GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
61
GitHub Actions
50
Go
3,821
Maven
5,000+
npm
5,000+
NuGet
939
pip
5,000+
Pub
13
RubyGems
1,059
Rust
1,357
Swift
54
Unreviewed advisories
All unreviewed
5,000+
5,090 advisories
Filter by severity
Microsoft APM: Windows absolute-path tar member overwrite during legacy-bundle probing in `apm install`
Moderate
CVE-2026-46383
was published
for
apm-cli
(pip)
May 15, 2026
Weblate: Stored HTML injection in editor search preview
Moderate
CVE-2026-45106
was published
for
weblate
(pip)
May 15, 2026
Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File Read via `%2F`-Encoded Separator
High
CVE-2026-44716
was published
for
pipecat-ai
(pip)
May 15, 2026
python-utcp: Full Process Environment Exposed to CLI Subprocess - Secrets Leakage via Command Injection
High
CVE-2026-45370
was published
for
utcp-cli
(pip)
May 14, 2026
utcp-cli Vulnerable to Command Injection via Unsanitized Argument Substitution in CLI Communication Protocol
Critical
CVE-2026-45369
was published
for
utcp-cli
(pip)
May 14, 2026
Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts
High
CVE-2026-45675
was published
for
open-webui
(pip)
May 14, 2026
Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed
High
CVE-2026-45672
was published
for
open-webui
(pip)
May 14, 2026
Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion
High
CVE-2026-45671
was published
for
open-webui
(pip)
May 14, 2026
Open WebUI: Unauthenticated endpoint can trigger embedding generation (cost/DoS)
Moderate
CVE-2026-45667
was published
for
open-webui
(pip)
May 14, 2026
Open WebUI has an Indirect Object Reference (IDOR) in user notes
Moderate
CVE-2026-45666
was published
for
open-webui
(pip)
May 14, 2026
Open WebUI: Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints
High
CVE-2026-45402
was published
for
open-webui
(pip)
May 14, 2026
Open WebUI vulnerable to stored XSS via OAuth picture claim stored as SVG data URI in profile_image_url
High
GHSA-3wgj-c2hg-vm6q
was published
for
open-webui
(pip)
May 14, 2026
Open WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)
High
CVE-2026-45401
was published
for
open-webui
(pip)
May 14, 2026
Open WebUI has a Server-Side Request Forgery (SSRF) bypass in `validate_url`
High
CVE-2026-45400
was published
for
open-webui
(pip)
May 14, 2026
Open WebUI: Low-privilege authenticated users can enumerate and stop global background tasks, causing system-wide chat disruption
High
CVE-2026-45399
was published
for
open-webui
(pip)
May 14, 2026
Open WebUI Vulnerable to IDOR: Retrieval API Bypasses Knowledge Base Access Controls
High
CVE-2026-45398
was published
for
open-webui
(pip)
May 14, 2026
Open WebUI Vulnerable to Unauthenticated RAG Configuration Disclosure
Moderate
CVE-2026-45397
was published
for
open-webui
(pip)
May 14, 2026
Open WebUI: Mass Assignment via FeedbackForm extra=allow Allows Feedback User ID Spoofing and Evaluation Data Manipulation
Moderate
CVE-2026-45396
was published
for
open-webui
(pip)
May 14, 2026
Open WebUI: Sharing models for others to use (read permission) also exposes model details (system prompt leakage)
Moderate
CVE-2026-45387
was published
for
open-webui
(pip)
May 14, 2026
Open WebUI has an IDOR vulnerability in the pin_channel_message API endpoint
Moderate
CVE-2026-45386
was published
for
open-webui
(pip)
May 14, 2026
Open WebUI has an IDOR vulnerability in the update_message_by_id API endpoint
Moderate
CVE-2026-45385
was published
for
open-webui
(pip)
May 14, 2026
Open WebUI: Authenticated users can bypass model access control via exposed query parameter [AI-ASSISTED]
Moderate
CVE-2026-45365
was published
for
open-webui
(pip)
May 14, 2026
Open WebUI Exposes System Prompt to Regular User [Non-Admin]
Moderate
CVE-2026-45351
was published
for
open-webui
(pip)
May 14, 2026
Open WebUI's chat completion API allows tool restrictions to be bypassed
High
CVE-2026-45350
was published
for
open-webui
(pip)
May 14, 2026
Open WebUI has Broken Access Control for Completions API
High
CVE-2026-45349
was published
for
open-webui
(pip)
May 14, 2026
ProTip!
Advisories are also available from the
GraphQL API