Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

20 advisories

Loading
manus-use Credited to manus-use
manus-use Credited to manus-use
manus-use Credited to manus-use and BarakSrour BarakSrour BarakSrour
manus-use Credited to manus-use and bhaswanthc bhaswanthc bhaswanthc
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages() High
CVE-2026-16796 was published for bedrock-agentcore (pip) Jul 24, 2026
MrCloudSec Credited to MrCloudSec
manus-use Credited to manus-use
manus-use Credited to manus-use
OoYo0uto Credited to OoYo0uto
Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages() High
CVE-2026-12530 was published for bedrock-agentcore (pip) Jun 19, 2026
MrCloudSec Credited to MrCloudSec
ansible-core: Argument injection in ansible-galaxy role install leads to arbitrary code execution High
CVE-2026-11332 was published for ansible-core (pip) Jun 5, 2026
Prefect has an Argument Injection issue High
CVE-2026-3515 was published for prefect (pip) May 26, 2026
pmcao Credited to pmcao, Yann-P, and krassowski Yann-P Yann-P
krassowski krassowski
GitPython: Unsafe option check validates multi_options before shlex.split transformation High
CVE-2026-42284 was published for GitPython (pip) Apr 25, 2026
Texuguinho1234 Credited to Texuguinho1234
aswinastro Credited to aswinastro and g0w6y g0w6y g0w6y
Apache Airflow ODBC Provider Argument Injection vulnerability High
CVE-2023-34395 was published for apache-airflow-providers-odbc (pip) Jun 27, 2023
Poetry Argument Injection can lead to Local Code Execution High
CVE-2022-36069 was published for poetry (pip) Sep 16, 2022
paul-gerste-sonarsource Credited to paul-gerste-sonarsource and neersighted neersighted neersighted
Codecov does not sanitize gcov arguments High
CVE-2019-10800 was published for codecov (pip) Jul 14, 2022
Improper Neutralization of Special Elements used in a Command ('Command Injection') in Weblate High
CVE-2022-23915 was published for Weblate (pip) Mar 4, 2022
dellalibera Credited to dellalibera
Arbitrary command execution on Windows via qutebrowserurl: URL handler High
CVE-2021-41146 was published for qutebrowser (pip) Oct 22, 2021
ProTip! Advisories are also available from the GraphQL API