Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

153 advisories

Loading
Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive Moderate
CVE-2026-50558 was published for penelope-shell-handler (pip) Jul 29, 2026
strikoder Credited to strikoder
PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path Moderate
CVE-2026-61632 was published for pymdown-extensions (pip) Jul 24, 2026
aqilFauzi121 Credited to aqilFauzi121
LiteLLM: Arbitrary file write via path traversal in Skills archive extraction Moderate
CVE-2026-59820 was published for litellm (pip) Jul 22, 2026
Mistune: Arbitrary File Read via Include directive path traversal Moderate
CVE-2026-59924 was published for mistune (pip) Jul 20, 2026
0x5t4l1n Credited to 0x5t4l1n
changedetection.io is vulnerable to unauthenticated static path traversal Moderate
CVE-2026-25527 was published for changedetection.io (pip) Jul 20, 2026
minnggyuu Credited to minnggyuu
x0root Credited to x0root
psd-tools vulnerable to arbitrary file write via smart-object filename Moderate
CVE-2026-49836 was published for psd-tools (pip) Jul 9, 2026
seankohjs Credited to seankohjs and yueyueL yueyueL yueyueL
Rattler vulnerable to package cache path traversal via conda package build string Moderate
CVE-2026-53956 was published for py_rattler (pip) Jul 9, 2026
LangGraph SDK has unsafe URL path construction Moderate
CVE-2026-48776 was published for langgraph-sdk (pip) Jun 25, 2026
pucagit Credited to pucagit
motionEye has an Arbitrary File Read via Path Traversal in Picture/Movie Preview Endpoint Moderate
CVE-2026-31978 was published for motioneye (pip) Jun 22, 2026
Neosprings Credited to Neosprings, blue-pho3nix, and MichaIng blue-pho3nix blue-pho3nix
MichaIng MichaIng
Faze-up Credited to Faze-up
Anki: User scripts in iframes have access to the internal Anki API Moderate
GHSA-cw6h-ffmh-x6vh was published for aqt (pip) Jun 19, 2026
Bankde Credited to Bankde
BBOT: Arbitrary File Write in postman_download Module Moderate
CVE-2026-12568 was published for bbot (pip) Jun 18, 2026
nedlir Credited to nedlir
BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284 Moderate
CVE-2026-12565 was published for bbot (pip) Jun 18, 2026
sondt99 Credited to sondt99
Open WebUI: Sibling-Prefix Path Traversal via /cache/{path} Moderate
CVE-2026-54014 was published for open-webui (pip) Jun 17, 2026
AAtomical Credited to AAtomical and Classic298 Classic298 Classic298
Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint Moderate
CVE-2026-42867 was published for langflow (pip) Jun 16, 2026
nekros1xx Credited to nekros1xx, Cristhianzl, andifilhohub, and AntonioABLima Cristhianzl Cristhianzl
andifilhohub andifilhohub AntonioABLima AntonioABLima
LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders Moderate
CVE-2026-55443 was published for langchain (pip) Jun 16, 2026
Mistz1 Credited to Mistz1 and deprrous deprrous deprrous
Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands Moderate
CVE-2026-44022 was published for docling (pip) Jun 3, 2026
brodmart Credited to brodmart
rattler has an entry-point path traversal in noarch:python install (arbitrary file write) Moderate
CVE-2026-47425 was published for py-rattler (pip) Jun 1, 2026
berkant-koc Credited to berkant-koc
uv is vulnerable to arbitrary file write through entry point names Moderate
GHSA-4gg8-gxpx-9rph was published for uv (pip) May 29, 2026
zsol Credited to zsol and zanieb zanieb zanieb
Shamefile has an arbitrary file read via shamefile.yaml in shame next Moderate
CVE-2026-47144 was published for shamefile (npm) May 28, 2026
BKDDFS Credited to BKDDFS
compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal Moderate
CVE-2026-45774 was published for compliance-trestle (pip) May 28, 2026
AnistoMejin Credited to AnistoMejin and yantongggg yantongggg yantongggg
0xHunSec Credited to 0xHunSec
ProTip! Advisories are also available from the GraphQL API