GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
340 advisories
Filter by severity
Payload: Incomplete validation during the upload file lifecycle
High
CVE-2026-105865
was published
for
payload
(npm)
Oct 7, 2026
Ghost: Remote Code Execution via Theme Translation Files
High
CVE-2026-105677
was published
for
ghost
(npm)
Oct 7, 2026
Backstage: Improper repository path validation in a Scaffolder backend module
High
CVE-2026-106560
was published
for
@backstage/plugin-scaffolder-backend-module-confluence-to-markdown
(npm)
Oct 7, 2026
Backstage has iImproper filesystem validation in Bitbucket pull-request scaffolder actions
High
CVE-2026-106486
was published
for
@backstage/plugin-scaffolder-backend-module-bitbucket-cloud
(npm)
Oct 7, 2026
Backstage has improper input validation in TechDocs Markdown extension configuration
High
CVE-2026-106557
was published
for
@backstage/plugin-techdocs-node
(npm)
Oct 7, 2026
Quasar Framework: Path Traversal / Arbitrary File Write via crafted Icon Genie profile
High
CVE-2026-106103
was published
for
@quasar/icongenie
(npm)
Oct 7, 2026
webpack-dev-middleware vulnerable to Path Traversal via non-slash-terminated publicPath
High
CVE-2026-76844
was published
for
webpack-dev-middleware
(npm)
Sep 29, 2026
Knowns Unrestricted Path Traversal leading to out-of-bounds arbitrary .md file read, write, and deletion in MCP Docs + Memory Tools
High
CVE-2026-86439
was published
for
knowns
(npm)
Sep 25, 2026
@roomi-fields/notebooklm-mcp has a path traversal in vault.batch tool that allows arbitrary file write outside intended vault directory
High
CVE-2026-61647
was published
for
@roomi-fields/notebooklm-mcp
(npm)
Sep 22, 2026
@openhop/server: Path Traversal in Flow ID File Operations
High
CVE-2026-59179
was published
for
@openhop/server
(npm)
Sep 9, 2026
OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree
High
GHSA-2q42-4q24-7rgv
was published
for
@typespec/compiler
(npm)
Sep 8, 2026
Duplicate Advisory: Knowns Unrestricted Path Traversal leading to out-of-bounds arbitrary .md file read, write, and deletion in MCP Docs + Memory Tools
High
GHSA-qjrq-cvv4-3g9w
was published
for
knowns
(npm)
Sep 8, 2026
•
withdrawn
CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
High
CVE-2026-75859
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes
High
CVE-2026-75914
was published
for
codewhale
(npm)
Sep 4, 2026
Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
High
CVE-2026-62680
was published
for
orval
(npm)
Sep 2, 2026
pnpm: Virtual store linker path traversal via unvalidated depPath name in lockfileToDepGraph
High
CVE-2026-82392
was published
for
pnpm
(npm)
Sep 2, 2026
pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on install
High
CVE-2026-82393
was published
for
pnpm
(npm)
Sep 2, 2026
pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project
High
GHSA-2rx9-3g3h-c2jv
was published
for
pnpm
(npm)
Sep 1, 2026
Whistle vulnerable to path traversal
High
CVE-2026-55629
was published
for
whistle
(npm)
Aug 25, 2026
browse-mcp has an arbitrary file write via unconfined download and state paths
High
CVE-2026-55557
was published
for
browse-mcp
(npm)
Aug 25, 2026
Duplicate Advisory: webpack-dev-middleware vulnerable to Path Traversal via non-slash-terminated publicPath
High
GHSA-p3f5-w63m-mxph
was published
for
webpack-dev-middleware
(npm)
Aug 24, 2026
•
withdrawn
logto-tunnel serves files outside --experience-path via path traversal
High
CVE-2026-63188
was published
for
@logto/tunnel
(npm)
Aug 19, 2026
claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
High
GHSA-rr55-jp92-8wp2
was published
for
claude-faf-mcp
(npm)
Aug 19, 2026
faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
High
GHSA-j4r7-8ph4-43g3
was published
for
faf-mcp
(npm)
Aug 19, 2026
grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools
High
GHSA-cc2g-gq8c-r332
was published
for
grok-faf-mcp
(npm)
Aug 19, 2026
ProTip!
Advisories are also available from the
GraphQL API