GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
2,376 advisories
Filter by severity
NLTK: Uncontrolled search path when invoking the Graphviz 'dot' binary
High
CVE-2026-78680
was published
for
nltk
(pip)
Sep 1, 2026
MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False safety control bypassed by mlflow.statsmodels flavor — RCE via crafted model artifact
High
GHSA-gqvg-gmmx-x4hm
was published
for
mlflow
(pip)
Sep 1, 2026
RestrictedPython guard hooks can be shadowed via positional-only arguments
High
CVE-2026-55830
was published
for
RestrictedPython
(pip)
Aug 28, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
High
CVE-2026-55228
was published
for
Weblate
(pip)
Aug 28, 2026
Protego has exponential backtracking ReDoS in robots.txt URL wildcard matching
High
CVE-2026-55520
was published
for
Protego
(pip)
Aug 28, 2026
piccolo-admin has a privilege escalation issue - admin to superuser via session-token disclosure in GET /api/tables/sessions/.
High
CVE-2026-55485
was published
for
piccolo-admin
(pip)
Aug 28, 2026
WsgiDAV MySQL provider has a blind SQL injection
High
CVE-2026-55509
was published
for
WsgiDAV
(pip)
Aug 28, 2026
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
High
CVE-2026-54757
was published
for
compliance-trestle
(pip)
Aug 28, 2026
asyncssh has SCP Path Traversal to Arbitrary File Write
High
CVE-2026-54591
was published
for
asyncssh
(pip)
Aug 26, 2026
icalendar has Algorithmic Complexity in Equality
High
CVE-2026-55099
was published
for
icalendar
(pip)
Aug 25, 2026
Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access
High
CVE-2026-45019
was published
for
chainlit
(pip)
Aug 25, 2026
eml_parser vulnerable to DoS via deeply nested parens in Received headers
High
CVE-2026-55620
was published
for
eml_parser
(pip)
Aug 25, 2026
mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
High
GHSA-vwf3-4xxj-qg6h
was published
for
mcp-contextforge-gateway
(pip)
Aug 25, 2026
qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()`
High
CVE-2026-55585
was published
for
qwed
(pip)
Aug 25, 2026
djust authentication bypass: a login_required / on_mount LiveView mount redirect does not close the WebSocket, allowing an unauthenticated client to dispatch event-handler calls
High
CVE-2026-55571
was published
for
djust
(pip)
Aug 25, 2026
utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion
High
GHSA-8cp3-qxj6-px34
was published
for
utcp-http
(pip)
Aug 25, 2026
utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target
High
GHSA-9qhg-99ww-9mqc
was published
for
utcp-http
(pip)
Aug 25, 2026
PraisonAI: Origin-validation bypass (startswith prefix match) enables unauthenticated cross-site request forgery against the PraisonAI MCP HTTP server
High
CVE-2026-55532
was published
for
PraisonAI
(pip)
Aug 25, 2026
PraisonAI: Authentication fail-open in Recipe server allows unauthenticated access when API key or JWT auth is configured without a secret
High
CVE-2026-55533
was published
for
PraisonAI
(pip)
Aug 25, 2026
PraisonAI: [Auth Bypass] PraisonAI async Jobs API (`/api/v1/runs`) has no authentication — unauthenticated job execution, result theft, cancel and delete
High
CVE-2026-55539
was published
for
PraisonAI
(pip)
Aug 25, 2026
praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location
High
CVE-2026-55527
was published
for
praisonaiagents
(pip)
Aug 25, 2026
PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced
High
CVE-2026-55541
was published
for
PraisonAI
(pip)
Aug 25, 2026
PraisonAI: Webhook SSRF via DNS fail-open in `JobSubmitRequest.validate_webhook_url()` — bypass of CVE-2026-40114
High
CVE-2026-55537
was published
for
PraisonAI
(pip)
Aug 25, 2026
PraisonAI: [Auth Bypass] `praisonai serve agents --api-key` is silently ignored — agent-invocation routes (`POST /agents`, `POST /agents/{agent_name}`) run unauthenticated
High
CVE-2026-55538
was published
for
PraisonAI
(pip)
Aug 25, 2026
PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks
High
CVE-2026-55540
was published
for
PraisonAI
(pip)
Aug 25, 2026
ProTip!
Advisories are also available from the
GraphQL API