GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
2,019 advisories
Filter by severity
pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project
High
GHSA-2rx9-3g3h-c2jv
was published
for
pnpm
(npm)
Sep 1, 2026
Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling
High
CVE-2026-75594
was published
for
getkirby/cms
(Composer)
Aug 31, 2026
SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read
High
CVE-2026-55874
was published
for
github.com/seaweedfs/seaweedfs
(Go)
Aug 28, 2026
Snipe-IT has a path traversal vulnerability via CSV import `image` field
Low
CVE-2026-55469
was published
for
snipe/snipe-it
(Composer)
Aug 28, 2026
Yamcs has Unauthenticated Directory Traversal
High
CVE-2026-55552
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
Aqua's archive extraction follows attacker-planted symlinks, allowing writes outside the install directory
Moderate
CVE-2026-55569
was published
for
github.com/aquaproj/aqua/v2
(Go)
Aug 28, 2026
libreoffice-convert vulnerable to path traversal / arbitrary file write
Moderate
CVE-2026-54732
was published
for
libreoffice-convert
(npm)
Aug 27, 2026
n8n-nodes-sqlite3 vulnerable to path traversal via user-controlled database file path (db_path parameter)
Moderate
CVE-2026-54687
was published
for
n8n-nodes-sqlite3
(npm)
Aug 27, 2026
asyncssh has SCP Path Traversal to Arbitrary File Write
High
CVE-2026-54591
was published
for
asyncssh
(pip)
Aug 26, 2026
asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution
Moderate
CVE-2026-54590
was published
for
asyncssh
(pip)
Aug 26, 2026
IzPack has Path Traversal in UnpackerBase that allows writing files outside the installation directory via malicious pack entries
High
CVE-2026-54550
was published
for
org.codehaus.izpack:izpack-installer
(Maven)
Aug 26, 2026
Whistle vulnerable to path traversal
High
CVE-2026-55629
was published
for
whistle
(npm)
Aug 25, 2026
Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts
High
CVE-2026-55092
was published
for
github.com/aquasecurity/trivy
(Go)
Aug 25, 2026
phpMyFAQ has Potential Authenticated Path Traversal in PDF Export
Moderate
GHSA-88g4-74f3-63x9
was published
for
phpmyfaq/phpmyfaq
(Composer)
Aug 25, 2026
browse-mcp has an arbitrary file write via unconfined download and state paths
High
CVE-2026-55557
was published
for
browse-mcp
(npm)
Aug 25, 2026
Echo: Encoded slash (%2F) bypasses route-level protection and exposes static files
High
CVE-2026-55677
was published
for
github.com/labstack/echo
(Go)
Aug 25, 2026
praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location
High
CVE-2026-55527
was published
for
praisonaiagents
(pip)
Aug 25, 2026
PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks
High
CVE-2026-55540
was published
for
PraisonAI
(pip)
Aug 25, 2026
Cloudreve's remote download file paths can escape the selected destination directory
Moderate
GHSA-w8j7-39hp-8x59
was published
for
github.com/cloudreve/Cloudreve/v4
(Go)
Aug 24, 2026
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation
High
CVE-2026-64679
was published
for
github.com/runatlantis/atlantis
(Go)
Aug 21, 2026
Winter: Local File Inclusion through =include directives in JavaScript asset compilation
Moderate
GHSA-2223-f22x-24cq
was published
for
winter/wn-system-module
(Composer)
Aug 20, 2026
Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assets
Moderate
CVE-2026-63179
was published
for
winter/wn-backend-module
(Composer)
Aug 20, 2026
Laravel Backpack CRUD: Arbitrary file deletion via attacker-controlled clear_<attr>[] in HasUploadFields::uploadMultipleFilesToDisk
High
CVE-2026-54178
was published
for
backpack/crud
(Composer)
Aug 20, 2026
Velero vulnerable to file path traversal when extracting from backup's tarball
Moderate
CVE-2026-32637
was published
for
github.com/vmware-tanzu/velero
(Go)
Aug 20, 2026
logto-tunnel serves files outside --experience-path via path traversal
High
CVE-2026-63188
was published
for
@logto/tunnel
(npm)
Aug 19, 2026
ProTip!
Advisories are also available from the
GraphQL API