Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

37 advisories

Loading
junbyjun1238 Credited to junbyjun1238
NLTK: Corpus Reader Sandbox Bypass High
CVE-2026-79674 was published for nltk (pip) Sep 8, 2026
nguyencanhthuong Credited to nguyencanhthuong
NLTK: Stable FrameNet and NKJP readers parse outside-root XML High
CVE-2026-62385 was published for nltk (pip) Sep 8, 2026
NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed roots High
CVE-2026-81726 was published for nltk (pip) Sep 2, 2026
Duplicate Advisory: Model-artifact APIs bypass pathsec and touch files outside allowed roots High
GHSA-hqj7-phwp-c3fp was published for nltk (pip) Aug 27, 2026 • withdrawn
Duplicate Advisory: NLTK: Corpus Reader Sandbox Bypass High
GHSA-rcw8-9qrw-27m2 was published for nltk (pip) Aug 25, 2026 • withdrawn
Duplicate Advisory: Stable FrameNet and NKJP readers parse outside-root XML in 3.9.4 High
GHSA-qp76-pq9f-gr9m was published for nltk (pip) Aug 22, 2026 • withdrawn
Duplicate Advisory: GitPython: Arbitrary file read via --pathspec-from-file in IndexFile.remove() and Head.checkout() High
GHSA-w672-239g-c3gr was published for gitpython (pip) Aug 19, 2026 • withdrawn
tinyb0y Credited to tinyb0y
nazeeh111 Credited to nazeeh111
Snowflake SQLAlchemy affected by SQL injection and local file disclosure vulnerabilities High
CVE-2026-15736 was published for snowflake-sqlalchemy (pip) Jul 14, 2026
mcp-atlassian: Arbitrary server-side file read via attachment upload High
GHSA-wm45-qh3g-v83f was published for mcp-atlassian (pip) Jul 10, 2026
0xmagic0 Credited to 0xmagic0
Phantom: Arbitrary file write and decode-bomb DoS via unconfined MCP tool paths High
GHSA-52vm-mxx8-f227 was published for phantom-audio (pip) Jul 9, 2026
leesaenz Credited to leesaenz
OctoPrint has possible file exfiltration via query parameters on upload endpoints High
CVE-2026-54134 was published for OctoPrint (pip) Jun 23, 2026
seankohjs Credited to seankohjs, jacopotediosi, and cookesan jacopotediosi jacopotediosi
cookesan cookesan
rexpository Credited to rexpository
Docling Core: Insufficient validation of image reference URIs High
CVE-2026-44019 was published for docling-core (pip) Jun 3, 2026
brodmart Credited to brodmart
Docling: Unsafe URI and Path Handling in HTML Backend High
CVE-2026-47214 was published for docling (pip) Jun 3, 2026
AnistoMejin Credited to AnistoMejin and brodmart brodmart brodmart
compliance-trestle - jinja has an Arbitrary File Write via Path Traversal High
CVE-2026-46345 was published for compliance-trestle (pip) May 28, 2026
l3tchupkt Credited to l3tchupkt
ProTip! Advisories are also available from the GraphQL API