Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

178 advisories

Loading
Streamlink: HTTPSession follows HTTP redirects into file:// URLs, reading local files Moderate
CVE-2026-92164 was published for streamlink (pip) Sep 24, 2026
arpitjain099 Credited to arpitjain099 and bastimeyer bastimeyer bastimeyer
junbyjun1238 Credited to junbyjun1238
mcfly-zzh Credited to mcfly-zzh
Redocly CLI: Path traversal when using `split` command Moderate
CVE-2026-63225 was published for @redocly/cli (npm) Sep 17, 2026
thegr1ffyn Credited to thegr1ffyn
mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url High
GHSA-wfgq-w7cq-qj7j was published for mistralrs-server-core (Rust) Sep 10, 2026
koyokr Credited to koyokr
Masofgon Credited to Masofgon
uziii2208 Credited to uziii2208
OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree High
GHSA-2q42-4q24-7rgv was published for @typespec/compiler (npm) Sep 8, 2026
NLx64 Credited to NLx64
Hcamael Credited to Hcamael
Laravel Excel writes exports outside the configured filesystem disk when given a caller-controlled path High
CVE-2026-84374 was published for maatwebsite/excel (Composer) Sep 8, 2026
seck19 Credited to seck19
NLTK: Corpus Reader Sandbox Bypass High
CVE-2026-79674 was published for nltk (pip) Sep 8, 2026
nguyencanhthuong Credited to nguyencanhthuong
NLTK: Stable FrameNet and NKJP readers parse outside-root XML High
CVE-2026-62385 was published for nltk (pip) Sep 8, 2026
CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval High
CVE-2026-75913 was published for codewhale (npm) Sep 4, 2026
0xEr3n Credited to 0xEr3n
OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download tool Moderate
CVE-2026-75602 was published for github.com/OpenListTeam/OpenList (Go) Sep 3, 2026
ILoveScratch2 Credited to ILoveScratch2, j2rong4cn, Suyunmeng, and jyxjjj j2rong4cn j2rong4cn
Suyunmeng Suyunmeng jyxjjj jyxjjj
NLTK: Downloader.download follows hardlinks and overwrites outside-root files Moderate
CVE-2026-81727 was published for nltk (pip) Sep 2, 2026
NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed roots High
CVE-2026-81726 was published for nltk (pip) Sep 2, 2026
pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project High
GHSA-2rx9-3g3h-c2jv was published for pnpm (npm) Sep 1, 2026
Duplicate Advisory: Model-artifact APIs bypass pathsec and touch files outside allowed roots High
GHSA-hqj7-phwp-c3fp was published for nltk (pip) Aug 27, 2026 • withdrawn
consciousness-explorer / sublinear-time-solver MCP export_state has an arbitrary file write High
CVE-2026-55609 was published for consciousness-explorer (npm) Aug 25, 2026
BruceJqs Credited to BruceJqs
Duplicate Advisory: NLTK: Corpus Reader Sandbox Bypass High
GHSA-rcw8-9qrw-27m2 was published for nltk (pip) Aug 25, 2026 • withdrawn
ProTip! Advisories are also available from the GraphQL API