GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
2,597 advisories
Filter by severity
pyload-ng: getUserData/get_userdata exposed at Perms.ANY allow any authenticated account to brute-force the administrator password
High
GHSA-68w4-83fh-f2w8
was published
for
pyload-ng
(pip)
Oct 9, 2026
pyLoad: Privilege revocation and password change through the REST API do not invalidate the user's session
High
GHSA-jq7h-wrvp-3rgx
was published
for
pyload-ng
(pip)
Oct 9, 2026
pyLoad: Api.set_user_permission never invalidates the target's session
High
GHSA-889w-m37p-88m5
was published
for
pyload-ng
(pip)
Oct 9, 2026
pyLoad: Tar extraction creates device nodes and FIFOs (member types not filtered; tarfile extractall without filter=)
High
GHSA-fr26-jjhm-638c
was published
for
pyload-ng
(pip)
Oct 9, 2026
pyLoad has an authentication bypass in API key validation (check_apikey cache)
High
GHSA-r44w-v6gf-x3p6
was published
for
pyload-ng
(pip)
Oct 9, 2026
Strawberry GraphQL: Synchronous permission checks can treat an awaitable authorization result as truthy
High
CVE-2026-107728
was published
for
strawberry-graphql
(pip)
Oct 9, 2026
PraisonAI: Platform member PATCH routes allow owner resource rewrites and project lead reassignment delete bypass
High
CVE-2026-61442
was published
for
praisonai-platform
(pip)
Oct 8, 2026
PraisonAI: Shell command allowlist bypass via find -exec built-in action
High
CVE-2026-61434
was published
for
praisonai
(pip)
Oct 8, 2026
PraisonAI: MCP HTTP-stream transport is unauthenticated by default, exposing tool enumeration and an unvalidated tool-call surface
High
CVE-2026-61427
was published
for
praisonai
(pip)
Oct 8, 2026
PraisonAI: SecurityPolicy command/path/import restrictions are completely unenforced by the default SubprocessSandbox backend
High
CVE-2026-60085
was published
for
praisonai
(pip)
Oct 8, 2026
PraisonAI: Jobs API is unauthenticated by default and allows attacker-controlled webhook SSRF
High
CVE-2026-60091
was published
for
praisonai
(pip)
Oct 8, 2026
Pydantic AI: Concurrency-limited models can keep their slot when a streamed request ends early
High
CVE-2026-107286
was published
for
pydantic-ai
(pip)
Oct 8, 2026
CairoSVG: Quadratic-time DoS parsing a crafted SVG <path>
High
CVE-2026-107378
was published
for
cairosvg
(pip)
Oct 8, 2026
PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source
High
CVE-2026-61433
was published
for
praisonai
(pip)
Oct 8, 2026
PraisonAI: Call API localhost-only authentication bypass via spoofed Host header
High
CVE-2026-61435
was published
for
praisonai
(pip)
Oct 8, 2026
datamodel-code-generator: Protobuf weak-import path traversal allows files to be written outside the temporary directory
High
CVE-2026-107377
was published
for
datamodel-code-generator
(pip)
Oct 8, 2026
Pydantic AI Web chat UI (`Agent.to_web()`, `clai web`): a website visited by the developer can trigger agent runs and server-side tool execution on the local chat endpoint
High
CVE-2026-107295
was published
for
pydantic-ai
(pip)
Oct 8, 2026
PraisonAI: SkillTools Executes Scripts Without Path Containment Validation
High
CVE-2026-61443
was published
for
praisonaiagents
(pip)
Oct 8, 2026
PraisonAI: Unsafe Dynamic Module Loading Leads to Arbitrary Code Execution via tools.py in AgentFlow
High
CVE-2026-61437
was published
for
praisonaiagents
(pip)
Oct 8, 2026
PraisonAI: Plugin Auto-Discovery Executes Arbitrary Python Files Without Verification
High
CVE-2026-61446
was published
for
praisonaiagents
(pip)
Oct 8, 2026
PraisonAI: DNS rebinding bypass in `web_crawl` SSRF protection allows internal response disclosure
High
CVE-2026-61430
was published
for
praisonaiagents
(pip)
Oct 8, 2026
PraisonAI: Prompt Injection Defense Bypassed for HIGH-Level Threats
High
CVE-2026-61439
was published
for
PraisonAI
(pip)
Oct 7, 2026
Docling has arbitrary file read/write (and command execution when shell-escape is enabled) when rendering untrusted TikZ with the opt-in Tectonic engine
High
CVE-2026-105744
was published
for
docling
(pip)
Oct 7, 2026
Langflow has Authenticated Cross-Project File Disclosure via Unscoped MCP Resource Handlers
High
CVE-2026-105699
was published
for
langflow
(pip)
Oct 7, 2026
Hydra: Optuna custom_search_space can resolve and execute untrusted callables via get_method
High
CVE-2026-106440
was published
for
hydra-optuna-sweeper
(pip)
Oct 7, 2026
ProTip!
Advisories are also available from the
GraphQL API