GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
85 advisories
Filter by severity
ActiveRecord::Tenanted::Storage::DiskService#path_for has a possible path traversal
Low
GHSA-pmwx-rm49-xv39
was published
for
activerecord-tenanted
(RubyGems)
Jul 29, 2026
hsweb-framework has a Path Traversal issue
Low
CVE-2026-11470
was published
for
org.hswebframework.web:hsweb-system-file
(Maven)
Jun 8, 2026
Dompdf: Chroot Validation Bypass
Low
CVE-2026-55554
was published
for
dompdf/dompdf
(Composer)
Jul 22, 2026
@babel/core: Arbitrary File Read via sourceMappingURL Comment
Low
CVE-2026-49356
was published
for
@babel/core
(npm)
Jun 15, 2026
Craft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file read
Low
GHSA-c43v-4cr8-6mvp
was published
for
craftcms/cms
(Composer)
Jul 9, 2026
land.oras:oras-java-sdk: Symlink-based path traversal in ArchiveUtils.untar / unzip allows arbitrary file write outside extraction directory
Low
GHSA-j6hm-v3x2-qv6j
was published
for
land.oras:oras-java-sdk
(Maven)
Jul 1, 2026
@cardano402/mcp-server missing spending limits, LAN-exposed HTTP transport, and SSRF via catalog.server.url
Low
GHSA-rp72-5v5q-2446
was published
for
@cardano402/mcp-server
(npm)
Jun 26, 2026
BBOT: Symlink-Following Arbitrary Write via github_workflows Module
Low
CVE-2026-12567
was published
for
bbot
(pip)
Jun 18, 2026
esbuild allows arbitrary file read when running the development server on Windows
Low
GHSA-g7r4-m6w7-qqqr
was published
for
esbuild
(npm)
Jun 12, 2026
TYPO3 CMS has Broken Access Control in its File Abstraction Layer
Low
CVE-2026-49738
was published
for
typo3/cms-core
(Composer)
Jun 12, 2026
Dulwich doesn't sanitize commit subjects in `porcelain.format_patch`
Low
CVE-2026-47712
was published
for
dulwich
(pip)
Jun 8, 2026
sudo-rs Session File Relative Path Traversal vulnerability
Low
CVE-2023-42456
was published
for
sudo-rs
(Rust)
Sep 21, 2023
Magic Wormhole: receive, with --output pointing at an existing directory can be path-traversed
Low
CVE-2026-42448
was published
for
magic-wormhole
(pip)
May 6, 2026
Omni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematic
Low
CVE-2026-45723
was published
for
github.com/siderolabs/omni
(Go)
Jun 5, 2026
AstrBot: File upload vulnerability in the function post_file of the file astrbot/dashboard/routes/chat.py
Low
CVE-2026-8754
was published
for
AstrBot
(pip)
May 17, 2026
androidqf: APK download Path Traversal in device APK paths
Low
GHSA-763j-3p5v-jfc6
was published
for
github.com/mvt-project/androidqf
(Go)
May 21, 2026
androidqf: Zip entry Name Injection in APK bundle (Zip Slip for zip consumers)
Low
GHSA-jf2q-463c-6f52
was published
for
github.com/mvt-project/androidqf
(Go)
May 21, 2026
@puchunjie/doc-tools-mcp has a Path Traversal Issue
Low
CVE-2026-7738
was published
for
@puchunjie/doc-tools-mcp
(npm)
May 4, 2026
Ollama is Vulnerable to Path Traversal
Low
CVE-2026-7020
was published
for
github.com/ollama/ollama
(Go)
Apr 26, 2026
auth-js Vulnerable to Insecure Path Routing from Malformed User Input
Low
CVE-2025-48370
was published
for
@supabase/auth-js
(npm)
May 27, 2025
melange has Path Traversal via .PKGINFO in --persist-lint-results
Low
CVE-2026-29051
was published
for
chainguard.dev/melange
(Go)
Apr 23, 2026
Poetry has Path Traversal in tar extraction on Python 3.10.0 - 3.10.12 and 3.11.0 - 3.11.4
Low
CVE-2026-41140
was published
for
poetry
(pip)
Apr 22, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
Low
GHSA-h39g-6x3c-7fq9
was published
for
Zio
(NuGet)
Apr 18, 2026
uv vulnerable to arbitrary file deletion through RECORD entries
Low
GHSA-pjjw-68hj-v9mw
was published
for
uv
(pip)
Apr 10, 2026
Zoraxy: Authenticated Path Traversal in Config Import leads to RCE
Low
CVE-2026-33529
was published
for
github.com/tobychui/zoraxy
(Go)
Mar 25, 2026
ProTip!
Advisories are also available from the
GraphQL API