Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

67 advisories

Loading
Copyparty vulnerable to file/dirkey confusion Moderate
CVE-2026-70657 was published for copyparty (pip) Aug 18, 2026
poolcritter Credited to poolcritter
LangGraph: Namespace prefix matching crosses segment boundaries in Postgres and SQLite stores Moderate
CVE-2026-71433 was published for langgraph-checkpoint-postgres (pip) Aug 6, 2026
VuxNx Credited to VuxNx
rexpository Credited to rexpository and Classic298 Classic298 Classic298
Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync cleanup Moderate
CVE-2026-70488 was published for open-webui (pip) Aug 4, 2026
whyiug Credited to whyiug and Classic298 Classic298 Classic298
Open WebUI: Users denied the image-generation permission can still generate images via chat completions Moderate
CVE-2026-70484 was published for open-webui (pip) Aug 4, 2026
DavidCarliez Credited to DavidCarliez and Classic298 Classic298 Classic298
OnionShare Receive mode writes uploaded files even when file uploads are disabled Moderate
CVE-2026-54707 was published for onionshare-cli (pip) Jul 31, 2026
sondt99 Credited to sondt99
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete Moderate
CVE-2026-59212 was published for open-webui (pip) Jul 24, 2026
rexpository Credited to rexpository and Classic298 Classic298 Classic298
jagstack Credited to jagstack and Classic298 Classic298 Classic298
jagstack Credited to jagstack and Classic298 Classic298 Classic298
JupyterLab PluginManager lock-rule enforcement bypass Moderate
GHSA-h5v5-8746-g7mm was published for jupyterlab (pip) Jul 22, 2026
rexpository Credited to rexpository, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
Flask-Security-Too: WebAuthn reauthentication freshness bypass via cross-user assertion Moderate
GHSA-f66q-9rf6-8795 was published for Flask-Security-Too (pip) Jul 7, 2026
tonghuaroot Credited to tonghuaroot
sour-exploit Credited to sour-exploit
LangGraph SDK has unsafe URL path construction Moderate
CVE-2026-48776 was published for langgraph-sdk (pip) Jun 25, 2026
pucagit Credited to pucagit
Duplicate Advisory: PraisonAI: Coarse-Grained Tool Approval Cache Bypasses Per-Invocation Consent for Shell Commands Moderate
GHSA-x44p-gg67-52fc was published for praisonai (pip) Jun 19, 2026 withdrawn
Open WebUI: Any authenticated user can read other users' private notes via Socket.IO Moderate
CVE-2026-54022 was published for open-webui (pip) Jun 17, 2026
johnatzeropath Credited to johnatzeropath, LeftenantZero, and Classic298 LeftenantZero LeftenantZero
Classic298 Classic298
brodmart Credited to brodmart and Classic298 Classic298 Classic298
OpenStack Neutron has an Incorrect Authorization issue Moderate
CVE-2026-49299 was published for neutron (pip) May 29, 2026
OpenStack Keystone has an Incorrect Authorization issue Moderate
CVE-2026-43000 was published for keystone (pip) May 28, 2026
OpenStack Keystone has an Authorization Bypass Moderate
CVE-2026-42999 was published for keystone (pip) May 28, 2026
aliceQWAS Credited to aliceQWAS and Classic298 Classic298 Classic298
Authlib OIDC Implicit/Hybrid Authorization Vulnerable to Open Redirect Moderate
CVE-2026-44681 was published for authlib (pip) May 13, 2026
y011d4 Credited to y011d4
Open WebUI: Deactivated Channel Members Retain Full Access to Group/DM Channels Moderate
CVE-2026-44561 was published for open-webui (pip) May 8, 2026
Classic298 Credited to Classic298
ProTip! Advisories are also available from the GraphQL API