Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

574 advisories

Loading
mistral.rs Media Loader: Unauthenticated SSRF and arbitrary local file read via image_url High
GHSA-wfgq-w7cq-qj7j was published for mistralrs-server-core (Rust) Sep 10, 2026
koyokr Credited to koyokr
Masofgon Credited to Masofgon
OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree High
GHSA-2q42-4q24-7rgv was published for @typespec/compiler (npm) Sep 8, 2026
NLx64 Credited to NLx64
Hcamael Credited to Hcamael
Laravel Excel writes exports outside the configured filesystem disk when given a caller-controlled path High
CVE-2026-84374 was published for maatwebsite/excel (Composer) Sep 8, 2026
seck19 Credited to seck19
NLTK: Corpus Reader Sandbox Bypass High
CVE-2026-79674 was published for nltk (pip) Sep 8, 2026
nguyencanhthuong Credited to nguyencanhthuong
NLTK: Stable FrameNet and NKJP readers parse outside-root XML High
CVE-2026-62385 was published for nltk (pip) Sep 8, 2026
ProTip! Advisories are also available from the GraphQL API