GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,788
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
33 advisories
Filter by severity
GitPython: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE
Critical
CVE-2026-78676
was published
for
GitPython
(pip)
Sep 8, 2026
Semaphore U: OS Command Injection
Critical
CVE-2026-73294
was published
for
github.com/semaphoreui/semaphore
(Go)
Sep 8, 2026
NLTK: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)
Critical
CVE-2026-79675
was published
for
nltk
(pip)
Sep 1, 2026
Duplicate Advisory: JVM argument injection bypass via per-call options in the NLTK Stanford wrappers (incomplete fix of CVE-2026-12841)
Critical
GHSA-3h2g-j4wp-7qqq
was published
for
nltk
(pip)
Aug 25, 2026
•
withdrawn
Duplicate Advisory: Dormant multi-line git-config values are corrupted into live injected directives (e.g. core.hooksPath) on any unrelated GitConfigParser write, enabling RCE
Critical
GHSA-9557-234j-7rv9
was published
for
GitPython
(pip)
Aug 25, 2026
•
withdrawn
mcp-server-kubernetes argument injection can expose Kubernetes cluster credentials
Critical
CVE-2026-61459
was published
for
mcp-server-kubernetes
(pip)
Jul 10, 2026
File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)
Critical
CVE-2026-54088
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Jul 10, 2026
Apache Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path traversal in DoclingProducer
Critical
CVE-2026-40047
was published
for
org.apache.camel:camel-docling
(Maven)
Jul 6, 2026
Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args
Critical
GHSA-r253-r9jw-qg44
was published
for
crawl4ai
(pip)
Jun 18, 2026
n8n Has an Arbitrary File Read via Git Node
Critical
CVE-2026-44790
was published
for
n8n
(npm)
May 14, 2026
ArchiveBox Vulnerable to RCE via unvalidated per-crawl config overrides in AddView
Critical
CVE-2026-42601
was published
for
archivebox
(pip)
May 4, 2026
Gotenberg has ExifTool stdin argument injection via metadata value newlines (bypass of key sanitization fix)
Critical
CVE-2026-40281
was published
for
github.com/gotenberg/gotenberg/v8
(Go)
Apr 30, 2026
Spring AI: SpEL injection is triggered when a user-supplied value is used as a filter expression key
Critical
CVE-2026-22738
was published
for
org.springframework.ai:spring-ai-vector-store
(Maven)
Mar 27, 2026
DevDojo Voyager Argument Injection vulnerability
Critical
CVE-2025-32931
was published
for
tcg/voyager
(Composer)
Apr 14, 2025
go-git has an Argument Injection via the URL field
Critical
CVE-2025-21613
was published
for
github.com/go-git/go-git/v5
(Go)
Jan 6, 2025
Gogs has an argument Injection in the built-in SSH server
Critical
CVE-2024-39930
was published
for
gogs.io/gogs
(Go)
Dec 23, 2024
Duplicate Advisory: github.com/gogs/gogs affected by CVE-2024-39930
Critical
GHSA-p69r-v3h4-rj4f
was published
for
github.com/gogs/gogs
(Go)
Jul 4, 2024
•
withdrawn
HashiCorp go-getter Vulnerable to Argument Injection When Fetching Remote Default Git Branches
Critical
CVE-2024-3817
was published
for
github.com/hashicorp/go-getter
(Go)
Apr 17, 2024
Code execution in Embedchain
Critical
CVE-2024-23731
was published
for
embedchain
(pip)
Jan 21, 2024
Gitea vulnerable to Argument Injection
Critical
CVE-2022-42968
was published
for
github.com/go-gitea/gitea
(Go)
Oct 16, 2022
Apache Hadoop argument injection vulnerability
Critical
CVE-2022-25168
was published
for
org.apache.hadoop:hadoop-common
(Maven)
Aug 5, 2022
Arbitrary file write in dragonfly
Critical
CVE-2021-33473
was published
for
dragonfly
(RubyGems)
Jun 3, 2022
Argument injection in python-libnmap
Critical
CVE-2022-30284
was published
for
python-libnmap
(pip)
May 6, 2022
Command injection in git-interface
Critical
CVE-2022-1440
was published
for
git-interface
(npm)
Apr 23, 2022
ProTip!
Advisories are also available from the
GraphQL API