GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
50
GitHub Actions
50
Go
3,673
Maven
5,000+
npm
5,000+
NuGet
932
pip
4,891
Pub
13
RubyGems
1,051
Rust
1,315
Swift
53
Unreviewed advisories
All unreviewed
5,000+
77 advisories
Filter by severity
changedetection.io has an Arbitrary Local File Read via a crafted backup restore
High
CVE-2026-43891
was published
for
changedetection.io
(pip)
May 5, 2026
@evomap/evolver: Path Traversal in `evolver fetch` default-branch `safeId` allows Hub-controlled overwrite of project files (RCE)
High
GHSA-cfcj-hqpf-hccf
was published
for
@evomap/evolver
(npm)
May 5, 2026
Duplicate Advisory: OpenClaw: Webchat media embedding enforces local-root containment for tool-result files
Moderate
GHSA-qc5j-2mqx-x83q
was published
for
openclaw
(npm)
Apr 20, 2026
•
withdrawn
i18next-fs-backend: Path traversal via unsanitised lng/ns allows arbitrary file read/overwrite
High
CVE-2026-41693
was published
for
i18next-fs-backend
(npm)
Apr 22, 2026
Pebble has Arbitrary Local File Inclusion (LFI) Vulnerability via `include` macro
High
CVE-2025-1686
was published
for
io.pebbletemplates:pebble
(Maven)
Feb 28, 2025
nbconvert has an Arbitrary File Write via Path Traversal in Cell Attachment Filenames
Moderate
CVE-2026-39377
was published
for
nbconvert
(pip)
Apr 21, 2026
OpenClaw: Webchat media embedding enforces local-root containment for tool-result files
High
GHSA-mr34-9552-qr95
was published
for
openclaw
(npm)
Apr 17, 2026
Paperclip: Arbitrary File Read via Agent-Controlled adapterConfig.instructionsFilePath
Moderate
GHSA-3pw3-v88x-xj24
was published
for
@paperclipai/shared
(npm)
Apr 16, 2026
External Control of File Name or Path in h2oai/h2o-3
Critical
CVE-2023-6569
was published
for
h2o
(pip)
Dec 14, 2023
Rembg has a Path Traversal via Custom Model Loading
Moderate
CVE-2026-40086
was published
for
rembg
(pip)
Apr 10, 2026
Gotenberg has incomplete fix for ExifTool arbitrary file write: case-insensitive bypass and missing HardLink/SymLink tags
High
GHSA-qmwh-9m9c-h36m
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
Apr 7, 2026
Ferret: Path Traversal in IO::FS::WRITE allows arbitrary file write when scraping malicious websites
High
CVE-2026-34783
was published
for
github.com/MontFerret/ferret
(Go)
Apr 1, 2026
SillyTavern has a path traversal in `/api/chats/import` allows arbitrary file write outside intended chat directory
High
CVE-2026-34522
was published
for
sillytavern
(npm)
Apr 1, 2026
@tinacms/graphql has Path Traversal that leads to overwrite of arbitrary files
High
CVE-2026-33949
was published
for
@tinacms/graphql
(npm)
Mar 30, 2026
baserCMS Path Traversal Leads to Arbitrary File Write and RCE via Theme File API
High
CVE-2026-30940
was published
for
baserproject/basercms
(Composer)
Mar 31, 2026
Nginx Configuration Directory Vulnerable to Recursive Deletion via Improper Path Validation
Moderate
CVE-2026-33027
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Mar 30, 2026
@mobilenext/mobile-mcp alllows arbitrary file write via Path Traversal in mobile screen capture tools
High
CVE-2026-33989
was published
for
@mobilenext/mobile-mcp
(npm)
Mar 27, 2026
Langflow has an Arbitrary File Write (RCE) via v2 API
Critical
CVE-2026-33309
was published
for
langflow
(pip)
Mar 19, 2026
AVideo has an authenticated arbitrary local file read via `chunkFile` path injection in `aVideoEncoder.json.php`
High
CVE-2026-33354
was published
for
wwbn/avideo
(Composer)
Mar 19, 2026
Siyuan has an Unauthenticated Arbitrary File Read via Path Traversal
High
CVE-2026-33476
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 20, 2026
Dompdf's usage of vulnerable version of phenx/php-svg-lib leads to restriction bypass and potential RCE
Critical
GHSA-97m3-52wr-xvv2
was published
for
phenx/php-svg-lib
(Composer)
Feb 22, 2024
SiYuan importSY/importZipMd: path traversal via multipart filename enables arbitrary file write
High
CVE-2026-32749
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Mar 16, 2026
php-svg-lib lacks path validation on font through SVG inline styles
Moderate
CVE-2024-25117
was published
for
phenx/php-svg-lib
(Composer)
Feb 21, 2024
MCP Atlassian has an arbitrary file write leading to arbitrary code execution via unconstrained download_path in confluence_download_attachment
Critical
CVE-2026-27825
was published
for
mcp-atlassian
(pip)
Mar 10, 2026
OpenClaw has an arbitrary transcript path file write via gateway sessionFile
High
CVE-2026-28459
was published
for
openclaw
(npm)
Feb 17, 2026
ProTip!
Advisories are also available from the
GraphQL API