Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,070 advisories

Loading
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
sai-sh Credited to sai-sh
Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout) Critical
CVE-2026-62681 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m and mrostamipoor mrostamipoor mrostamipoor
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via schema default -> zod module-level template literal Critical
CVE-2026-72717 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via array-items default -> zod module-level template literal Critical
CVE-2026-71869 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via header-parameter default -> zod module-level template literal Critical
CVE-2026-71871 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via enum-typed default -> zod module-level template literal Critical
CVE-2026-71868 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli Critical
CVE-2026-71865 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Gal3m Credited to Gal3m, mrostamipoor, aqeelat, and mohammad228 mrostamipoor mrostamipoor
aqeelat aqeelat mohammad228 mohammad228
pierreolivierbonin Credited to pierreolivierbonin and jperezdealgaba jperezdealgaba jperezdealgaba
Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE Critical
CVE-2026-62674 was published for omnigent (pip) Sep 2, 2026
xttraa Credited to xttraa
Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools High
CVE-2026-62675 was published for omnigent (pip) Sep 2, 2026
xttraa Credited to xttraa
mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server Critical
CVE-2026-53710 was published for mcp-contextforge-gateway (pip) Aug 24, 2026
Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData() High
CVE-2026-64850 was published for getgrav/grav (Composer) Sep 2, 2026
YuvalMil Credited to YuvalMil, MatiHub25, and LeonKaya MatiHub25 MatiHub25
LeonKaya LeonKaya
Apache Dolphinscheduler Code Injection vulnerability Critical
CVE-2024-43202 was published for org.apache.dolphinscheduler:dolphinscheduler-task-api (Maven) Aug 20, 2024
sealbenb Credited to sealbenb
ibondarenko1 Credited to ibondarenko1 and antonisloukis antonisloukis antonisloukis
Pimcore Vulnerable to Remote Code Execution via DataObject Class-Definition Field Name Critical
CVE-2026-55634 was published for pimcore/pimcore (Composer) Aug 28, 2026
Yanchon918s Credited to Yanchon918s
Marnick39 Credited to Marnick39
Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance) Critical
CVE-2026-55559 was published for org.yamcs:yamcs-core (Maven) Aug 28, 2026
MarkLee131 Credited to MarkLee131 and manus-use manus-use manus-use
Yamcs vulnerable to authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql` Critical
CVE-2026-55511 was published for org.yamcs:yamcs-core (Maven) Aug 28, 2026
Yanchon918s Credited to Yanchon918s and manus-use manus-use manus-use
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data High
CVE-2026-54757 was published for compliance-trestle (pip) Aug 28, 2026
EclipsSec Credited to EclipsSec
silverstripe/userforms vulnerable to remote code execution via userforms email subject High
CVE-2026-54721 was published for silverstripe/userforms (Composer) Aug 27, 2026
Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE) Critical
CVE-2026-59989 was published for phalcon/cphalcon (Composer) Aug 21, 2026
nikkoenggaliano Credited to nikkoenggaliano
ProTip! Advisories are also available from the GraphQL API