Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,654 advisories

Loading
ihopenre-eng Credited to ihopenre-eng
Duplicate Advisory: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf Critical
GHSA-hg4j-w33m-p7g4 was published for github.com/siyuan-note/siyuan/kernel (Go) Aug 12, 2026 withdrawn
Duplicate Advisory: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns Critical
GHSA-mg8q-52j3-w5f8 was published for github.com/siyuan-note/siyuan/kernel (Go) Aug 12, 2026 withdrawn
SurrealDB server-takeover via SurrealQL injection on backup import Critical
CVE-2025-71392 was published for surrealdb (Rust) Apr 11, 2025
cure53 Credited to cure53
Duplicate Advisory: SurrealDB server-takeover via SurrealQL injection on backup import Critical
GHSA-h5q3-3v5q-v5j8 was published for surrealdb (Rust) Jul 18, 2026 withdrawn
Apache Airflow allows code execution through unsafe serialized DAG deserialization Critical
CVE-2026-33264 was published for apache-airflow (pip) Jul 7, 2026
MCP Toolbox HTTP tool path parameters allow traversal to unintended endpoints Critical
CVE-2026-11720 was published for github.com/googleapis/mcp-toolbox (Go) Jun 29, 2026
CodeWhale: SSRF‌ bypass - TOCTOU on DNS failure for DNS pinning Critical
CVE-2026-75856 was published for codewhale (npm) Sep 4, 2026
JafarAkhondali Credited to JafarAkhondali
Duplicate Advisory: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents Critical
GHSA-v598-7627-g9fx was published for github.com/siyuan-note/siyuan/kernel (Go) Aug 12, 2026 withdrawn
Shirshakhtml Credited to Shirshakhtml
Duplicate Advisory: Unauthenticated arbitrary SQL execution via searchEmbedBlock (publish mode) : reader-reachable raw statement on read-write handle, cross-notebook read/write Critical
GHSA-p2x7-4c4p-8wh6 was published for github.com/siyuan-note/siyuan/kernel (Go) Aug 3, 2026 withdrawn
Cognee allows non-superusers to overwrite global LLM configuration Critical
CVE-2026-58473 was published for cognee (pip) Jul 7, 2026
randomnimbus Credited to randomnimbus
Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout) Critical
CVE-2026-62681 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m and mrostamipoor mrostamipoor mrostamipoor
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via schema default -> zod module-level template literal Critical
CVE-2026-72717 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via array-items default -> zod module-level template literal Critical
CVE-2026-71869 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
ProTip! Advisories are also available from the GraphQL API