Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

248 advisories

Loading
Omnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCE Critical
CVE-2026-62674 was published for omnigent (pip) Sep 2, 2026
xttraa Credited to xttraa
Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools High
CVE-2026-62675 was published for omnigent (pip) Sep 2, 2026
xttraa Credited to xttraa
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data High
CVE-2026-54757 was published for compliance-trestle (pip) Aug 28, 2026
EclipsSec Credited to EclipsSec
qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()` High
CVE-2026-55585 was published for qwed (pip) Aug 25, 2026
EQSTLab Credited to EQSTLab
qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input Critical
CVE-2026-55546 was published for qwed-mcp (pip) Aug 25, 2026
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code High
CVE-2026-55522 was published for PraisonAI (pip) Aug 25, 2026
rexpository Credited to rexpository
mcp-contextforge-gateway has RestrictedPython sandbox bypass via getattr builtin in python_sandbox_server Critical
CVE-2026-53710 was published for mcp-contextforge-gateway (pip) Aug 24, 2026
Hydra: hydra.utils.instantiate with untrusted config can lead to code execution High
CVE-2026-68508 was published for hydra-core (pip) Aug 21, 2026
guwu1017 Credited to guwu1017
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted High
CVE-2026-53951 was published for copier (pip) Aug 19, 2026
seankohjs Credited to seankohjs and sisp sisp sisp
sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes Moderate
CVE-2026-59894 was published for sqlparse (pip) Aug 17, 2026
7thParkk Credited to 7thParkk
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install` High
CVE-2026-55071 was published for stata-mcp (pip) Aug 12, 2026
EQSTLab Credited to EQSTLab and useworld useworld useworld
manus-use Credited to manus-use and BarakSrour BarakSrour BarakSrour
thegr1ffyn Credited to thegr1ffyn
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field High
CVE-2026-54653 was published for datamodel-code-generator (pip) Jul 28, 2026
thegr1ffyn Credited to thegr1ffyn
thegr1ffyn Credited to thegr1ffyn
thegr1ffyn Credited to thegr1ffyn, mhamzakhattak, and Muzammilxi mhamzakhattak mhamzakhattak
Muzammilxi Muzammilxi
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description High
CVE-2026-54621 was published for datamodel-code-generator (pip) Jul 28, 2026
thegr1ffyn Credited to thegr1ffyn
thegr1ffyn Credited to thegr1ffyn
waiveyk Credited to waiveyk and Classic298 Classic298 Classic298
SSJCorpSec Credited to SSJCorpSec, thesecguy45, sfwani, and bveeramani thesecguy45 thesecguy45
sfwani sfwani bveeramani bveeramani
LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks Low
CVE-2026-59821 was published for litellm (pip) Jul 22, 2026
yaaras Credited to yaaras
YLChen-007 Credited to YLChen-007
hackkim Credited to hackkim and matte1782 matte1782 matte1782
Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args Critical
GHSA-r253-r9jw-qg44 was published for crawl4ai (pip) Jun 18, 2026
hoanggxyuuki Credited to hoanggxyuuki
ProTip! Advisories are also available from the GraphQL API