GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
97 advisories
Filter by severity
A security vulnerability has been detected in gouguoa up to 5.10.0/6.0.1. This vulnerability...
Low
Unreviewed
CVE-2026-84430
was published
Sep 2, 2026
Applications that evaluate Spring Expression Language (SpEL) expressions using...
Critical
Unreviewed
CVE-2026-59283
was published
Aug 27, 2026
Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173...
High
Unreviewed
CVE-2026-76023
was published
Aug 20, 2026
asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter
Moderate
GHSA-9w56-46f6-3qhx
was published
for
asteval
(pip)
Aug 20, 2026
A flaw was found in the search-v2-operator. This vulnerability allows a privileged user,...
Critical
Unreviewed
CVE-2026-71470
was published
Aug 19, 2026
vm2: Sandbox Breakout Using Dangerous Host Proto Mutators
Critical
CVE-2026-47698
was published
for
vm2
(npm)
Aug 17, 2026
LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading
Moderate
CVE-2026-48775
was published
for
langgraph-checkpoint
(pip)
Jun 25, 2026
Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API
Critical
CVE-2026-53753
was published
for
crawl4ai
(pip)
Jun 16, 2026
vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass
Critical
CVE-2026-47210
was published
for
vm2
(npm)
May 29, 2026
vm2 has a CVE-2023-37903 patch bypass: nesting:true without explicit require still allows full RCE
Critical
CVE-2026-47137
was published
for
vm2
(npm)
May 29, 2026
vm2 is Vulnerable to Sandbox Breakout Through Promise Species
Critical
CVE-2026-47208
was published
for
vm2
(npm)
May 29, 2026
An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's...
Critical
Unreviewed
CVE-2026-48700
was published
May 26, 2026
LiteLLM has a sandbox escape in custom-code guardrail
High
CVE-2026-40217
was published
for
litellm
(pip)
May 11, 2026
PraisonAI MCP `tools/call` path-traversal => RCE via Python `.pth` injection
Critical
CVE-2026-44336
was published
for
PraisonAI
(pip)
May 11, 2026
A vulnerability was identified in z-9527 admin 1.0/2.0. This impacts an unknown function of the...
Moderate
Unreviewed
CVE-2026-5251
was published
Apr 1, 2026
A vulnerability has been found in gougucms 4.08.18. This affects the function reg_submit of the...
Moderate
Unreviewed
CVE-2026-5248
was published
Apr 1, 2026
NocoBase Affected by Sandbox Escape to RCE via console._stdout Prototype Chain Traversal in Workflow Script Node
Critical
CVE-2026-34156
was published
for
@nocobase/plugin-workflow-javascript
(npm)
Mar 30, 2026
Graphiti Affected by Arbitrary Method Execution via Unvalidated Relationship Names
Critical
CVE-2026-33286
was published
for
graphiti
(RubyGems)
Mar 20, 2026
Apache Airflow Providers Http has Unsafe Pickle Deserializatio leading to RCE via HttpOperator
High
CVE-2025-69219
was published
for
apache-airflow-providers-http
(pip)
Mar 9, 2026
n8n Has Expression Escape Vulnerability Leading to RCE
Critical
CVE-2026-25049
was published
for
n8n
(npm)
Feb 4, 2026
Crafter CMS has Improper Control of Dynamically-Managed Code Resources
Moderate
CVE-2026-1770
was published
for
org.craftercms:craftercms
(Maven)
Feb 2, 2026
SandboxJS has Sandbox Escape via Unprotected AsyncFunction Constructor
Critical
CVE-2026-23830
was published
for
@nyariv/sandboxjs
(npm)
Jan 27, 2026
Signal K Server has Unauthenticated State Pollution leading to Remote Code Execution (RCE)
Critical
CVE-2025-66398
was published
for
signalk-server
(npm)
Jan 2, 2026
ProTip!
Advisories are also available from the
GraphQL API