Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

38 advisories

Loading
Plate: SSRF with response disclosure in DOCX image embedding High
CVE-2026-65842 was published for @platejs/docx-io (npm) Sep 2, 2026
EQSTLab Credited to EQSTLab and min8282 min8282 min8282
qwed Vulnerable to Authenticated Remote Code Execution via Unsafe SymPy `parse_expr()` High
CVE-2026-55585 was published for qwed (pip) Aug 25, 2026
EQSTLab Credited to EQSTLab
utcp-http has an OAuth2 `tokenUrl` Trust Boundary Bypass in OpenAPI Conversion High
GHSA-8cp3-qxj6-px34 was published for utcp-http (pip) Aug 25, 2026
EQSTLab Credited to EQSTLab and 232-323 232-323 232-323
mcp-shell has a Secure Mode Allowlist Bypass via Default `/bin/bash` Executable High
CVE-2026-55581 was published for github.com/sonirico/mcp-shell (Go) Aug 25, 2026
EQSTLab Credited to EQSTLab, useworld, and sonirico useworld useworld
sonirico sonirico
mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias High
CVE-2026-55582 was published for github.com/sonirico/mcp-shell (Go) Aug 25, 2026
EQSTLab Credited to EQSTLab and sonirico sonirico sonirico
vouch-proxy has an Unbounded Multipart Cookie Allocation DoS High
CVE-2026-55149 was published for github.com/vouch/vouch-proxy (Go) Aug 20, 2026
EQSTLab Credited to EQSTLab
EQSTLab Credited to EQSTLab, min8282, and 7thParkk min8282 min8282
7thParkk 7thParkk
EQSTLab Credited to EQSTLab
MCP-for-Stata: Stata Command Injection via Unsanitized `package` in `ado_package_install` High
CVE-2026-55071 was published for stata-mcp (pip) Aug 12, 2026
EQSTLab Credited to EQSTLab and useworld useworld useworld
`@dynatrace-oss/dynatrace-mcp-server` has Unauthenticated HTTP MCP Tool Invocation High
GHSA-p7w7-4929-vpj5 was published for @dynatrace-oss/dynatrace-mcp-server (npm) Jul 31, 2026
EQSTLab Credited to EQSTLab, 232-323, and yotampe-pluto 232-323 232-323
yotampe-pluto yotampe-pluto
pytonapi has a Webhook Custom Path Authentication Bypass High
CVE-2026-54635 was published for pytonapi (pip) Jul 28, 2026
EQSTLab Credited to EQSTLab
@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion High
CVE-2026-73561 was published for @anephenix/hub (npm) Jul 24, 2026
EQSTLab Credited to EQSTLab and min8282 min8282 min8282
kin-openapi: ValidationHandler.Load() Fail-Open Authentication Bypass via NoopAuthenticationFunc Default Critical
GHSA-r277-6w6q-xmqw was published for github.com/getkin/kin-openapi (Go) Jul 24, 2026
EQSTLab Credited to EQSTLab and 232-323 232-323 232-323
OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header High
CVE-2026-59892 was published for @opentelemetry/propagator-jaeger (npm) Jul 21, 2026
EQSTLab Credited to EQSTLab and pichlermarc pichlermarc pichlermarc
meta-ads-mcp: X-Pipeboard-Token Header Auth Bypass Reuses Operator Meta Token High
CVE-2026-54547 was published for meta-ads-mcp (pip) Jul 17, 2026
EQSTLab Credited to EQSTLab
EQSTLab Credited to EQSTLab and useworld useworld useworld
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store High
CVE-2026-54447 was published for garminconnect (pip) Jul 15, 2026
EQSTLab Credited to EQSTLab and 232-323 232-323 232-323
NetLicensing-MCP: Unauthenticated Use of Server-Side NetLicensing API Key in HTTP Mode High
CVE-2026-54446 was published for netlicensing-mcp (pip) Jul 14, 2026
EQSTLab Credited to EQSTLab
yutu: Arbitrary File Write via MCP `caption-download` Tool High
CVE-2026-50158 was published for github.com/eat-pray-ai/yutu (Go) Jul 14, 2026
EQSTLab Credited to EQSTLab
MKP: Unbounded Pod Log Read via Attacker-Controlled `limitBytes`/`tailLines` Causes Memory Exhaustion High
CVE-2026-50125 was published for github.com/StacklokLabs/mkp (Go) Jul 14, 2026
EQSTLab Credited to EQSTLab
BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py High
CVE-2026-54071 was published for BabelDOC (pip) Jul 10, 2026
EQSTLab Credited to EQSTLab and awwaawwa awwaawwa awwaawwa
Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS) High
CVE-2026-54063 was published for github.com/xuri/excelize/v2 (Go) Jul 10, 2026
EQSTLab Credited to EQSTLab
flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module` High
CVE-2026-55786 was published for flyto-core (pip) Jul 6, 2026
EQSTLab Credited to EQSTLab
mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete Critical
CVE-2026-50027 was published for mcp-memory-service (pip) Jul 2, 2026
EQSTLab Credited to EQSTLab
Apify Model Context Protocol (MCP) server: Actor MCP path authority injection leaks Apify token High
CVE-2026-50143 was published for @apify/actors-mcp-server (npm) Jul 1, 2026
EQSTLab Credited to EQSTLab and 232-323 232-323 232-323
ProTip! Advisories are also available from the GraphQL API