Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

184 advisories

Loading
atomic-agents-stack: HTTP MCP catalog accepts cleartext http and spawns catalog-supplied commands (MITM to RCE) High
GHSA-xhcr-cqfr-m3hv was published for atomic-agents-stack (pip) Aug 17, 2026
Duplicate Advisory: NLTK: Missing Post-Download Integrity Verification Allows Malicious Package Injection Moderate
GHSA-pv39-qrfq-g8gc was published for nltk (pip) Aug 3, 2026 withdrawn
navaneethibm Credited to navaneethibm
pnpm: Repository-controlled configDependencies can select a pacquet native install engine High
CVE-2026-55697 was published for pnpm (npm) Jun 26, 2026
massif-01 Credited to massif-01, G-Rath, and gabe-gfm G-Rath G-Rath
gabe-gfm gabe-gfm
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
stigmem-node's unsigned plugin override could be enabled without a second explicit acknowledgment High
GHSA-w7pm-9g55-mxfm was published for stigmem-node (pip) May 29, 2026
A firmware update mechanism in the affected charging controller fails to validate the... Critical Unreviewed
CVE-2026-9037 was published May 28, 2026
amwhoi Credited to amwhoi
apko doesn't verify downloaded apk packages against APKINDEX checksum (package substitution possible) High
CVE-2026-42575 was published for chainguard.dev/apko (Go) May 4, 2026
1seal Credited to 1seal and antitree antitree antitree
ProTip! Advisories are also available from the GraphQL API