GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,894
Erlang
38
GitHub Actions
38
Go
2,558
Maven
5,000+
npm
4,232
NuGet
751
pip
4,001
Pub
12
RubyGems
953
Rust
1,042
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,233 advisories
Filter by severity
Open WebUI allows Remote Code Execution via Arbitrary File Upload to /audio/api/v1/transcriptions
High
CVE-2024-8060
was published
for
open-webui
(pip)
Mar 20, 2025
GluonCV Arbitrary File Write via TarSlip
High
CVE-2024-12216
was published
for
gluoncv
(pip)
Mar 20, 2025
InvokeAI Arbitrary File Deletion vulnerability
Critical
CVE-2024-11042
was published
for
InvokeAI
(pip)
Mar 20, 2025
DB-GPT vulnerable to Arbitrary File Upload with Path Traversal
Critical
CVE-2024-10902
was published
for
dbgpt
(pip)
Mar 20, 2025
DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload
Critical
CVE-2024-10833
was published
for
dbgpt
(pip)
Mar 20, 2025
LoLLMS vulnerable to Expected Behavior Violation
High
CVE-2024-6281
was published
for
lollms
(pip)
Jul 20, 2024
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
Critical
CVE-2024-5980
was published
for
lightning
(pip)
Jun 27, 2024
AWS SAM CLI Path Traversal allows file copy to local cache
Moderate
CVE-2025-3048
was published
for
aws-sam-cli
(pip)
Mar 31, 2025
AWS SAM CLI Path Traversal allows file copy to build container
Moderate
CVE-2025-3047
was published
for
aws-sam-cli
(pip)
Mar 31, 2025
Deep Java Library path traversal issue
Critical
CVE-2025-0851
was published
for
ai.djl:api
(Maven)
Jan 29, 2025
Argo Workflow has a Zipslip Vulnerability
High
CVE-2025-62156
was published
for
github.com/argoproj/argo-workflows/v3
(Go)
Oct 14, 2025
Grafana path traversal
High
CVE-2021-43798
was published
for
github.com/grafana/grafana
(Go)
Feb 1, 2024
cross-zip is vulnerable to Directory Traversal through selective use of zip/unzip operations
High
CVE-2025-11569
was published
for
cross-zip
(npm)
Oct 10, 2025
Flowise is vulnerable to arbitrary file exposure through its ReadFileTool
High
GHSA-j44m-5v8f-gc9c
was published
for
flowise
(npm)
Oct 10, 2025
BBOT's insufficient sanitization issues in gitdumper.py can lead to RCE
Critical
CVE-2025-10283
was published
for
bbot
(pip)
Oct 9, 2025
BBOT's various issues in unarchive.py can cause arbitrary file write and RCE
Critical
CVE-2025-10284
was published
for
bbot
(pip)
Oct 9, 2025
Flowise is vulnerable to arbitrary file write through its WriteFileTool
Critical
CVE-2025-61913
was published
for
flowise
(npm)
Oct 9, 2025
LLaMA Factory's Chat API Contains Critical SSRF and LFI Vulnerabilities
High
CVE-2025-61784
was published
for
llamafactory
(pip)
Oct 7, 2025
clearml is vulnerable to Path Traversal through its `safe_extract` function
Moderate
CVE-2025-8917
was published
for
clearml
(pip)
Oct 5, 2025
ZenML is vulnerable to Path Traversal through its `PathMaterializer` class
Moderate
CVE-2025-8406
was published
for
zenml
(pip)
Oct 5, 2025
Withdrawn Advisory: Python-Future Module Arbitrary Code Execution via Unintended Import of test.py
High
CVE-2025-50817
was published
for
future
(pip)
Aug 14, 2025
•
withdrawn
NLnet Labs’ Routinator vulnerable to path traversal
Critical
CVE-2023-39916
was published
for
routinator
(Rust)
Sep 13, 2023
Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval Function
High
CVE-2025-54293
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
ProTip!
Advisories are also available from the
GraphQL API