GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,931
Maven
5,000+
npm
5,000+
NuGet
969
pip
5,000+
Pub
13
RubyGems
1,062
Rust
1,382
Swift
56
Unreviewed advisories
All unreviewed
5,000+
446 advisories
Filter by severity
ngrok is Vulnerable to Command Injection
High
CVE-2025-57282
was published
for
ngrok
(npm)
May 18, 2026
gitoxide: CommandForbiddenInModulesConfiguration Bypass in gix_submodule::File::update() Enables Arbitrary Command Execution via .gitmodules
High
GHSA-f26g-jm89-4g65
was published
for
gix
(Rust)
May 5, 2026
net-imap vulnerable to command Injection via "raw" arguments to multiple commands
Moderate
CVE-2026-42257
was published
for
net-imap
(RubyGems)
May 4, 2026
net-imap vulnerable to command Injection via unvalidated Symbol inputs
Moderate
CVE-2026-42258
was published
for
net-imap
(RubyGems)
May 4, 2026
yii2-mcp-server has a Command Injection Issue
Low
CVE-2026-7600
was published
for
yii2-mcp-server
(npm)
May 2, 2026
mcp-server-semgrep has a Command Injection issue
Moderate
CVE-2026-7446
was published
for
mcp-server-semgrep
(npm)
Apr 30, 2026
LiteLLM: Authenticated command execution via MCP stdio test endpoints
High
CVE-2026-42271
was published
for
litellm
(pip)
Apr 25, 2026
electerm has Command Injection via runLinux funtion
Critical
CVE-2026-41501
was published
for
electerm
(npm)
Apr 24, 2026
Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses
Critical
GHSA-wpqr-6v78-jr5g
was published
for
@google/gemini-cli
(GitHub Actions)
Apr 24, 2026
Claude Code: Trust Dialog Bypass via Git Worktree Spoofing Allows Arbitrary Code Execution
High
CVE-2026-40068
was published
for
@anthropic-ai/claude-code
(npm)
Apr 24, 2026
Inspektor Gadget: Command Injection via malicious buildOptions manipulation
Moderate
CVE-2026-24905
was published
for
github.com/inspektor-gadget/inspektor-gadget
(Go)
Apr 22, 2026
Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability
Critical
CVE-2026-41265
was published
for
flowise
(npm)
Apr 18, 2026
PraisonAI has an incomplete fix for CVE-2026-34935 - OS Command Injection
Critical
CVE-2026-41497
was published
for
praisonai
(pip)
Apr 17, 2026
Paperclip: Malicious skills able to exfiltrate and destroy all user data
High
GHSA-w8hx-hqjv-vjcq
was published
for
@paperclipai/server
(npm)
Apr 16, 2026
WWBN AVideo: RCE cause by clonesite plugin
High
CVE-2026-41304
was published
for
wwbn/avideo
(Composer)
Apr 16, 2026
electerm: electerm_install_script_CommandInjection Vulnerability Report
Critical
CVE-2026-41500
was published
for
electerm
(npm)
Apr 16, 2026
Upsonic: remote code execution vulnerability in its MCP server/task creation functionality
Critical
CVE-2026-30625
was published
for
upsonic
(pip)
Apr 15, 2026
NietThijmen ShoppingCart: Command injection in the connect function
High
CVE-2024-53412
was published
for
github.com/NietThijmen/ShoppingCart
(Go)
Apr 15, 2026
FoundationAgents MetaGPT vulnerable to os command injection via the Terminal.run_command
Moderate
CVE-2026-5972
was published
for
metagpt
(pip)
Apr 9, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/tools/libs/terminal.py
Moderate
CVE-2026-5974
was published
for
metagpt
(pip)
Apr 9, 2026
FoundationAgents MetaGPT vulnerable to OS Command Injection in metagpt/utils/common.py
Moderate
CVE-2026-5973
was published
for
metagpt
(pip)
Apr 9, 2026
Agions taskflow-ai vulnerable to os command injection in src/mcp/server/handlers.ts
Moderate
CVE-2026-5831
was published
for
taskflow-ai
(npm)
Apr 9, 2026
Emissary has GitHub Actions Shell Injection via Workflow Inputs
Critical
CVE-2026-35580
was published
for
gov.nsa.emissary:emissary
(Maven)
Apr 8, 2026
@nor2/heim-mcp vulnerable to command injection
Low
CVE-2026-5602
was published
for
@nor2/heim-mcp
(npm)
Apr 6, 2026
@elgentos/magento2-dev-mcp vulnerable to command injection
Low
CVE-2026-5603
was published
for
@elgentos/magento2-dev-mcp
(npm)
Apr 6, 2026
ProTip!
Advisories are also available from the
GraphQL API