Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

485 advisories

Loading
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
sai-sh Credited to sai-sh
pierreolivierbonin Credited to pierreolivierbonin and jperezdealgaba jperezdealgaba jperezdealgaba
Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools High
CVE-2026-62675 was published for omnigent (pip) Sep 2, 2026
xttraa Credited to xttraa
Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData() High
CVE-2026-64850 was published for getgrav/grav (Composer) Sep 2, 2026
YuvalMil Credited to YuvalMil, MatiHub25, and LeonKaya MatiHub25 MatiHub25
LeonKaya LeonKaya
ibondarenko1 Credited to ibondarenko1 and antonisloukis antonisloukis antonisloukis
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data High
CVE-2026-54757 was published for compliance-trestle (pip) Aug 28, 2026
EclipsSec Credited to EclipsSec
silverstripe/userforms vulnerable to remote code execution via userforms email subject High
CVE-2026-54721 was published for silverstripe/userforms (Composer) Aug 27, 2026
qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()` High
CVE-2026-55585 was published for qwed (pip) Aug 25, 2026
EQSTLab Credited to EQSTLab
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code High
CVE-2026-55522 was published for PraisonAI (pip) Aug 25, 2026
rexpository Credited to rexpository
Hydra: hydra.utils.instantiate with untrusted config can lead to code execution High
CVE-2026-68508 was published for hydra-core (pip) Aug 21, 2026
guwu1017 Credited to guwu1017
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted High
CVE-2026-53951 was published for copier (pip) Aug 19, 2026
seankohjs Credited to seankohjs and sisp sisp sisp
Kiota: Code Generation Literal Injection High
CVE-2026-41134 was published for Microsoft.OpenApi.Kiota (NuGet) Apr 14, 2026
baywet Credited to baywet and gavinbarron gavinbarron gavinbarron
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName High
CVE-2026-59866 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
Gal3m Credited to Gal3m, mrostamipoor, baywet, and gavinbarron mrostamipoor mrostamipoor
baywet baywet gavinbarron gavinbarron
Microsoft Kiota: Code Generation Literal Injection in Kiota PHP Generator High
CVE-2026-59859 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
peombwa Credited to peombwa and thegr1ffyn thegr1ffyn thegr1ffyn
Microsoft Kiota: Code Generation Literal Injection in Kiota Python Generator High
CVE-2026-59862 was published for Microsoft.OpenAPI.Kiota (NuGet) Jul 24, 2026
baywet Credited to baywet
Microsoft Kiota: Code Generation Literal Injection in Kiota Ruby Generator High
CVE-2026-59861 was published for Microsoft.OpenAPI.Kiota (NuGet) Jul 24, 2026
baywet Credited to baywet
Microsoft Kiota: XML Doc-Comment Newline Breakout Code Injection High
CVE-2026-59860 was published for Microsoft.OpenApi.Kiota (NuGet) Jul 24, 2026
thegr1ffyn Credited to thegr1ffyn, gavinbarron, and peombwa gavinbarron gavinbarron
peombwa peombwa
Oh My Posh: Arbitrary command execution via template injection in the path segment High
CVE-2026-73505 was published for github.com/jandedobbeleer/oh-my-posh (Go) Jul 24, 2026
ihopenre-eng Credited to ihopenre-eng
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install` High
CVE-2026-55071 was published for stata-mcp (pip) Aug 12, 2026
EQSTLab Credited to EQSTLab and useworld useworld useworld
manus-use Credited to manus-use and BarakSrour BarakSrour BarakSrour
Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview High
CVE-2026-56382 was published for craftcms/cms (Composer) Jul 9, 2026
q1uf3ng Credited to q1uf3ng
Duplicate Advisory: Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview High
GHSA-pmm4-v8f6-4vpp was published for craftcms/cms (Composer) Jun 21, 2026 withdrawn
ProTip! Advisories are also available from the GraphQL API