Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

12,566 advisories

Loading
PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks High
CVE-2026-55540 was published for PraisonAI (pip) Aug 25, 2026
riodrwn Credited to riodrwn
sour-exploit Credited to sour-exploit
PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution High
CVE-2026-55534 was published for PraisonAI (pip) Aug 25, 2026
huslayer826 Credited to huslayer826
evertrustai Credited to evertrustai
praisonaiagents: AgentServer declares auth_token but never enforces it on any route High
CVE-2026-55528 was published for praisonaiagents (pip) Aug 25, 2026
SnailSploit Credited to SnailSploit
praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets High
CVE-2026-55523 was published for praisonaiagents (pip) Aug 25, 2026
rexpository Credited to rexpository
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code High
CVE-2026-55522 was published for PraisonAI (pip) Aug 25, 2026
rexpository Credited to rexpository
praisonaiagents web_crawl vulnerable to SSRF via redirect-following High
CVE-2026-55525 was published for praisonaiagents (pip) Aug 25, 2026
Ampliox Credited to Ampliox
Duplicate Advisory: Uncontrolled search path when invoking the Graphviz 'dot' binary (CWE-426/CWE-427) High
GHSA-54xp-3ww7-6wjg was published for nltk (pip) Aug 25, 2026 withdrawn
3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation High
CVE-2026-55477 was published for github.com/mhsanaei/3x-ui/v2 (Go) Aug 24, 2026
itsamirhn Credited to itsamirhn
django CMS: Plugin move endpoint allows cyclic reparenting (DoS) High
CVE-2026-54623 was published for django-cms (pip) Aug 24, 2026
Zyy0530 Credited to Zyy0530, Str1ckl4nd, 7thParkk, and mauriceng98 Str1ckl4nd Str1ckl4nd
7thParkk 7thParkk mauriceng98 mauriceng98
postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service High
GHSA-5x78-73v4-xg6w was published for postgres-protocol (Rust) Aug 24, 2026
Sakai Conversations has a Stored XSS Issue High
CVE-2026-54049 was published for org.sakaiproject.conversations:sakai-conversations-impl (Maven) Aug 24, 2026
geo-chen Credited to geo-chen and ottenhoff ottenhoff ottenhoff
oscerd Credited to oscerd
Duplicate Advisory: Uncontrolled recursion DoS in JustHTML() via deeply nested HTML High
GHSA-892m-gcq8-2468 was published for justhtml (pip) Aug 23, 2026 withdrawn
Hydra: hydra.utils.instantiate with untrusted config can lead to code execution High
CVE-2026-68508 was published for hydra-core (pip) Aug 21, 2026
guwu1017 Credited to guwu1017
YOURLS has stored XSS in referrer statistics chart via crafted Referer header High
CVE-2026-63135 was published for yourls/yourls (Composer) Aug 21, 2026
sondt99 Credited to sondt99, dgw, ozh, and LeoColomb dgw dgw
ozh ozh LeoColomb LeoColomb
kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding High
CVE-2026-77354 was published for github.com/getkin/kin-openapi (Go) Aug 21, 2026
matiasinsaurralde Credited to matiasinsaurralde
kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoS High
CVE-2026-76905 was published for github.com/getkin/kin-openapi (Go) Aug 21, 2026
matiasinsaurralde Credited to matiasinsaurralde
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation High
CVE-2026-64679 was published for github.com/runatlantis/atlantis (Go) Aug 21, 2026
shblue21 Credited to shblue21
Keystone vulnerable to `graphql.maxTake` bypass with negative `take` High
CVE-2026-63421 was published for @keystone-6/core (npm) Aug 21, 2026
Haxset Credited to Haxset
Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors High
CVE-2026-61824 was published for defuddle (npm) Aug 21, 2026
Mr-DJ Credited to Mr-DJ
Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter High
CVE-2026-63462 was published for unleash-server (npm) Aug 21, 2026
kah-ja Credited to kah-ja
Winter: ImportExportController AJAX handlers bypass granular import/export permission gate High
GHSA-fm29-4mq3-phg6 was published for winter/wn-backend-module (Composer) Aug 20, 2026
manus-use Credited to manus-use
ProTip! Advisories are also available from the GraphQL API