GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,553
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
58 advisories
Filter by severity
GitPython: Unsafe git option guard bypass via split_single_char_options=False short-option token smuggling enables command execution
High
GHSA-wvpp-8hx9-p66j
was published
for
GitPython
(pip)
Aug 7, 2026
GitPython: git-config OPTION-name injection via =/#/whitespace bypasses name validator, enabling forged core.sshCommand/hooksPath (RCE)
High
GHSA-jm78-9fvv-mhgr
was published
for
GitPython
(pip)
Aug 7, 2026
GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks
High
GHSA-9rj7-rf2p-w77r
was published
for
GitPython
(pip)
Aug 7, 2026
GitPython: Unguarded git read-tree option forwarding in IndexFile.from_tree/reset/merge_tree enables arbitrary file overwrite
High
GHSA-4gmw-gg2m-w46p
was published
for
GitPython
(pip)
Aug 7, 2026
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages()
High
CVE-2026-16796
was published
for
bedrock-agentcore
(pip)
Jul 24, 2026
Pheditor: Terminal command-allowlist bypass via argument injection leads to RCE — surviving vector after the metacharacter-sanitization fixes
High
GHSA-g3hq-hphg-8fhh
was published
for
pheditor/pheditor
(Composer)
Jul 24, 2026
GitPython: Unsafe git option guard bypass via single-character kwarg value token smuggling enables arbitrary command execution
High
GHSA-r9mr-m37c-5fr3
was published
for
GitPython
(pip)
Jul 24, 2026
GitPython: Arbitrary file overwrite via git diff --output argument injection in Diffable.diff (key- and value-controlled)
High
GHSA-fjr4-x663-mwxc
was published
for
GitPython
(pip)
Jul 24, 2026
GitPython: command injection via unguarded Git options in `Repo.archive()`, `git.ls_remote()`, and arbitrary file overwrite via `Repo.iter_commits()` / `Repo.blame()`
High
GHSA-956x-8gvw-wg5v
was published
for
GitPython
(pip)
Jul 21, 2026
Tekton Pipeline: Git Resolver Unsanitized Revision Parameter Enables git Argument Injection Leading to RCE
High
CVE-2026-40938
was published
for
github.com/tektoncd/pipeline
(Go)
Apr 21, 2026
ansible-core: Argument injection in ansible-galaxy role install leads to arbitrary code execution
High
CVE-2026-11332
was published
for
ansible-core
(pip)
Jun 5, 2026
Linuxfabrik Monitoring Plugins: Sudoers may be able to obtain privilege escalation via /usr/bin/apt-get arguments
High
CVE-2026-52817
was published
for
linuxfabrik-lib
(pip)
Jul 2, 2026
Grackle has command/argument injection in the git worktree executor that enables RCE on provisioned hosts via an unsanitized task branch name (shell:true)
High
GHSA-vv65-f55v-xm6g
was published
for
@grackle-ai/powerline
(npm)
Jul 2, 2026
repomix Vulnerable to Command Injection (RCE) via `--remote-branch` Argument Injection
High
CVE-2026-49987
was published
for
repomix
(npm)
Jul 1, 2026
Prefect has an Argument Injection issue
High
CVE-2026-3515
was published
for
prefect
(pip)
May 26, 2026
Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()
High
CVE-2026-12530
was published
for
bedrock-agentcore
(pip)
Jun 19, 2026
skillctl: argument injection, path traversal in --dest, FIFO/device DoS, hardlink exfiltration, and commit-trailer forgery
High
GHSA-74p7-6h78-gw8p
was published
for
skillctl
(Rust)
Jun 22, 2026
Docker MCP Gateway: Argument injection via OCI image label YAML
High
CVE-2026-55887
was published
for
github.com/docker/mcp-gateway
(Go)
Jun 18, 2026
filebrowser Allows Shell Commands to Spawn Other Commands
High
CVE-2025-52903
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jun 27, 2025
File Browser has a Command Injection via Hook Runner
High
CVE-2026-35585
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Apr 8, 2026
JupyterLab has an Extension Manager API/GUI Policy Discrepancy, allowing 3rd party (malicious) extensions install via POST request
High
CVE-2026-42266
was published
for
jupyterlab
(pip)
May 5, 2026
exiftool-vendored vulnerable to argument injection via newline characters in tag names
High
CVE-2026-43893
was published
for
exiftool-vendored
(npm)
May 5, 2026
GitPython: Unsafe option check validates multi_options before shlex.split transformation
High
CVE-2026-42284
was published
for
GitPython
(pip)
Apr 25, 2026
PHPUnit has Argument injection via newline in PHP INI values that are forwarded to child processes
High
CVE-2026-41570
was published
for
phpunit/phpunit
(Composer)
Apr 18, 2026
Electerm Security Vulnerability: RCE via malicious SSH server filename in openFileWithEditor
High
CVE-2026-43943
was published
for
electerm
(npm)
May 8, 2026
ProTip!
Advisories are also available from the
GraphQL API