Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

446 advisories

Loading
ngrok is Vulnerable to Command Injection High
CVE-2025-57282 was published for ngrok (npm) May 18, 2026
net-imap vulnerable to command Injection via "raw" arguments to multiple commands Moderate
CVE-2026-42257 was published for net-imap (RubyGems) May 4, 2026
manunio Credited to manunio
net-imap vulnerable to command Injection via unvalidated Symbol inputs Moderate
CVE-2026-42258 was published for net-imap (RubyGems) May 4, 2026
manunio Credited to manunio
yii2-mcp-server has a Command Injection Issue Low
CVE-2026-7600 was published for yii2-mcp-server (npm) May 2, 2026
mcp-server-semgrep has a Command Injection issue Moderate
CVE-2026-7446 was published for mcp-server-semgrep (npm) Apr 30, 2026
LiteLLM: Authenticated command execution via MCP stdio test endpoints High
CVE-2026-42271 was published for litellm (pip) Apr 25, 2026
electerm has Command Injection via runLinux funtion Critical
CVE-2026-41501 was published for electerm (npm) Apr 24, 2026
Yuremin Credited to Yuremin and FORIMOC FORIMOC FORIMOC
Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses Critical
GHSA-wpqr-6v78-jr5g was published for @google/gemini-cli (GitHub Actions) Apr 24, 2026
DanusMinimus Credited to DanusMinimus and EladMeged-Novee EladMeged-Novee EladMeged-Novee
Claude Code: Trust Dialog Bypass via Git Worktree Spoofing Allows Arbitrary Code Execution High
CVE-2026-40068 was published for @anthropic-ai/claude-code (npm) Apr 24, 2026
Inspektor Gadget: Command Injection via malicious buildOptions manipulation Moderate
CVE-2026-24905 was published for github.com/inspektor-gadget/inspektor-gadget (Go) Apr 22, 2026
ndaprela Credited to ndaprela, suidpit, eiffel-fl, and burak-ok suidpit suidpit
eiffel-fl eiffel-fl burak-ok burak-ok
Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability Critical
CVE-2026-41265 was published for flowise (npm) Apr 18, 2026
zdi-disclosures Credited to zdi-disclosures
PraisonAI has an incomplete fix for CVE-2026-34935 - OS Command Injection Critical
CVE-2026-41497 was published for praisonai (pip) Apr 17, 2026
decsecre583 Credited to decsecre583
Paperclip: Malicious skills able to exfiltrate and destroy all user data High
GHSA-w8hx-hqjv-vjcq was published for @paperclipai/server (npm) Apr 16, 2026
WWBN AVideo: RCE cause by clonesite plugin High
CVE-2026-41304 was published for wwbn/avideo (Composer) Apr 16, 2026
Rangar0k Credited to Rangar0k
electerm: electerm_install_script_CommandInjection Vulnerability Report Critical
CVE-2026-41500 was published for electerm (npm) Apr 16, 2026
Yuremin Credited to Yuremin and FORIMOC FORIMOC FORIMOC
Upsonic: remote code execution vulnerability in its MCP server/task creation functionality Critical
CVE-2026-30625 was published for upsonic (pip) Apr 15, 2026
NietThijmen ShoppingCart: Command injection in the connect function High
CVE-2024-53412 was published for github.com/NietThijmen/ShoppingCart (Go) Apr 15, 2026
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command Moderate
CVE-2026-5972 was published for metagpt (pip) Apr 9, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py Moderate
CVE-2026-5974 was published for metagpt (pip) Apr 9, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py Moderate
CVE-2026-5973 was published for metagpt (pip) Apr 9, 2026
Agions taskflow-ai vulnerable to os command injection in src/mcp/server/handlers.ts Moderate
CVE-2026-5831 was published for taskflow-ai (npm) Apr 9, 2026
Emissary has GitHub Actions Shell Injection via Workflow Inputs Critical
CVE-2026-35580 was published for gov.nsa.emissary:emissary (Maven) Apr 8, 2026
BrennanTM Credited to BrennanTM
@nor2/heim-mcp vulnerable to command injection Low
CVE-2026-5602 was published for @nor2/heim-mcp (npm) Apr 6, 2026
@elgentos/magento2-dev-mcp vulnerable to command injection Low
CVE-2026-5603 was published for @elgentos/magento2-dev-mcp (npm) Apr 6, 2026
ProTip! Advisories are also available from the GraphQL API