Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

485 advisories

Loading
7a6163 Credited to 7a6163
NLTK: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement High
CVE-2026-79676 was published for nltk (pip) Sep 8, 2026
leduckhuong Credited to leduckhuong
NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely Moderate
CVE-2026-62383 was published for nltk (pip) Sep 8, 2026
LiteshGhute Credited to LiteshGhute
LiteshGhute Credited to LiteshGhute
NLTK: Stable FrameNet and NKJP readers parse outside-root XML High
CVE-2026-62385 was published for nltk (pip) Sep 8, 2026
NLTK: StreamBackedCorpusView Bypasses pathsec.ENFORCE - Arbitrary Local File Read High
CVE-2026-63312 was published for nltk (pip) Sep 8, 2026
meme-dm Credited to meme-dm
spbavarva Credited to spbavarva
NLTK: Model-artifact APIs bypass pathsec and touch files outside allowed roots High
CVE-2026-81726 was published for nltk (pip) Sep 2, 2026
asyncssh has SCP Path Traversal to Arbitrary File Write High
CVE-2026-54591 was published for asyncssh (pip) Aug 26, 2026
Jaden-Furtado Credited to Jaden-Furtado and JadenFurtado JadenFurtado JadenFurtado
Duplicate Advisory: Corpus readers follow symlinks outside trusted roots despite pathsec enforcement High
GHSA-w5q8-6jpp-4246 was published for nltk (pip) Aug 25, 2026 withdrawn
PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks High
CVE-2026-55540 was published for PraisonAI (pip) Aug 25, 2026
riodrwn Credited to riodrwn
Duplicate Advisory: Symlink-based sandbox bypass in FramenetCorpusReader (bypasses the fix for CVE-2026-54292) High
GHSA-qq3h-cgj8-w3fx was published for nltk (pip) Aug 22, 2026 withdrawn
Duplicate Advisory: NLTK: Symlink-based arbitrary file read in IPIPANCorpusReader, bypasses nltk.pathsec entirely Moderate
GHSA-343m-9fqq-97c7 was published for nltk (pip) Aug 22, 2026 withdrawn
Duplicate Advisory: Security Report: StreamBackedCorpusView Bypasses pathsec.ENFORCE - Arbitrary Local File Read High
GHSA-8w48-h75v-cxpv was published for nltk (pip) Aug 22, 2026 withdrawn
NLTK CrubadanCorpusReader path traversal allows arbitrary file disclosure Low
CVE-2026-71514 was published for nltk (pip) Aug 22, 2026
Duplicate Advisory: ONNX: TOCTOU arbitrary file read/write in save_external_dat Moderate
GHSA-486p-g8x4-77mg was published for onnx (pip) Aug 21, 2026 withdrawn
Copier has a trust-prefix bypass via path traversal that runs tasks unprompted High
CVE-2026-53951 was published for copier (pip) Aug 19, 2026
seankohjs Credited to seankohjs and sisp sisp sisp
manus-use Credited to manus-use
MobSF Vulnerable to Arbitrary File Read via Path Traversal in ZIP Uploads Moderate
CVE-2026-68922 was published for mobsf (pip) Aug 18, 2026
Daniel-GrunbergerCA Credited to Daniel-GrunbergerCA
ProTip! Advisories are also available from the GraphQL API