Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,597 advisories

Loading
prnjlksingh Credited to prnjlksingh
arpitjain099 Credited to arpitjain099
pyLoad: Api.set_user_permission never invalidates the target's session High
GHSA-889w-m37p-88m5 was published for pyload-ng (pip) Oct 9, 2026
FlowOverFail Credited to FlowOverFail
skeletonsec Credited to skeletonsec
pyLoad has an authentication bypass in API key validation (check_apikey cache) High
GHSA-r44w-v6gf-x3p6 was published for pyload-ng (pip) Oct 9, 2026
nirtem Credited to nirtem
Strawberry GraphQL: Synchronous permission checks can treat an awaitable authorization result as truthy High
CVE-2026-107728 was published for strawberry-graphql (pip) Oct 9, 2026
Hama1cco Credited to Hama1cco and patrick91 patrick91 patrick91
rexpository Credited to rexpository
PraisonAI: Shell command allowlist bypass via find -exec built-in action High
CVE-2026-61434 was published for praisonai (pip) Oct 8, 2026
HiyokoSauna37 Credited to HiyokoSauna37
dinhvaren Credited to dinhvaren
LHMisme420 Credited to LHMisme420
PraisonAI: Jobs API is unauthenticated by default and allows attacker-controlled webhook SSRF High
CVE-2026-60091 was published for praisonai (pip) Oct 8, 2026
dinhvaren Credited to dinhvaren
Pydantic AI: Concurrency-limited models can keep their slot when a streamed request ends early High
CVE-2026-107286 was published for pydantic-ai (pip) Oct 8, 2026
lche511 Credited to lche511
CairoSVG: Quadratic-time DoS parsing a crafted SVG <path> High
CVE-2026-107378 was published for cairosvg (pip) Oct 8, 2026
mohammedix88 Credited to mohammedix88
PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source High
CVE-2026-61433 was published for praisonai (pip) Oct 8, 2026
rexpository Credited to rexpository
PraisonAI: Call API localhost-only authentication bypass via spoofed Host header High
CVE-2026-61435 was published for praisonai (pip) Oct 8, 2026
rexpository Credited to rexpository
datamodel-code-generator: Protobuf weak-import path traversal allows files to be written outside the temporary directory High
CVE-2026-107377 was published for datamodel-code-generator (pip) Oct 8, 2026
alex131125 Credited to alex131125
PraisonAI: SkillTools Executes Scripts Without Path Containment Validation High
CVE-2026-61443 was published for praisonaiagents (pip) Oct 8, 2026
anushkavirgaonkar Credited to anushkavirgaonkar
PraisonAI: Unsafe Dynamic Module Loading Leads to Arbitrary Code Execution via tools.py in AgentFlow High
CVE-2026-61437 was published for praisonaiagents (pip) Oct 8, 2026
Nx7n Credited to Nx7n
PraisonAI: Plugin Auto-Discovery Executes Arbitrary Python Files Without Verification High
CVE-2026-61446 was published for praisonaiagents (pip) Oct 8, 2026
anushkavirgaonkar Credited to anushkavirgaonkar
PraisonAI: DNS rebinding bypass in `web_crawl` SSRF protection allows internal response disclosure High
CVE-2026-61430 was published for praisonaiagents (pip) Oct 8, 2026
dinhvaren Credited to dinhvaren
PraisonAI: Prompt Injection Defense Bypassed for HIGH-Level Threats High
CVE-2026-61439 was published for PraisonAI (pip) Oct 7, 2026
chakrapani150 Credited to chakrapani150
wittjeff Credited to wittjeff, hoanggxyuuki, Smavl, 3m4n5, and Jiayang-Lai hoanggxyuuki hoanggxyuuki
Smavl Smavl 3m4n5 3m4n5 Jiayang-Lai Jiayang-Lai
Langflow has Authenticated Cross-Project File Disclosure via Unscoped MCP Resource Handlers High
CVE-2026-105699 was published for langflow (pip) Oct 7, 2026
R1ZZG0D Credited to R1ZZG0D, andifilhohub, and erichare andifilhohub andifilhohub
erichare erichare
Hydra: Optuna custom_search_space can resolve and execute untrusted callables via get_method High
CVE-2026-106440 was published for hydra-optuna-sweeper (pip) Oct 7, 2026
manus-pi Credited to manus-pi and manus-use manus-use manus-use
ProTip! Advisories are also available from the GraphQL API