Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,038 advisories

Loading
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted High
CVE-2026-53951 was published for copier (pip) Aug 19, 2026
seankohjs Credited to seankohjs and sisp sisp sisp
jmespath.php has CompilerRuntime code injection via unescaped function names Critical
CVE-2026-54133 was published for mtdowling/jmespath.php (Composer) Aug 18, 2026
edorian Credited to edorian
kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service) Critical
CVE-2026-55107 was published for kobako (RubyGems) Aug 18, 2026
alhafoudh Credited to alhafoudh
sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes Moderate
CVE-2026-59894 was published for sqlparse (pip) Aug 17, 2026
7thParkk Credited to 7thParkk
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install` High
CVE-2026-55071 was published for stata-mcp (pip) Aug 12, 2026
EQSTLab Credited to EQSTLab and useworld useworld useworld
manus-use Credited to manus-use and BarakSrour BarakSrour BarakSrour
Mermaid allows CSS injection applying to sibling elements of the diagram Moderate
CVE-2026-50159 was published for mermaid (npm) Aug 6, 2026
h3ri0s Credited to h3ri0s and aloisklink aloisklink aloisklink
Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host Critical
CVE-2026-71319 was published for @nuxt/devtools (npm) Aug 5, 2026
TazmiDev Credited to TazmiDev and anzuukino anzuukino anzuukino
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter Moderate
CVE-2026-70609 was published for electron (npm) Aug 5, 2026
hackerman70000 Credited to hackerman70000
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability Critical
CVE-2026-70477 was published for flowise (npm) Aug 4, 2026
zdi-disclosures Credited to zdi-disclosures
amwhoi Credited to amwhoi
Flowise RCE via SQLite Record Manager Node Critical
CVE-2026-69259 was published for flowise (npm) Aug 4, 2026
alex-elttam Credited to alex-elttam
Flowise: Remote Code Execution Vulnerability in CSVAgent Critical
CVE-2026-69256 was published for flowise (npm) Aug 4, 2026
jia-elttam Credited to jia-elttam
Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified Critical
CVE-2026-69255 was published for flowise (npm) Aug 4, 2026
lexi-core-ai Credited to lexi-core-ai
Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override Critical
CVE-2026-69254 was published for flowise (npm) Aug 4, 2026
akshat-sj Credited to akshat-sj
Flowise RCE via TypeORM DataSource Critical
CVE-2026-69251 was published for flowise (npm) Aug 4, 2026
alex-elttam Credited to alex-elttam
Savon::Model evaluates WSDL operation names as Ruby source High
CVE-2026-53510 was published for savon (RubyGems) Jul 31, 2026
connorshea Credited to connorshea
AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping High
CVE-2026-11393 was published for @aws/agentcore (npm) Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies High
CVE-2026-54666 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
swagger-typescript-api vulnerable to code injection via unescaped enum string values High
CVE-2026-54664 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template High
CVE-2026-54661 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template High
CVE-2026-54662 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
thegr1ffyn Credited to thegr1ffyn
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field High
CVE-2026-54653 was published for datamodel-code-generator (pip) Jul 28, 2026
thegr1ffyn Credited to thegr1ffyn
ProTip! Advisories are also available from the GraphQL API