GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,535
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,515
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
372 advisories
Filter by severity
uniget CLI has an EDITOR Command Injection
Moderate
CVE-2026-55061
was published
for
gitlab.com/uniget-org/cli
(Go)
Aug 17, 2026
Semaphore versions prior to 2.18.20 contain an OS command injection (argument injection)...
High
Unreviewed
CVE-2026-73682
was published
Aug 14, 2026
GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the...
High
Unreviewed
CVE-2026-73624
was published
Aug 13, 2026
GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method...
Moderate
Unreviewed
CVE-2026-73621
was published
Aug 13, 2026
PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags...
Critical
Unreviewed
CVE-2026-16770
was published
Aug 13, 2026
Specifically crafted inputs may lead to git argument injection in Apache Allura.
This issue...
Critical
Unreviewed
CVE-2026-73240
was published
Aug 12, 2026
An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 allows authenticated users...
High
Unreviewed
CVE-2026-72538
was published
Aug 11, 2026
GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution
High
GHSA-wvpp-8hx9-p66j
was published
for
GitPython
(pip)
Aug 7, 2026
GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)
High
GHSA-jm78-9fvv-mhgr
was published
for
GitPython
(pip)
Aug 7, 2026
GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks
High
GHSA-9rj7-rf2p-w77r
was published
for
GitPython
(pip)
Aug 7, 2026
GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
High
GHSA-4gmw-gg2m-w46p
was published
for
GitPython
(pip)
Aug 7, 2026
xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp command-line invocation (xidown/core...
Moderate
Unreviewed
CVE-2026-71212
was published
Aug 5, 2026
GitPython: Arbitrary file truncation via git rev-list --output argument injection in unguarded Commit.count
Moderate
GHSA-p538-c434-8v24
was published
for
GitPython
(pip)
Aug 3, 2026
A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to...
High
Unreviewed
CVE-2026-18157
was published
Jul 31, 2026
An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia...
High
Unreviewed
CVE-2026-43698
was published
Jul 27, 2026
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
High
CVE-2026-16796
was published
for
bedrock-agentcore
(pip)
Jul 24, 2026
Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes
High
GHSA-g3hq-hphg-8fhh
was published
for
pheditor/pheditor
(Composer)
Jul 24, 2026
GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution
High
GHSA-r9mr-m37c-5fr3
was published
for
GitPython
(pip)
Jul 24, 2026
GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)
High
GHSA-fjr4-x663-mwxc
was published
for
GitPython
(pip)
Jul 24, 2026
A flaw was found in the Visual Studio Code Ansible Lightspeed extension's...
High
Unreviewed
CVE-2026-44189
was published
Jul 22, 2026
GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
High
GHSA-956x-8gvw-wg5v
was published
for
GitPython
(pip)
Jul 21, 2026
A flaw was found in ansible-core. The _extract_collection_from_git() function in ansible-core's...
High
Unreviewed
CVE-2026-16493
was published
Jul 21, 2026
FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line...
High
Unreviewed
CVE-2026-64624
was published
Jul 21, 2026
mcp-server-kubernetes argument injection can expose Kubernetes cluster credentials
Critical
CVE-2026-61459
was published
for
mcp-server-kubernetes
(pip)
Jul 10, 2026
File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)
Critical
CVE-2026-54088
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 10, 2026
ProTip!
Advisories are also available from the
GraphQL API