GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,894
Maven
5,000+
npm
5,000+
NuGet
963
pip
5,000+
Pub
13
RubyGems
1,061
Rust
1,373
Swift
54
Unreviewed advisories
All unreviewed
5,000+
640 advisories
Filter by severity
Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the Host
Critical
CVE-2026-46703
was published
for
@boxlite-ai/boxlite
(Go)
May 21, 2026
BoxLite: Permission Bypass Allows Modification of Read-Only Files
Critical
CVE-2026-46695
was published
for
@boxlite-ai/boxlite
(Go)
May 21, 2026
Mlflow: Command Injection when serving models with enable_mlserver=True
Critical
CVE-2026-0596
was published
for
mlflow
(pip)
Mar 31, 2026
SaltStack Salt Directory traversal vulnerability in minion id validation
Critical
CVE-2017-12791
was published
for
salt
(pip)
May 17, 2022
Malicious code in guardrails-ai 0.10.1 (supply chain compromise)
Critical
CVE-2026-45758
was published
for
guardrails-ai
(pip)
May 19, 2026
rok Python ProxyShare can be used as an SSRF proxy through absolute URL paths
Critical
CVE-2026-45568
was published
for
zrok
(pip)
May 19, 2026
PySyft server-side arbitrary Python execution after code approval
Critical
CVE-2026-31220
was published
for
syft
(pip)
May 12, 2026
Malicious dropper in mistralai 2.4.6 PyPI package
Critical
GHSA-wx9m-wx4f-4cmg
was published
for
mistralai
(pip)
May 18, 2026
pgAdmin 4 server mode has an authorization vulnerability affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules
Critical
CVE-2026-7813
was published
for
pgadmin4
(pip)
May 11, 2026
Open WebUI has an LDAP Empty Password Authentication Bypass
Critical
CVE-2026-44551
was published
for
open-webui
(pip)
May 8, 2026
utcp-cli Vulnerable to Command Injection via Unsanitized Argument Substitution in CLI Communication Protocol
Critical
CVE-2026-45369
was published
for
utcp-cli
(pip)
May 14, 2026
Dulwich Arbitrary code execution via commit with directory path starting with .git
Critical
CVE-2014-9706
was published
for
dulwich
(pip)
May 17, 2022
ArchiveBox Vulnerable to RCE via unvalidated per-crawl config overrides in AddView
Critical
CVE-2026-42601
was published
for
archivebox
(pip)
May 4, 2026
Compromise of PyTorch Lightning PyPi Package Versions
Critical
CVE-2026-44484
was published
for
pytorch-lightning
(pip)
May 7, 2026
misp-modules website - Missing CSRF protection in the website home blueprint
Critical
CVE-2026-44364
was published
for
misp-modules
(pip)
May 6, 2026
wger: cross-tenant password reset and plaintext disclosure via gym=None bypass
Critical
CVE-2026-43948
was published
for
wger
(pip)
May 6, 2026
django-s3file is vulnerable to relative path traversal
Critical
CVE-2026-42196
was published
for
django-s3file
(pip)
May 5, 2026
Langflow Knowledge Bases API is Vulnerable to Path Traversal
Critical
CVE-2026-42048
was published
for
langflow
(pip)
May 5, 2026
FireFighter has unauthenticated SSRF in its Raid jira_bot endpoint that allows IAM credential theft
Critical
CVE-2026-42864
was published
for
firefighter-incident
(pip)
May 5, 2026
Sentry's improper authentication on SAML SSO process allows user identity linking
Critical
CVE-2026-42354
was published
for
sentry
(pip)
Apr 30, 2026
PraisonAI has an incomplete fix for CVE-2026-34935 - OS Command Injection
Critical
CVE-2026-41497
was published
for
praisonai
(pip)
Apr 17, 2026
AstrBot is vulnerable to RCE with hard-coded JWT signing keys
Critical
CVE-2025-55449
was published
for
astrbot
(pip)
Nov 14, 2025
LiteLLM has SQL Injection in Proxy API key verification
Critical
CVE-2026-42208
was published
for
litellm
(pip)
Apr 24, 2026
PraisonAI MCP `tools/call` path-traversal => RCE via Python `.pth` injection
Critical
CVE-2026-44336
was published
for
PraisonAI
(pip)
May 11, 2026
PraisonAI Vulnerable to Remote Code Execution via YAML Deserialization in Agent Definition Loading
Critical
CVE-2026-39890
was published
for
praisonai
(pip)
Apr 8, 2026
ProTip!
Advisories are also available from the
GraphQL API