Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

245 advisories

Loading
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data High
CVE-2026-54757 was published for compliance-trestle (pip) Aug 28, 2026
EclipsSec Credited to EclipsSec
qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()` High
CVE-2026-55585 was published for qwed (pip) Aug 25, 2026
EQSTLab Credited to EQSTLab
qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input Critical
CVE-2026-55546 was published for qwed-mcp (pip) Aug 25, 2026
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code High
CVE-2026-55522 was published for PraisonAI (pip) Aug 25, 2026
rexpository Credited to rexpository
Hydra: hydra.utils.instantiate with untrusted config can lead to code execution High
CVE-2026-68508 was published for hydra-core (pip) Aug 21, 2026
guwu1017 Credited to guwu1017
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted High
CVE-2026-53951 was published for copier (pip) Aug 19, 2026
seankohjs Credited to seankohjs and sisp sisp sisp
sqlparse: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes Moderate
CVE-2026-59894 was published for sqlparse (pip) Aug 17, 2026
7thParkk Credited to 7thParkk
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install` High
CVE-2026-55071 was published for stata-mcp (pip) Aug 12, 2026
EQSTLab Credited to EQSTLab and useworld useworld useworld
manus-use Credited to manus-use and BarakSrour BarakSrour BarakSrour
thegr1ffyn Credited to thegr1ffyn
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field High
CVE-2026-54653 was published for datamodel-code-generator (pip) Jul 28, 2026
thegr1ffyn Credited to thegr1ffyn
thegr1ffyn Credited to thegr1ffyn
thegr1ffyn Credited to thegr1ffyn, mhamzakhattak, and Muzammilxi mhamzakhattak mhamzakhattak
Muzammilxi Muzammilxi
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description High
CVE-2026-54621 was published for datamodel-code-generator (pip) Jul 28, 2026
thegr1ffyn Credited to thegr1ffyn
thegr1ffyn Credited to thegr1ffyn
waiveyk Credited to waiveyk and Classic298 Classic298 Classic298
SSJCorpSec Credited to SSJCorpSec, thesecguy45, sfwani, and bveeramani thesecguy45 thesecguy45
sfwani sfwani bveeramani bveeramani
LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks Low
CVE-2026-59821 was published for litellm (pip) Jul 22, 2026
yaaras Credited to yaaras
YLChen-007 Credited to YLChen-007
hackkim Credited to hackkim and matte1782 matte1782 matte1782
Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args Critical
GHSA-r253-r9jw-qg44 was published for crawl4ai (pip) Jun 18, 2026
hoanggxyuuki Credited to hoanggxyuuki
rexpository Credited to rexpository
PraisonAI: Jobs API exposes agent-execution endpoints with no authentication Critical
CVE-2026-57131 was published for praisonai (pip) Jun 18, 2026
SnailSploit Credited to SnailSploit
Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution Critical
CVE-2026-56266 was published for crawl4ai (pip) Jun 16, 2026
August829 Credited to August829
ProTip! Advisories are also available from the GraphQL API