GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
485 advisories
Filter by severity
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
CVE-2026-75911
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
CVE-2026-75858
was published
for
codewhale
(npm)
Sep 4, 2026
vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution
High
CVE-2026-41523
was published
for
vllm
(pip)
Jun 16, 2026
Omnigent: Uploaded Agent Bundle Allows Authenticated Runner RCE via Python Callable Tools
High
CVE-2026-62675
was published
for
omnigent
(pip)
Sep 2, 2026
Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()
High
CVE-2026-64850
was published
for
getgrav/grav
(Composer)
Sep 2, 2026
pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on install
High
CVE-2026-82393
was published
for
pnpm
(npm)
Sep 2, 2026
lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out
High
CVE-2026-46517
was published
for
lmdeploy
(pip)
May 21, 2026
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
High
CVE-2026-54757
was published
for
compliance-trestle
(pip)
Aug 28, 2026
silverstripe/userforms vulnerable to remote code execution via userforms email subject
High
CVE-2026-54721
was published
for
silverstripe/userforms
(Composer)
Aug 27, 2026
mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
High
GHSA-vwf3-4xxj-qg6h
was published
for
mcp-contextforge-gateway
(pip)
Aug 25, 2026
qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`
High
CVE-2026-55585
was published
for
qwed
(pip)
Aug 25, 2026
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
High
CVE-2026-55522
was published
for
PraisonAI
(pip)
Aug 25, 2026
Hydra: hydra.utils.instantiate with untrusted config can lead to code execution
High
CVE-2026-68508
was published
for
hydra-core
(pip)
Aug 21, 2026
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
High
CVE-2026-53951
was published
for
copier
(pip)
Aug 19, 2026
Kiota: Code Generation Literal Injection
High
CVE-2026-41134
was published
for
Microsoft.OpenApi.Kiota
(NuGet)
Apr 14, 2026
Microsoft Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
High
CVE-2026-59866
was published
for
Microsoft.OpenApi.Kiota
(NuGet)
Jul 24, 2026
Microsoft Kiota: Code Generation Literal Injection in Kiota PHP Generator
High
CVE-2026-59859
was published
for
Microsoft.OpenApi.Kiota
(NuGet)
Jul 24, 2026
Microsoft Kiota: Code Generation Literal Injection in Kiota Python Generator
High
CVE-2026-59862
was published
for
Microsoft.OpenAPI.Kiota
(NuGet)
Jul 24, 2026
Microsoft Kiota: Code Generation Literal Injection in Kiota Ruby Generator
High
CVE-2026-59861
was published
for
Microsoft.OpenAPI.Kiota
(NuGet)
Jul 24, 2026
Microsoft Kiota: XML Doc-Comment Newline Breakout Code Injection
High
CVE-2026-59860
was published
for
Microsoft.OpenApi.Kiota
(NuGet)
Jul 24, 2026
Oh My Posh: Arbitrary command execution via template injection in the path segment
High
CVE-2026-73505
was published
for
github.com/jandedobbeleer/oh-my-posh
(Go)
Jul 24, 2026
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
High
CVE-2026-55071
was published
for
stata-mcp
(pip)
Aug 12, 2026
GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks
High
GHSA-9rj7-rf2p-w77r
was published
for
GitPython
(pip)
Aug 7, 2026
Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview
High
CVE-2026-56382
was published
for
craftcms/cms
(Composer)
Jul 9, 2026
Duplicate Advisory: Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview
High
GHSA-pmm4-v8f6-4vpp
was published
for
craftcms/cms
(Composer)
Jun 21, 2026
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API