Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

102 advisories

Loading
Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generator Critical
CVE-2026-71867 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli Critical
CVE-2026-71865 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Gal3m Credited to Gal3m, mrostamipoor, aqeelat, and mohammad228 mrostamipoor mrostamipoor
aqeelat aqeelat mohammad228 mohammad228
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Faker: helpers.fake exploitable into arbritary code execution High
CVE-2026-73231 was published for @faker-js/faker (npm) Sep 2, 2026
ST-DDT Credited to ST-DDT and Shinigami92 Shinigami92 Shinigami92
senaite.core Vulnerable to Eval Injection and Missing Authorization Critical
CVE-2026-54569 was published for senaite.core (pip) Aug 26, 2026
snomi Credited to snomi and Volcore Volcore Volcore
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing Critical
CVE-2026-61539 was published for xinference (pip) Aug 21, 2026
XlabAITeam Credited to XlabAITeam, keenanwgn, and A7um keenanwgn keenanwgn
A7um A7um
NLTK vulnerable to Eval Injection via collocations CLI arguments High
CVE-2025-71408 was published for nltk (pip) Jul 25, 2026
PercevalFox Credited to PercevalFox
amwhoi Credited to amwhoi
Flowise Sandbox Escape to RCE Critical
CVE-2026-69253 was published for flowise (npm) Aug 4, 2026
alex-elttam Credited to alex-elttam
Rancher vulnerable to command injection through unsanitized YAML parameter Critical
CVE-2026-44939 was published for github.com/rancher/rancher (Go) Jul 1, 2026
Ibonok Credited to Ibonok
AWS Amplify Studio UI Component Properties Has an Input Validation Issue Critical
CVE-2025-4318 was published for @aws-amplify/codegen-ui-react (npm) Jul 30, 2026
thegr1ffyn Credited to thegr1ffyn, mhamzakhattak, and Muzammilxi mhamzakhattak mhamzakhattak
Muzammilxi Muzammilxi
WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability High
CVE-2026-45293 was published for wp-coding-standards/wpcs (Composer) Jul 28, 2026
FORIMOC Credited to FORIMOC, rodrigoprimo, and jrfnl rodrigoprimo rodrigoprimo
jrfnl jrfnl
Picklescan has a missing detection when calling built-in python idlelib.calltip.Calltip High
CVE-2025-71361 was published for picklescan (pip) Aug 26, 2025
FredericDT Credited to FredericDT
django-haystack: Remote Code Execution via `eval()` in Elasticsearch Result Deserialization High
GHSA-r3hx-x5rh-p9vv was published for django-haystack (pip) Jul 15, 2026
MantisBT: Remote Code Execution via eval() Class Hoisting in adm_config_set.php High
CVE-2026-49273 was published for mantisbt/mantisbt (Composer) Jul 15, 2026
McCaulay Credited to McCaulay and dregad dregad dregad
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval Critical
CVE-2026-61667 was published for DIRAC (pip) Jul 13, 2026
sfayer Credited to sfayer
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input Critical
CVE-2026-45579 was published for DIRAC (pip) Jul 13, 2026
sfayer Credited to sfayer
EGroupware has Authenticated RCE via Malicious eTemplate Upload High
CVE-2026-40187 was published for egroupware/egroupware (Composer) Jul 7, 2026
dapickle Credited to dapickle
xwiki-pro-macros has remote code execution from page title and content via excerpt-include macro Critical
CVE-2026-44179 was published for com.xwiki.pro:xwiki-pro-macros (Maven) Jun 22, 2026
michitux Credited to michitux
Duplicate Advisory: Picklescan (scan_pytorch) Bypass via dynamic eval MAGIC_NUMBER High
GHSA-cc5p-54x3-hcf8 was published for picklescan (pip) Jun 17, 2026 withdrawn
python-statemachine SCXML <data expr> Eval Injection Critical
CVE-2026-47103 was published for python-statemachine (pip) Jun 18, 2026
wsparks-vc Credited to wsparks-vc and SaiTeja-Erukude SaiTeja-Erukude SaiTeja-Erukude
Karate Mock Server RCE via embedded expression evaluation of request-derived data High
GHSA-2c85-rfcc-g74j was published for io.karatelabs:karate-core (Maven) Jun 18, 2026
baozongwi Credited to baozongwi
Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint Critical
CVE-2026-33017 was published for langflow (pip) Mar 17, 2026
Aviral2642 Credited to Aviral2642, andifilhohub, Jkavia, and srmish-jfrog andifilhohub andifilhohub
Jkavia Jkavia srmish-jfrog srmish-jfrog
ProTip! Advisories are also available from the GraphQL API