close
Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

28,459 advisories

Loading
PraisonAI Has Path Traversal in FileTools Critical
CVE-2026-35615 was published for PraisonAI (pip) Apr 6, 2026
kritsana-chaikaew Credited to kritsana-chaikaew
PraisonAI recipe registry publish path traversal allows out-of-root file write High
CVE-2026-39308 was published for PraisonAI (pip) Apr 6, 2026
R1ZZG0D Credited to R1ZZG0D
PraisonAI recipe registry pull path traversal writes files outside the chosen output directory High
CVE-2026-39306 was published for PraisonAI (pip) Apr 6, 2026
R1ZZG0D Credited to R1ZZG0D
PraisonAI Vulnerable to Arbitrary File Write / Path Traversal in Action Orchestrator Critical
CVE-2026-39305 was published for PraisonAI (pip) Apr 6, 2026
liyander Credited to liyander
PraisonAI Has Arbitrary File Write (Zip Slip) in Templates Extraction High
CVE-2026-39307 was published for PraisonAI (pip) Apr 6, 2026
liyander Credited to liyander
go-ipld-prime: DAG-CBOR decoder unbounded memory allocation from CBOR headers Moderate
CVE-2026-35480 was published for github.com/ipld/go-ipld-prime (Go) Apr 6, 2026
yuliyu123 Credited to yuliyu123
PocketMine-MP: Player entities can still die and drop items in flaggedForDespawn state Low
GHSA-f9jp-856v-8642 was published for pocketmine/pocketmine-mp (Composer) Apr 6, 2026
kostamax27 Credited to kostamax27 and dktapps dktapps dktapps
PocketMine-MP: Network amplification vulnerability with `ActorEventPacket` Moderate
GHSA-7hmv-4j2j-pp6f was published for pocketmine/pocketmine-mp (Composer) Apr 6, 2026
dktapps Credited to dktapps
PocketMine-MP: JSON decoding of unlimited size large arrays/objects in ModalFormResponse Handling High
GHSA-788v-5pfp-93ff was published for pocketmine/pocketmine-mp (Composer) Apr 6, 2026
Zwuiix-cmd Credited to Zwuiix-cmd and dktapps dktapps dktapps
PocketMine-MP: LogDoS by large complex unknown property logging in clientData in LoginPacket High
GHSA-h6rj-3m53-887h was published for pocketmine/pocketmine-mp (Composer) Apr 6, 2026
ArkadiaEU Credited to ArkadiaEU and dktapps dktapps dktapps
OpenClaw's complex interpreter pipelines could skip exec script preflight validation Moderate
CVE-2026-34425 was published for openclaw (npm) Apr 6, 2026
wsparks-vc Credited to wsparks-vc and iskindar iskindar iskindar
Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling Moderate
GHSA-4w7w-66w2-5vf9 was published for vite (npm) Apr 6, 2026
odgrso Credited to odgrso, Ochk0, and bluwy Ochk0 Ochk0
bluwy bluwy
Vite: `server.fs.deny` bypassed with queries High
GHSA-v2wj-q39q-566r was published for vite (npm) Apr 6, 2026
odgrso Credited to odgrso, ritikchaddha, neo-ai-engineer, instantraaamen, fg0x0, jonathanwd, kq5y, and bluwy ritikchaddha ritikchaddha
neo-ai-engineer neo-ai-engineer instantraaamen instantraaamen fg0x0 fg0x0 jonathanwd jonathanwd kq5y kq5y bluwy bluwy
Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket High
CVE-2026-39363 was published for vite (npm) Apr 6, 2026
odgrso Credited to odgrso, CodeAnt-AI-Security, tronglinh23, and bluwy CodeAnt-AI-Security CodeAnt-AI-Security
tronglinh23 tronglinh23 bluwy bluwy
strawberry-graphql: Denial of Service via unbounded WebSocket subscriptions High
CVE-2026-35526 was published for strawberry-graphql (pip) Apr 6, 2026
JFOZ1010 Credited to JFOZ1010, patrick91, and bellini666 patrick91 patrick91
bellini666 bellini666
strawberry-graphql: Authentication bypass via legacy graphql-ws WebSocket subprotocol High
CVE-2026-35523 was published for strawberry-graphql (pip) Apr 6, 2026
bellini666 Credited to bellini666, patrick91, katzj, and WesR patrick91 patrick91
katzj katzj WesR WesR
changedetection.io Vulnerable to Authentication Bypass via Decorator Ordering Critical
CVE-2026-35490 was published for changedetection.io (pip) Apr 6, 2026
axel-corsiez Credited to axel-corsiez
@nestjs/core Improperly Neutralizes Special Elements in Output Used by a Downstream Component ('Injection') Moderate
CVE-2026-35515 was published for @nestjs/core (npm) Apr 6, 2026
aleister1102 Credited to aleister1102
Authorizer: Password reset token theft and full auth token redirect via unvalidated redirect_uri High
GHSA-x3f4-v83f-7wp2 was published for github.com/authorizerdev/authorizer (Go) Apr 6, 2026
kodareef5 Credited to kodareef5
Authorizer: CQL/N1QL Injection in Cassandra and Couchbase Backends via fmt.Sprintf String Interpolation High
GHSA-jfwg-rxf3-p7r9 was published for github.com/authorizerdev/authorizer (Go) Apr 6, 2026
morimori-dev Credited to morimori-dev
kedro-datasets has a path traversal vulnerability in PartitionedDataset that allows arbitrary file write Moderate
CVE-2026-35492 was published for kedro-datasets (pip) Apr 6, 2026
redyank Credited to redyank
rdiscount has an Out-of-bounds Read Moderate
CVE-2026-35201 was published for rdiscount (RubyGems) Apr 6, 2026
WesR Credited to WesR
Distribution: stale blob access resurrection via repo-scoped redis descriptor cache invalidation High
CVE-2026-35172 was published for github.com/distribution/distribution (Go) Apr 6, 2026
1seal Credited to 1seal
Distribution affected by pull-through cache credential exfiltration via www-authenticate bearer realm High
CVE-2026-33540 was published for github.com/distribution/distribution (Go) Apr 6, 2026
1seal Credited to 1seal
ProTip! Advisories are also available from the GraphQL API