GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,510
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
239 advisories
Filter by severity
Microsoft Kiota: Path traversal in generated plugin manifest static_template.file reference (percent-encoding bypass)
Moderate
GHSA-p5rm-jg5c-8c77
was published
for
Microsoft.OpenApi.Kiota
(NuGet)
Jul 24, 2026
Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
Critical
CVE-2026-59865
was published
for
Microsoft.OpenApi.Kiota
(NuGet)
Jul 24, 2026
Microsoft Kiota Workspace-config poisoning: out-of-repo file write + generation-time SSRF
High
CVE-2026-59863
was published
for
Microsoft.OpenApi.Kiota
(NuGet)
Jul 24, 2026
Microsoft Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref
High
CVE-2026-59867
was published
for
Microsoft.OpenApi.Kiota
(NuGet)
Jul 24, 2026
Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions
Critical
CVE-2026-59864
was published
for
Microsoft.OpenApi.Kiota
(NuGet)
Jul 24, 2026
Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe...
High
Unreviewed
CVE-2026-66141
was published
Jul 24, 2026
In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python...
High
Unreviewed
CVE-2026-65908
was published
Jul 23, 2026
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project...
High
Unreviewed
CVE-2026-64809
was published
Jul 23, 2026
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting...
High
Unreviewed
CVE-2026-64811
was published
Jul 23, 2026
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied...
High
Unreviewed
CVE-2026-64807
was published
Jul 23, 2026
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project...
High
Unreviewed
CVE-2026-64806
was published
Jul 23, 2026
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project...
High
Unreviewed
CVE-2026-64805
was published
Jul 23, 2026
In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project...
High
Unreviewed
CVE-2026-64808
was published
Jul 23, 2026
In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project...
High
Unreviewed
CVE-2026-64804
was published
Jul 23, 2026
A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. Affected is the...
Low
Unreviewed
CVE-2026-16085
was published
Jul 18, 2026
ForgeCode (tailcallhq/forgecode), an AI pair-programming CLI, automatically loads and executes...
High
Unreviewed
CVE-2026-57860
was published
Jul 17, 2026
OpenClaw before 2026.5.22 contain a vulnerability in setup-mode discovery that allows loading of...
High
Unreviewed
CVE-2026-62222
was published
Jul 17, 2026
Cherry Studio versions 1.2.2 through 1.9.12, fixed in commit 1518530, contain a remote code...
High
Unreviewed
CVE-2026-40501
was published
Jul 15, 2026
NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause improper...
Moderate
Unreviewed
CVE-2026-24226
was published
Jul 14, 2026
A vulnerability was found in usestrix strix up to 1.0.2. This affects an unknown function of the...
Low
Unreviewed
CVE-2026-15519
was published
Jul 13, 2026
OpenClaw's marketplace runtime extension metadata could point at unscanned payloads
High
CVE-2026-53810
was published
for
openclaw
(npm)
Jul 2, 2026
Cortex has Untrusted Project Bootstrap Code Execution via `CLAUDE_PROJECT_DIR`
High
CVE-2026-49986
was published
for
neuro-cortex-memory
(pip)
Jul 1, 2026
Improper handling of untrusted remote references in Snowflake CLI versions prior to 3.19 allowed...
Moderate
Unreviewed
CVE-2026-13751
was published
Jun 29, 2026
pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes
High
CVE-2026-55698
was published
for
pnpm
(npm)
Jun 26, 2026
pnpm: Repository-controlled configDependencies can select a pacquet native install engine
High
CVE-2026-55697
was published
for
pnpm
(npm)
Jun 26, 2026
ProTip!
Advisories are also available from the
GraphQL API