GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,070 advisories
Filter by severity
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
CVE-2026-75911
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
CVE-2026-75858
was published
for
codewhale
(npm)
Sep 4, 2026
Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout)
Critical
CVE-2026-62681
was published
for
orval
(npm)
Sep 3, 2026
Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification)
Critical
CVE-2026-62682
was published
for
orval
(npm)
Sep 3, 2026
Orval: Import-time RCE via schema default -> zod module-level template literal
Critical
CVE-2026-72717
was published
for
orval
(npm)
Sep 3, 2026
Orval: Import-time RCE via array-items default -> zod module-level template literal
Critical
CVE-2026-71869
was published
for
orval
(npm)
Sep 3, 2026
Orval: Import-time RCE via header-parameter default -> zod module-level template literal
Critical
CVE-2026-71871
was published
for
orval
(npm)
Sep 3, 2026
Orval: Import-time RCE via enum-typed default -> zod module-level template literal
Critical
CVE-2026-71868
was published
for
orval
(npm)
Sep 3, 2026
Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli
Critical
CVE-2026-71865
was published
for
orval
(npm)
Sep 3, 2026
Orval: Import-time RCE via header parameter name -> computed-property-key injection in the zod client
Critical
CVE-2026-71864
was published
for
orval
(npm)
Sep 3, 2026
vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution
High
CVE-2026-41523
was published
for
vllm
(pip)
Jun 16, 2026
Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE
Critical
CVE-2026-62674
was published
for
omnigent
(pip)
Sep 2, 2026
Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools
High
CVE-2026-62675
was published
for
omnigent
(pip)
Sep 2, 2026
mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server
Critical
CVE-2026-53710
was published
for
mcp-contextforge-gateway
(pip)
Aug 24, 2026
Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()
High
CVE-2026-64850
was published
for
getgrav/grav
(Composer)
Sep 2, 2026
pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on install
High
CVE-2026-82393
was published
for
pnpm
(npm)
Sep 2, 2026
Apache Dolphinscheduler Code Injection vulnerability
Critical
CVE-2024-43202
was published
for
org.apache.dolphinscheduler:dolphinscheduler-task-api
(Maven)
Aug 20, 2024
lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out
High
CVE-2026-46517
was published
for
lmdeploy
(pip)
May 21, 2026
Pimcore Vulnerable to Remote Code Execution via DataObject Class-Definition Field Name
Critical
CVE-2026-55634
was published
for
pimcore/pimcore
(Composer)
Aug 28, 2026
Yamcs vulnerable to authenticated remote code execution via unescaped StreamSQL `LIKE` pattern compiled by Janino (`LikeExpression`)
Critical
CVE-2026-55565
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance)
Critical
CVE-2026-55559
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Yamcs vulnerable to authenticated RCE via StreamSQL aggregate-compiler column-name injection in Yamcs `executeSql`
Critical
CVE-2026-55511
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
High
CVE-2026-54757
was published
for
compliance-trestle
(pip)
Aug 28, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
High
CVE-2026-54721
was published
for
silverstripe/userforms
(Composer)
Aug 27, 2026
Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE)
Critical
CVE-2026-59989
was published
for
phalcon/cphalcon
(Composer)
Aug 21, 2026
ProTip!
Advisories are also available from the
GraphQL API