Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

58 advisories

Loading
manus-use Credited to manus-use
manus-use Credited to manus-use
manus-use Credited to manus-use and BarakSrour BarakSrour BarakSrour
manus-use Credited to manus-use and bhaswanthc bhaswanthc bhaswanthc
AWS Bedrock AgentCore: Improper neutralization of argument delimiters in the Python SDK install_packages() High
CVE-2026-16796 was published for bedrock-agentcore (pip) Jul 24, 2026
MrCloudSec Credited to MrCloudSec
anir0y Credited to anir0y, manus-use, sermikr0, adamyordan, Pig-Tail, tonghuaroot, and alimony manus-use manus-use
sermikr0 sermikr0 adamyordan adamyordan Pig-Tail Pig-Tail tonghuaroot tonghuaroot alimony alimony
manus-use Credited to manus-use
manus-use Credited to manus-use
Tekton Pipeline: Git Resolver Unsanitized Revision Parameter Enables git Argument Injection Leading to RCE High
CVE-2026-40938 was published for github.com/tektoncd/pipeline (Go) Apr 21, 2026
offset Credited to offset, vdemeester, kodareef5, and waveywaves vdemeester vdemeester
kodareef5 kodareef5 waveywaves waveywaves
ansible-core: Argument injection in ansible-galaxy role install leads to arbitrary code execution High
CVE-2026-11332 was published for ansible-core (pip) Jun 5, 2026
OoYo0uto Credited to OoYo0uto
repomix Vulnerable to Command Injection (RCE) via `--remote-branch` Argument Injection High
CVE-2026-49987 was published for repomix (npm) Jul 1, 2026
kakashi-kx Credited to kakashi-kx
Prefect has an Argument Injection issue High
CVE-2026-3515 was published for prefect (pip) May 26, 2026
Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages() High
CVE-2026-12530 was published for bedrock-agentcore (pip) Jun 19, 2026
MrCloudSec Credited to MrCloudSec
Docker MCP Gateway: Argument injection via OCI image label YAML High
CVE-2026-55887 was published for github.com/docker/mcp-gateway (Go) Jun 18, 2026
filebrowser Allows Shell Commands to Spawn Other Commands High
CVE-2025-52903 was published for github.com/filebrowser/filebrowser/v2 (Go) Jun 27, 2025
mtausig Credited to mtausig and hacdias hacdias hacdias
File Browser has a Command Injection via Hook Runner High
CVE-2026-35585 was published for github.com/filebrowser/filebrowser/v2 (Go) Apr 8, 2026
Saku0512 Credited to Saku0512
pmcao Credited to pmcao, Yann-P, and krassowski Yann-P Yann-P
krassowski krassowski
exiftool-vendored vulnerable to argument injection via newline characters in tag names High
CVE-2026-43893 was published for exiftool-vendored (npm) May 5, 2026
Dobby153 Credited to Dobby153
GitPython: Unsafe option check validates multi_options before shlex.split transformation High
CVE-2026-42284 was published for GitPython (pip) Apr 25, 2026
Texuguinho1234 Credited to Texuguinho1234
PHPUnit has Argument injection via newline in PHP INI values that are forwarded to child processes High
CVE-2026-41570 was published for phpunit/phpunit (Composer) Apr 18, 2026
kayw-geek Credited to kayw-geek, sebastianbergmann, and sanmai sebastianbergmann sebastianbergmann
sanmai sanmai
Electerm Security Vulnerability: RCE via malicious SSH server filename in openFileWithEditor High
CVE-2026-43943 was published for electerm (npm) May 8, 2026
osageling Credited to osageling
ProTip! Advisories are also available from the GraphQL API