Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

94 advisories

Loading
junbyjun1238 Credited to junbyjun1238
mcfly-zzh Credited to mcfly-zzh
mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url High
GHSA-wfgq-w7cq-qj7j was published for mistralrs-server-core (Rust) Sep 10, 2026
koyokr Credited to koyokr
OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree High
GHSA-2q42-4q24-7rgv was published for @typespec/compiler (npm) Sep 8, 2026
NLx64 Credited to NLx64
Laravel Excel writes exports outside the configured filesystem disk when given a caller-controlled path High
CVE-2026-84374 was published for maatwebsite/excel (Composer) Sep 8, 2026
seck19 Credited to seck19
NLTK: Corpus Reader Sandbox Bypass High
CVE-2026-79674 was published for nltk (pip) Sep 8, 2026
nguyencanhthuong Credited to nguyencanhthuong
NLTK: Stable FrameNet and NKJP readers parse outside-root XML High
CVE-2026-62385 was published for nltk (pip) Sep 8, 2026
CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval High
CVE-2026-75913 was published for codewhale (npm) Sep 4, 2026
0xEr3n Credited to 0xEr3n
NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed roots High
CVE-2026-81726 was published for nltk (pip) Sep 2, 2026
pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project High
GHSA-2rx9-3g3h-c2jv was published for pnpm (npm) Sep 1, 2026
Duplicate Advisory: Model-artifact APIs bypass pathsec and touch files outside allowed roots High
GHSA-hqj7-phwp-c3fp was published for nltk (pip) Aug 27, 2026 • withdrawn
consciousness-explorer / sublinear-time-solver MCP export_state has an arbitrary file write High
CVE-2026-55609 was published for consciousness-explorer (npm) Aug 25, 2026
BruceJqs Credited to BruceJqs
Duplicate Advisory: NLTK: Corpus Reader Sandbox Bypass High
GHSA-rcw8-9qrw-27m2 was published for nltk (pip) Aug 25, 2026 • withdrawn
3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation High
CVE-2026-55477 was published for github.com/mhsanaei/3x-ui/v2 (Go) Aug 24, 2026
itsamirhn Credited to itsamirhn
Duplicate Advisory: Stable FrameNet and NKJP readers parse outside-root XML in 3.9.4 High
GHSA-qp76-pq9f-gr9m was published for nltk (pip) Aug 22, 2026 • withdrawn
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation High
CVE-2026-64679 was published for github.com/runatlantis/atlantis (Go) Aug 21, 2026
shblue21 Credited to shblue21
NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution High
GHSA-ghvf-qf6h-g8x5 was published for @nocobase/server (npm) Aug 20, 2026
lukehebe Credited to lukehebe
claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools High
GHSA-rr55-jp92-8wp2 was published for claude-faf-mcp (npm) Aug 19, 2026
ProTip! Advisories are also available from the GraphQL API