GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
153 advisories
Filter by severity
Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive
Moderate
CVE-2026-50558
was published
for
penelope-shell-handler
(pip)
Jul 29, 2026
PyMdown Extensions: Path traversal in the b64 extension lets <img src> read files outside base_path
Moderate
CVE-2026-61632
was published
for
pymdown-extensions
(pip)
Jul 24, 2026
LiteLLM: Arbitrary file write via path traversal in Skills archive extraction
Moderate
CVE-2026-59820
was published
for
litellm
(pip)
Jul 22, 2026
Mistune: Arbitrary File Read via Include directive path traversal
Moderate
CVE-2026-59924
was published
for
mistune
(pip)
Jul 20, 2026
changedetection.io is vulnerable to unauthenticated static path traversal
Moderate
CVE-2026-25527
was published
for
changedetection.io
(pip)
Jul 20, 2026
PRoot-Distro has Path Traversal in proot-distro copy — Arbitrary Read, Write, and Persistent Code Execution Outside Container Rootfs
Moderate
GHSA-mfr4-mq8w-vmg6
was published
for
proot-distro
(pip)
Jul 17, 2026
psd-tools vulnerable to arbitrary file write via smart-object filename
Moderate
CVE-2026-49836
was published
for
psd-tools
(pip)
Jul 9, 2026
Rattler vulnerable to package cache path traversal via conda package build string
Moderate
CVE-2026-53956
was published
for
py_rattler
(pip)
Jul 9, 2026
LangGraph SDK has unsafe URL path construction
Moderate
CVE-2026-48776
was published
for
langgraph-sdk
(pip)
Jun 25, 2026
motionEye has an Arbitrary File Read via Path Traversal in Picture/Movie Preview Endpoint
Moderate
CVE-2026-31978
was published
for
motioneye
(pip)
Jun 22, 2026
pydantic-settings: NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size
Moderate
GHSA-4xgf-cpjx-pc3j
was published
for
pydantic-settings
(pip)
Jun 19, 2026
Anki: User scripts in iframes have access to the internal Anki API
Moderate
GHSA-cw6h-ffmh-x6vh
was published
for
aqt
(pip)
Jun 19, 2026
BBOT: Arbitrary File Write in postman_download Module
Moderate
CVE-2026-12568
was published
for
bbot
(pip)
Jun 18, 2026
BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284
Moderate
CVE-2026-12565
was published
for
bbot
(pip)
Jun 18, 2026
Open WebUI: Sibling-Prefix Path Traversal via /cache/{path}
Moderate
CVE-2026-54014
was published
for
open-webui
(pip)
Jun 17, 2026
Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint
Moderate
CVE-2026-42867
was published
for
langflow
(pip)
Jun 16, 2026
LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders
Moderate
CVE-2026-55443
was published
for
langchain
(pip)
Jun 16, 2026
Docling: Potential Path Traversal via LaTeX \includegraphics and \input Commands
Moderate
CVE-2026-44022
was published
for
docling
(pip)
Jun 3, 2026
pip: Path traversal in console_scripts/gui_scripts entry point names allows installing scripts outside of target directory
Moderate
CVE-2026-8643
was published
for
pip
(pip)
Jun 1, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write)
Moderate
CVE-2026-47425
was published
for
py-rattler
(pip)
Jun 1, 2026
uv is vulnerable to arbitrary file write through entry point names
Moderate
GHSA-4gg8-gxpx-9rph
was published
for
uv
(pip)
May 29, 2026
Shamefile has an arbitrary file read via shamefile.yaml in shame next
Moderate
CVE-2026-47144
was published
for
shamefile
(npm)
May 28, 2026
compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal
Moderate
CVE-2026-45774
was published
for
compliance-trestle
(pip)
May 28, 2026
AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal username
Moderate
CVE-2026-45309
was published
for
asyncssh
(pip)
May 27, 2026
Mobile Verification Toolkit (MVT): Path Traversal via unsanitized File identifiers in iOS Backup processing
Moderate
CVE-2026-46486
was published
for
mvt
(pip)
May 21, 2026
ProTip!
Advisories are also available from the
GraphQL API