GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
12,566 advisories
Filter by severity
PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks
High
CVE-2026-55540
was published
for
PraisonAI
(pip)
Aug 25, 2026
praisonaiagents vulnerable to SSRF in web_crawl tool via redirect-following and DNS rebinding (validate-then-fetch gap)
High
CVE-2026-55524
was published
for
praisonaiagents
(pip)
Aug 25, 2026
PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution
High
CVE-2026-55534
was published
for
PraisonAI
(pip)
Aug 25, 2026
praisonaiagents has an SSRF protection bypass in `spider_tools._host_is_blocked()` via DNS-resolved hostnames (`127.0.0.1.nip.io`)
High
CVE-2026-55526
was published
for
praisonaiagents
(pip)
Aug 25, 2026
praisonaiagents: AgentServer declares auth_token but never enforces it on any route
High
CVE-2026-55528
was published
for
praisonaiagents
(pip)
Aug 25, 2026
praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets
High
CVE-2026-55523
was published
for
praisonaiagents
(pip)
Aug 25, 2026
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
High
CVE-2026-55522
was published
for
PraisonAI
(pip)
Aug 25, 2026
praisonaiagents web_crawl vulnerable to SSRF via redirect-following
High
CVE-2026-55525
was published
for
praisonaiagents
(pip)
Aug 25, 2026
Duplicate Advisory: Uncontrolled search path when invoking the Graphviz 'dot' binary (CWE-426/CWE-427)
High
GHSA-54xp-3ww7-6wjg
was published
for
nltk
(pip)
Aug 25, 2026
•
withdrawn
3X-UI Vulnerable to Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation
High
CVE-2026-55477
was published
for
github.com/mhsanaei/3x-ui/v2
(Go)
Aug 24, 2026
django CMS: Plugin move endpoint allows cyclic reparenting (DoS)
High
CVE-2026-54623
was published
for
django-cms
(pip)
Aug 24, 2026
postgres-protocol: Unbounded SCRAM iteration count allows a malicious server to cause CPU-exhaustion denial of service
High
GHSA-5x78-73v4-xg6w
was published
for
postgres-protocol
(Rust)
Aug 24, 2026
Sakai Conversations has a Stored XSS Issue
High
CVE-2026-54049
was published
for
org.sakaiproject.conversations:sakai-conversations-impl
(Maven)
Aug 24, 2026
Apache Camel-platform-http-main: when JWT authentication was configured with a keystore but no issuer or audience, the iss and aud claims were never validated, so any unexpired token signed by a trusted key was accepted
High
CVE-2026-66908
was published
for
org.apache.camel:camel-platform-http-main
(Maven)
Aug 24, 2026
Apache Camel-Google-Storage: the consumer appended the remote object name to the configured downloadFileName directory without constraining the result
High
CVE-2026-66907
was published
for
org.apache.camel:camel-google-storage
(Maven)
Aug 24, 2026
Duplicate Advisory: Uncontrolled recursion DoS in JustHTML() via deeply nested HTML
High
GHSA-892m-gcq8-2468
was published
for
justhtml
(pip)
Aug 23, 2026
•
withdrawn
Hydra: hydra.utils.instantiate with untrusted config can lead to code execution
High
CVE-2026-68508
was published
for
hydra-core
(pip)
Aug 21, 2026
YOURLS has stored XSS in referrer statistics chart via crafted Referer header
High
CVE-2026-63135
was published
for
yourls/yourls
(Composer)
Aug 21, 2026
kin-openapi has uncontrolled resource consumption in openapi3filter deepObject query parameter decoding
High
CVE-2026-77354
was published
for
github.com/getkin/kin-openapi
(Go)
Aug 21, 2026
kin-openapi openai3filter: nil-pointer panic in ConvertErrors on malformed multipart/form-data body enables unauthenticated DoS
High
CVE-2026-76905
was published
for
github.com/getkin/kin-openapi
(Go)
Aug 21, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation
High
CVE-2026-64679
was published
for
github.com/runatlantis/atlantis
(Go)
Aug 21, 2026
Keystone vulnerable to `graphql.maxTake` bypass with negative `take`
High
CVE-2026-63421
was published
for
@keystone-6/core
(npm)
Aug 21, 2026
Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors
High
CVE-2026-61824
was published
for
defuddle
(npm)
Aug 21, 2026
Unleash: Unauthenticated single-request DoS via OpenAPI validation error formatter
High
CVE-2026-63462
was published
for
unleash-server
(npm)
Aug 21, 2026
Winter: ImportExportController AJAX handlers bypass granular import/export permission gate
High
GHSA-fm29-4mq3-phg6
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
ProTip!
Advisories are also available from the
GraphQL API