GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,741
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,570
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
485 advisories
Filter by severity
GitHacker: Path traversal in ref/hash parsing enables existence oracle and hex-fragment exfiltration via malicious .git server
Moderate
CVE-2026-50024
was published
for
githacker
(pip)
Sep 9, 2026
GitPython: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination
High
CVE-2026-78677
was published
for
GitPython
(pip)
Sep 8, 2026
NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement
High
CVE-2026-79676
was published
for
nltk
(pip)
Sep 8, 2026
NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely
Moderate
CVE-2026-62383
was published
for
nltk
(pip)
Sep 8, 2026
NLTK: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292)
High
CVE-2026-62384
was published
for
nltk
(pip)
Sep 8, 2026
NLTK: Stable FrameNet and NKJP readers parse outside-root XML
High
CVE-2026-62385
was published
for
nltk
(pip)
Sep 8, 2026
NLTK: StreamBackedCorpusView Bypasses pathsec.ENFORCE - Arbitrary Local File Read
High
CVE-2026-63312
was published
for
nltk
(pip)
Sep 8, 2026
Omnigent: Unvalidated os_env.cwd in agent bundle yields arbitrary host filesystem access on runners without OMNIGENT_RUNNER_WORKSPACE
High
CVE-2026-62677
was published
for
omnigent
(pip)
Sep 2, 2026
Banks: Path traversal in `DirectoryPromptRegistry.set()` allows arbitrary file write outside the registry root
Moderate
CVE-2026-71492
was published
for
banks
(pip)
Sep 2, 2026
NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed roots
High
CVE-2026-81726
was published
for
nltk
(pip)
Sep 2, 2026
asyncssh has SCP Path Traversal to Arbitrary File Write
High
CVE-2026-54591
was published
for
asyncssh
(pip)
Aug 26, 2026
asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution
Moderate
CVE-2026-54590
was published
for
asyncssh
(pip)
Aug 26, 2026
Duplicate Advisory: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement
High
GHSA-w5q8-6jpp-4246
was published
for
nltk
(pip)
Aug 25, 2026
•
withdrawn
praisonaiagents vulnerable to arbitrary file write via unsanitized `user_id` in `FileMemory.__init__()` — path traversal to any writable location
High
CVE-2026-55527
was published
for
praisonaiagents
(pip)
Aug 25, 2026
PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks
High
CVE-2026-55540
was published
for
PraisonAI
(pip)
Aug 25, 2026
Duplicate Advisory: clone_from()/clone() omit --separate-git-dir from unsafe_git_clone_options, enabling arbitrary git-directory creation outside the destination
High
GHSA-7r39-6q8m-qw68
was published
for
gitpython
(pip)
Aug 25, 2026
•
withdrawn
Duplicate Advisory: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292)
High
GHSA-qq3h-cgj8-w3fx
was published
for
nltk
(pip)
Aug 22, 2026
•
withdrawn
Duplicate Advisory: NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely
Moderate
GHSA-343m-9fqq-97c7
was published
for
nltk
(pip)
Aug 22, 2026
•
withdrawn
Duplicate Advisory: Security Report: StreamBackedCorpusView Bypasses pathsec.ENFORCE - Arbitrary Local File Read
High
GHSA-8w48-h75v-cxpv
was published
for
nltk
(pip)
Aug 22, 2026
•
withdrawn
NLTK CrubadanCorpusReader path traversal allows arbitrary file disclosure
Low
CVE-2026-71514
was published
for
nltk
(pip)
Aug 22, 2026
Duplicate Advisory: ONNX: TOCTOU arbitrary file read/write in save_external_dat
Moderate
GHSA-486p-g8x4-77mg
was published
for
onnx
(pip)
Aug 21, 2026
•
withdrawn
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted
High
CVE-2026-53951
was published
for
copier
(pip)
Aug 19, 2026
Duplicate Advisory: GitPython: Arbitrary Git Repository Creation Outside the Working Tree via Unvalidated .gitmodules Submodule Name in GitPython
High
GHSA-3vrx-526r-64rm
was published
for
gitpython
(pip)
Aug 19, 2026
•
withdrawn
linuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)
Moderate
CVE-2026-73974
was published
for
linuxfabrik-lib
(pip)
Aug 18, 2026
MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads
Moderate
CVE-2026-68922
was published
for
mobsf
(pip)
Aug 18, 2026
ProTip!
Advisories are also available from the
GraphQL API