Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

74 advisories

Loading
Duplicate Advisory: Craft CMS: Authenticated leak of secret environment variables High
GHSA-cc2g-26rw-g997 was published for craftcms/cms (Composer) Aug 11, 2026 withdrawn
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket High
CVE-2026-53657 was published for github.com/lima-vm/lima/v2 (Go) Aug 14, 2026
misop00p Credited to misop00p and ansjdnakjdnajkd ansjdnakjdnajkd ansjdnakjdnajkd
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted High
CVE-2026-67427 was published for flyto-core (pip) Jul 30, 2026
kaimandalic Credited to kaimandalic
proot-distro has a Container Isolation Bypass via Crafted Restore Archive High
CVE-2026-54727 was published for proot-distro (pip) Jul 29, 2026
x0root Credited to x0root
OpenShift GitOps Operator Namespace Isolation Break High
CVE-2024-13484 was published for github.com/redhat-developer/gitops-operator (Go) Jan 28, 2025
svghadi Credited to svghadi
File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path High
CVE-2026-54096 was published for github.com/filebrowser/filebrowser (Go) Jun 12, 2026
quart27219 Credited to quart27219, kimdu0, and hacdias kimdu0 kimdu0
hacdias hacdias
runc vulnerable to container breakout through process.cwd trickery and leaked fds High
CVE-2024-21626 was published for github.com/opencontainers/runc (Go) Jan 31, 2024
rmcnamara-snyk Credited to rmcnamara-snyk, cyphar, and lifubang cyphar cyphar
lifubang lifubang
rexpository Credited to rexpository
@andrea9293/mcp-documentation-server: Web UI API binds to all interfaces without authentication by default High
CVE-2026-54504 was published for @andrea9293/mcp-documentation-server (npm) Jul 15, 2026
mcfly-zzh Credited to mcfly-zzh
Symfony has Unauthenticated PHP Object Deserialization in MonologBridge server:log Listener High
CVE-2026-45077 was published for symfony/monolog-bridge (Composer) May 27, 2026
snoopysecurity Credited to snoopysecurity, nicolas-grekas, and a-tt-om nicolas-grekas nicolas-grekas
a-tt-om a-tt-om
Classic298 Credited to Classic298
tdjackey Credited to tdjackey
Electron: Context Isolation bypass via contextBridge VideoFrame transfer High
CVE-2026-34780 was published for electron (npm) Apr 3, 2026
OpenClaw: Gateway `agent` calls could override the workspace boundary High
GHSA-2rqg-gjgv-84jm was published for openclaw (npm) Mar 13, 2026
tdjackey Credited to tdjackey
AVideo: Unauthenticated PHP session store exposed to host network via published memcached port High
CVE-2026-29093 was published for wwbn/avideo (Composer) Mar 5, 2026
bugbunny-research Credited to bugbunny-research
OpenClaw: Hardlink alias checks could bypass workspace-only file boundaries in specific configurations High
GHSA-3jx4-q2m7-r496 was published for openclaw (npm) Mar 4, 2026
tdjackey Credited to tdjackey
Claude Code has Sandbox Escape via Persistent Configuration Injection in settings.json High
CVE-2026-25725 was published for @anthropic-ai/claude-code (npm) Feb 6, 2026
n8n's Unsafe Buffer Allocation Allows In-Process Memory Disclosure in Task Runner High
CVE-2025-61917 was published for n8n (npm) Feb 4, 2026
OpenClaw/Clawdbot has 1-Click RCE via Authentication Token Exfiltration From gatewayUrl High
CVE-2026-25253 was published for clawdbot (npm) Feb 2, 2026
DepthFirstDisclosures Credited to DepthFirstDisclosures, 0xacb, and mavlevin 0xacb 0xacb
mavlevin mavlevin
DIRAC: Unauthorized users can read proxy contents during generation High
CVE-2024-29905 was published for DIRAC (pip) Apr 9, 2024
Agno session state overwrites between different sessions/users High
CVE-2025-64168 was published for agno (pip) Oct 31, 2025
JasonLovesDoggo Credited to JasonLovesDoggo and dirkbrnd dirkbrnd dirkbrnd
Apache Helix Front (UI) component contained a hard-coded secret High
CVE-2024-22281 was published for org.apache.helix:helix (Maven) Aug 21, 2024
ProTip! Advisories are also available from the GraphQL API