaroot
vndasunkid Credited to vndasunkid
PraisonAI LinearBot processes unsigned webhooks when LINEAR_WEBHOOK_SECRET is missing High
CVE-2026-56837 was published for praisonai (pip) Jun 18, 2026
rexpository Credited to rexpository
PraisonAI recipe serve Typer command bypasses the non-localhost authentication guard High
CVE-2026-56836 was published for praisonai (pip) Jun 18, 2026
rexpository Credited to rexpository
aradona91 Credited to aradona91
eduMFA Passkeys: missing expiration flag may allow replay attacks and reuse of old challenges High
GHSA-j5rm-v3vh-vx94 was published for edumfa (pip) May 18, 2026
LightRAG: Hardcoded JWT Signing Secret Allows Authentication Bypass High
CVE-2026-30762 was published for lightrag-hku (pip) Apr 4, 2026
Venkatatadu Credited to Venkatatadu
Auth0OAuthenticator has an Authentication Bypass via Unverified Email Claims High
CVE-2026-33175 was published for oauthenticator (pip) Apr 3, 2026
Jaynornj Credited to Jaynornj and Pr00fOf3xpl0it Pr00fOf3xpl0it Pr00fOf3xpl0it
Salt Authentication Protocol Version Downgrade Allows Minion Impersonation High
CVE-2025-62349 was published for salt (pip) Jan 30, 2026
FastMCP Auth Integration Allows for Confused Deputy Account Takeover High
GHSA-c2jp-c369-7pvx was published for fastmcp (pip) Oct 29, 2025
localden Credited to localden
Salt has minion event bus authorization bypass vulnerability High
CVE-2025-22236 was published for salt (pip) Jun 13, 2025
Open WebUI lacks authentication for the `api/v1/utils/pdf` endpoint High
CVE-2024-8053 was published for open-webui (pip) Mar 20, 2025
NiceGUI On Air authentication issue High
CVE-2025-21618 was published for nicegui (pip) Jan 6, 2025
streamcfd Credited to streamcfd and rodja rodja rodja
djoser Authentication Bypass High
CVE-2024-21543 was published for djoser (pip) Dec 13, 2024
asyncua Improper Authentication vulnerability High
CVE-2023-26150 was published for asyncua (pip) Oct 3, 2023
rdiffweb vulnerable to Authentication Bypass by Primary Weakness High
CVE-2022-4722 was published for rdiffweb (pip) Dec 27, 2022
CKAN contains Improper Authentication leading to account takeover High
CVE-2022-43685 was published for ckan (pip) Nov 22, 2022
Indy's NODE_UPGRADE transaction vulnerable to remote code execution High
CVE-2022-31020 was published for indy-node (pip) Sep 2, 2022
shakreiner Credited to shakreiner
ProTip! Advisories are also available from the GraphQL API