Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

5,299 advisories

Loading
WsgiDAV encoded dot segments can escape filesystem share roots High
CVE-2026-48099 was published for wsgidav (pip) Jun 11, 2026
0xHunSec Credited to 0xHunSec
Kolibri has Unauthenticated Server-Side Request Forgery (SSRF) in RemoteFacilityUserViewset Moderate
CVE-2026-48053 was published for kolibri (pip) Jun 11, 2026
beraoudabdelkhalek Credited to beraoudabdelkhalek and rtibbles rtibbles rtibbles
Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token Critical
CVE-2026-48039 was published for meta-ads-mcp (pip) Jun 11, 2026
232-323 Credited to 232-323
PDM: Project-Controlled `.pdm-plugins` Content Executes Before CLI Parsing High
CVE-2026-47781 was published for pdm (pip) Jun 11, 2026
xuemian168 Credited to xuemian168
PDM wheel installation leads to Path Traversal via overridden write_to_fs High
CVE-2026-47764 was published for pdm (pip) Jun 10, 2026
PDM: Project-Local State and Config Writes Follow Symlinks Moderate
CVE-2026-47763 was published for pdm (pip) Jun 10, 2026
xuemian168 Credited to xuemian168 and ZejiHui ZejiHui ZejiHui
Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header Moderate
CVE-2026-48061 was published for litestar (pip) Jun 10, 2026
gik2927 Credited to gik2927
Litestar has HTML Injection Through its CSRF Token High
CVE-2026-48060 was published for litestar (pip) Jun 10, 2026
Blinky-Keys Credited to Blinky-Keys
addcontent Credited to addcontent, russellb, and jperezdealgaba russellb russellb
jperezdealgaba jperezdealgaba
Dulwich has unbounded memory allocation in receive-pack from crafted thin packs Moderate
CVE-2026-47734 was published for dulwich (pip) Jun 8, 2026
jelmer Credited to jelmer
Dulwich doesn't sanitize commit subjects in `porcelain.format_patch` Low
CVE-2026-47712 was published for dulwich (pip) Jun 8, 2026
ctoth Credited to ctoth and jelmer jelmer jelmer
GeoNode contains a server-side request forgery vulnerability in the service registration endpoint Moderate
CVE-2026-39922 was published for geonode (pip) Jun 8, 2026
CodingRule Credited to CodingRule
Bugsink: DOS using large numbers of event tags Moderate
GHSA-5x67-j5xg-c5gj was published for bugsink (pip) Jun 5, 2026
seankohjs Credited to seankohjs
Bugsink: Project scoping missing in sourcemap and debug-file lookup Moderate
CVE-2026-47728 was published for bugsink (pip) Jun 5, 2026
ShuluZhuo Credited to ShuluZhuo
Bugsink: Issue bulk actions can affect another project’s issue if its UUID is known Low
CVE-2026-47716 was published for bugsink (pip) Jun 5, 2026
Susen2 Credited to Susen2
Bugsink: Issue event views can show an event from another project if its UUID is known Low
CVE-2026-47715 was published for bugsink (pip) Jun 5, 2026
nuiifornet Credited to nuiifornet
Improper Access Control in vantage6 node Moderate
GHSA-x9f6-9rvm-mmrg was published for vantage6 (pip) Jun 5, 2026
Vantage6: Set admin user and password from environment or configuration Moderate
GHSA-fgmc-2hqj-86v4 was published for vantage6 (pip) Jun 5, 2026
offset Credited to offset and 0xEr3n 0xEr3n 0xEr3n
Vantage6: 2FA can be circumvented with hacked email access Moderate
CVE-2024-27928 was published for vantage6 (pip) Jun 5, 2026
Vantage6: No limit on emails sent for password/MFA reset Low
CVE-2024-24769 was published for vantage6 (pip) Jun 5, 2026
MCP-for-Stata: Command injection via log_file_name parameter in Stata command wrapper Critical
CVE-2026-47708 was published for stata-mcp (pip) Jun 4, 2026
SepineTam Credited to SepineTam
ProTip! Advisories are also available from the GraphQL API