Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,019 advisories

Loading
pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project High
GHSA-2rx9-3g3h-c2jv was published for pnpm (npm) Sep 1, 2026
Pig-Tail Credited to Pig-Tail
SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read High
CVE-2026-55874 was published for github.com/seaweedfs/seaweedfs (Go) Aug 28, 2026
47Cid Credited to 47Cid
Snipe-IT has a path traversal vulnerability via CSV import `image` field Low
CVE-2026-55469 was published for snipe/snipe-it (Composer) Aug 28, 2026
Vasco0x4 Credited to Vasco0x4
Yamcs has Unauthenticated Directory Traversal High
CVE-2026-55552 was published for org.yamcs:yamcs-core (Maven) Aug 28, 2026
suffs811 Credited to suffs811, AbdrrahimDahmani, and 0x4ndy AbdrrahimDahmani AbdrrahimDahmani
0x4ndy 0x4ndy
Aqua's archive extraction follows attacker-planted symlinks, allowing writes outside the install directory Moderate
CVE-2026-55569 was published for github.com/aquaproj/aqua/v2 (Go) Aug 28, 2026
zerodaybugs Credited to zerodaybugs
libreoffice-convert vulnerable to path traversal / arbitrary file write Moderate
CVE-2026-54732 was published for libreoffice-convert (npm) Aug 27, 2026
Santoshkumarpuppala Credited to Santoshkumarpuppala
n8n-nodes-sqlite3 vulnerable to path traversal via user-controlled database file path (db_path parameter) Moderate
CVE-2026-54687 was published for n8n-nodes-sqlite3 (npm) Aug 27, 2026
dyingman1 Credited to dyingman1
asyncssh has SCP Path Traversal to Arbitrary File Write High
CVE-2026-54591 was published for asyncssh (pip) Aug 26, 2026
Jaden-Furtado Credited to Jaden-Furtado and JadenFurtado JadenFurtado JadenFurtado
IzPack has Path Traversal in UnpackerBase that allows writing files outside the installation directory via malicious pack entries High
CVE-2026-54550 was published for org.codehaus.izpack:izpack-installer (Maven) Aug 26, 2026
sectroyer Credited to sectroyer
Whistle vulnerable to path traversal High
CVE-2026-55629 was published for whistle (npm) Aug 25, 2026
researchersongwu Credited to researchersongwu
Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts High
CVE-2026-55092 was published for github.com/aquasecurity/trivy (Go) Aug 25, 2026
ikkebr Credited to ikkebr
phpMyFAQ has Potential Authenticated Path Traversal in PDF Export Moderate
GHSA-88g4-74f3-63x9 was published for phpmyfaq/phpmyfaq (Composer) Aug 25, 2026
DomainXTech Credited to DomainXTech
browse-mcp has an arbitrary file write via unconfined download and state paths High
CVE-2026-55557 was published for browse-mcp (npm) Aug 25, 2026
novice-22 Credited to novice-22
Echo: Encoded slash (%2F) bypasses route-level protection and exposes static files High
CVE-2026-55677 was published for github.com/labstack/echo (Go) Aug 25, 2026
a-tt-om Credited to a-tt-om and oran-gugu oran-gugu oran-gugu
PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks High
CVE-2026-55540 was published for PraisonAI (pip) Aug 25, 2026
riodrwn Credited to riodrwn
Cloudreve's remote download file paths can escape the selected destination directory Moderate
GHSA-w8j7-39hp-8x59 was published for github.com/cloudreve/Cloudreve/v4 (Go) Aug 24, 2026
jinhao-huang Credited to jinhao-huang
Atlantis Workspace Handling has Path Traversal that Allows Out-of-Bounds Directory Deletion/Creation High
CVE-2026-64679 was published for github.com/runatlantis/atlantis (Go) Aug 21, 2026
shblue21 Credited to shblue21
Winter: Local File Inclusion through =include directives in JavaScript asset compilation Moderate
GHSA-2223-f22x-24cq was published for winter/wn-system-module (Composer) Aug 20, 2026
elmahy111 Credited to elmahy111
Winter: Local File Inclusion through @import directives in LESS compilation of backend customizable stylesheets and theme assets Moderate
CVE-2026-63179 was published for winter/wn-backend-module (Composer) Aug 20, 2026
hypnguyen1209 Credited to hypnguyen1209
therawdev Credited to therawdev, pxpm, and tabacitu pxpm pxpm
tabacitu tabacitu
Velero vulnerable to file path traversal when extracting from backup's tarball Moderate
CVE-2026-32637 was published for github.com/vmware-tanzu/velero (Go) Aug 20, 2026
KoreaSecurity Credited to KoreaSecurity
logto-tunnel serves files outside --experience-path via path traversal High
CVE-2026-63188 was published for @logto/tunnel (npm) Aug 19, 2026
pyuysig Credited to pyuysig
ProTip! Advisories are also available from the GraphQL API