GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,553
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,038 advisories
Filter by severity
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
High
CVE-2026-53951
was published
for
copier
(pip)
Aug 19, 2026
jmespath.php has CompilerRuntime code injection via unescaped function names
Critical
CVE-2026-54133
was published
for
mtdowling/jmespath.php
(Composer)
Aug 18, 2026
kobako Sandbox Escape: guest eval reaches host RCE via method_missing → public_send (any bound Service)
Critical
CVE-2026-55107
was published
for
kobako
(RubyGems)
Aug 18, 2026
sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes
Moderate
CVE-2026-59894
was published
for
sqlparse
(pip)
Aug 17, 2026
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install`
High
CVE-2026-55071
was published
for
stata-mcp
(pip)
Aug 12, 2026
GitPython: Unguarded git option forwarding in Repo.init enables arbitrary command execution via --template clone hooks
High
GHSA-9rj7-rf2p-w77r
was published
for
GitPython
(pip)
Aug 7, 2026
Mermaid allows CSS injection applying to sibling elements of the diagram
Moderate
CVE-2026-50159
was published
for
mermaid
(npm)
Aug 6, 2026
Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
High
CVE-2026-71320
was published
for
nuxt
(npm)
Aug 5, 2026
Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host
Critical
CVE-2026-71319
was published
for
@nuxt/devtools
(npm)
Aug 5, 2026
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter
Moderate
CVE-2026-70609
was published
for
electron
(npm)
Aug 5, 2026
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
Critical
CVE-2026-70477
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
Critical
CVE-2026-69264
was published
for
flowise
(npm)
Aug 4, 2026
Flowise RCE via SQLite Record Manager Node
Critical
CVE-2026-69259
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: Remote Code Execution Vulnerability in CSVAgent
Critical
CVE-2026-69256
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
Critical
CVE-2026-69255
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
Critical
CVE-2026-69254
was published
for
flowise
(npm)
Aug 4, 2026
Flowise RCE via TypeORM DataSource
Critical
CVE-2026-69251
was published
for
flowise
(npm)
Aug 4, 2026
Savon::Model evaluates WSDL operation names as Ruby source
High
CVE-2026-53510
was published
for
savon
(RubyGems)
Jul 31, 2026
AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping
High
CVE-2026-11393
was published
for
@aws/agentcore
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
High
CVE-2026-54666
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped enum string values
High
CVE-2026-54664
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
High
CVE-2026-54661
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
High
CVE-2026-54662
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field
High
CVE-2026-54654
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
High
CVE-2026-54653
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
ProTip!
Advisories are also available from the
GraphQL API