GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,508
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
179 advisories
Filter by severity
Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts
Moderate
GHSA-957r-qf9p-67xw
was published
for
craftcms/cms
(Composer)
Aug 6, 2026
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due...
High
Unreviewed
CVE-2026-17630
was published
Aug 5, 2026
ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url() validator in...
High
Unreviewed
CVE-2026-71259
was published
Aug 5, 2026
Ghost: Private IP filtering bypass to make server-side requests to internal services
Moderate
CVE-2026-53944
was published
for
ghost
(npm)
Aug 4, 2026
Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
Critical
CVE-2026-70470
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
High
CVE-2026-69263
was published
for
flowise
(npm)
Aug 4, 2026
NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass
Moderate
CVE-2026-52888
was published
for
@nocobase/plugin-collection-sql
(npm)
Jul 28, 2026
GitPython: Incomplete unsafe_git_clone_options denylist omits --template enabling arbitrary command execution via clone hooks
High
GHSA-6p8h-3wgx-97gf
was published
for
GitPython
(pip)
Jul 24, 2026
In NLnet Labs Unbound up to and including version 1.25.1, when 'unwanted-reply-threshold' is...
Moderate
Unreviewed
CVE-2026-50251
was published
Jul 22, 2026
Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
Low
GHSA-5qhf-9phg-95m2
was published
for
loofah
(RubyGems)
Jul 21, 2026
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist
High
GHSA-2f96-g7mh-g2hx
was published
for
GitPython
(pip)
Jul 21, 2026
SVGO removeScripts plugin leaves some executable scripts intact
High
GHSA-2p49-hgcm-8545
was published
for
svgo
(npm)
Jul 21, 2026
DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.
Low
GHSA-c2j3-45gr-mqc4
was published
for
dompurify
(npm)
Jul 21, 2026
Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references
Low
GHSA-8whx-365g-h9vv
was published
for
loofah
(RubyGems)
Jul 21, 2026
Mistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and chained schemes that historically chain to `javascript:` execution
Moderate
CVE-2026-59929
was published
for
mistune
(pip)
Jul 20, 2026
Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute...
High
Unreviewed
CVE-2026-63108
was published
Jul 20, 2026
IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code...
High
Unreviewed
CVE-2026-13448
was published
Jul 17, 2026
OpenClaw versions before 2026.6.6 contain an environment variable filtering vulnerability in host...
High
Unreviewed
CVE-2026-62203
was published
Jul 17, 2026
OpenClaw versions before 2026.6.1 contain a flaw in host exec environment filtering that could...
High
Unreviewed
CVE-2026-62200
was published
Jul 14, 2026
OpenClaw versions before 2026.6.6 contain a flaw in host exec environment filtering that can miss...
High
Unreviewed
CVE-2026-62199
was published
Jul 14, 2026
SiYuan: Stored XSS in Bazaar marketplace via package README event handlers
High
CVE-2026-54070
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Jul 10, 2026
`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes
High
CVE-2026-49825
was published
for
lxml_html_clean
(pip)
Jul 8, 2026
OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv...
High
Unreviewed
CVE-2026-59261
was published
Jul 8, 2026
Trail of Bits fickling versions up to and including 0.1.10 do not include the Python standard...
High
Unreviewed
CVE-2026-14534
was published
Jul 4, 2026
OpenClaw: PowerShell encoded-command aliases could miss exec allowlist checks
High
GHSA-j472-gf56-x589
was published
for
openclaw
(npm)
Jul 2, 2026
ProTip!
Advisories are also available from the
GraphQL API