GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,863
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,585
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
94 advisories
Filter by severity
MCP Atlassian: Arbitrary server-local file upload to Jira/Confluence attachments via unrestricted file_path parameters
High
CVE-2026-77247
was published
for
mcp-atlassian
(pip)
Sep 22, 2026
@roomi-fields/notebooklm-mcp has a path traversal in vault.batch tool that allows arbitrary file write outside intended vault directory
High
CVE-2026-61647
was published
for
@roomi-fields/notebooklm-mcp
(npm)
Sep 22, 2026
mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url
High
GHSA-wfgq-w7cq-qj7j
was published
for
mistralrs-server-core
(Rust)
Sep 10, 2026
OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree
High
GHSA-2q42-4q24-7rgv
was published
for
@typespec/compiler
(npm)
Sep 8, 2026
Laravel Excel writes exports outside the configured filesystem disk when given a caller-controlled path
High
CVE-2026-84374
was published
for
maatwebsite/excel
(Composer)
Sep 8, 2026
GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination
High
CVE-2026-78677
was published
for
GitPython
(pip)
Sep 8, 2026
GitPython: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)
High
CVE-2026-78675
was published
for
GitPython
(pip)
Sep 8, 2026
NLTK: Stable FrameNet and NKJP readers parse outside-root XML
High
CVE-2026-62385
was published
for
nltk
(pip)
Sep 8, 2026
CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval
High
CVE-2026-75913
was published
for
codewhale
(npm)
Sep 4, 2026
pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on install
High
CVE-2026-82393
was published
for
pnpm
(npm)
Sep 2, 2026
NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed roots
High
CVE-2026-81726
was published
for
nltk
(pip)
Sep 2, 2026
pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project
High
GHSA-2rx9-3g3h-c2jv
was published
for
pnpm
(npm)
Sep 1, 2026
Duplicate Advisory: Nodemailer: Message-level raw option bypasses disableFileAccess/disableUrlAccess, enabling arbitrary file read and full-response SSRF in the delivered message
High
GHSA-h3hj-cmcx-xc66
was published
for
nodemailer
(npm)
Aug 31, 2026
•
withdrawn
Duplicate Advisory: Model-artifact APIs bypass pathsec and touch files outside allowed roots
High
GHSA-hqj7-phwp-c3fp
was published
for
nltk
(pip)
Aug 27, 2026
•
withdrawn
consciousness-explorer / sublinear-time-solver MCP export_state has an arbitrary file write
High
CVE-2026-55609
was published
for
consciousness-explorer
(npm)
Aug 25, 2026
Duplicate Advisory: NLTK: Corpus Reader Sandbox Bypass
High
GHSA-rcw8-9qrw-27m2
was published
for
nltk
(pip)
Aug 25, 2026
•
withdrawn
praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location
High
CVE-2026-55527
was published
for
praisonaiagents
(pip)
Aug 25, 2026
Duplicate Advisory: GitPython: TagReference.create positional reference bypasses kwargs-only --file guard, enabling arbitrary file read (incomplete fix of 3af0c251)
High
GHSA-6rj2-96f5-chj9
was published
for
GitPython
(pip)
Aug 25, 2026
•
withdrawn
Duplicate Advisory: Arbitrary local file content disclosure via [include] directive in untrusted .gitmodules (SubmoduleConfigParser never disables merge_includes)
High
GHSA-crmc-f4m7-33fj
was published
for
gitpython
(pip)
Aug 25, 2026
•
withdrawn
3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation
High
CVE-2026-55477
was published
for
github.com/mhsanaei/3x-ui/v2
(Go)
Aug 24, 2026
Duplicate Advisory: Stable FrameNet and NKJP readers parse outside-root XML in 3.9.4
High
GHSA-qp76-pq9f-gr9m
was published
for
nltk
(pip)
Aug 22, 2026
•
withdrawn
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation
High
CVE-2026-64679
was published
for
github.com/runatlantis/atlantis
(Go)
Aug 21, 2026
NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution
High
GHSA-ghvf-qf6h-g8x5
was published
for
@nocobase/server
(npm)
Aug 20, 2026
claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
High
GHSA-rr55-jp92-8wp2
was published
for
claude-faf-mcp
(npm)
Aug 19, 2026
ProTip!
Advisories are also available from the
GraphQL API