Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

61 advisories

Loading
vm2: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks Moderate
CVE-2026-92952 was published for vm2 (npm) Oct 1, 2026
rexpository Credited to rexpository
nasaa0x Credited to nasaa0x, rexpository, sangnigege, and manus-use rexpository rexpository
sangnigege sangnigege manus-use manus-use
rexpository Credited to rexpository, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
rexpository Credited to rexpository, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation Moderate
CVE-2026-69147 was published for vllm (pip) Sep 17, 2026
rexpository Credited to rexpository and jperezdealgaba jperezdealgaba jperezdealgaba
rexpository Credited to rexpository and jperezdealgaba jperezdealgaba jperezdealgaba
OpenClaw Feishu permission tools could ignore per-account disablement High
GHSA-w8wf-3qvj-6xqf was published for @openclaw/feishu (npm) Sep 3, 2026
rexpository Credited to rexpository
OpenClaw Feishu tools could ignore per-account disablement High
GHSA-2q7j-2vhx-56g8 was published for @openclaw/feishu (npm) Sep 3, 2026
rexpository Credited to rexpository
Mailpit: SMTP command parser buffers unbounded command lines before syntax rejection High
CVE-2026-67445 was published for github.com/axllent/mailpit (Go) Sep 2, 2026
rexpository Credited to rexpository
Mailpit: Thumbnail generation decodes unbounded image dimensions before scaling High
CVE-2026-67446 was published for github.com/axllent/mailpit (Go) Sep 2, 2026
rexpository Credited to rexpository
praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets High
CVE-2026-55523 was published for praisonaiagents (pip) Aug 25, 2026
rexpository Credited to rexpository
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code High
CVE-2026-55522 was published for PraisonAI (pip) Aug 25, 2026
rexpository Credited to rexpository
Mailpit: SMTP DATA line reader buffers over-limit input before size enforcement Moderate
CVE-2026-67447 was published for github.com/axllent/mailpit (Go) Aug 20, 2026
rexpository Credited to rexpository
vm2: Sandbox Breakout Using Dangerous Host Proto Mutators Critical
CVE-2026-47698 was published for vm2 (npm) Aug 17, 2026
XmiliaH Credited to XmiliaH, the-vibe-dev, oran-s, dinhvaren, PowerliftLog, zolbooo, nil340, rexpository, and lukefr09 the-vibe-dev the-vibe-dev
oran-s oran-s dinhvaren dinhvaren PowerliftLog PowerliftLog zolbooo zolbooo nil340 nil340 rexpository rexpository lukefr09 lukefr09
vLLM: Completion prompt lists fan out into unbounded engine requests Moderate
CVE-2026-73559 was published for vllm (pip) Aug 13, 2026
rexpository Credited to rexpository, jperezdealgaba, and DarkLight1337 jperezdealgaba jperezdealgaba
DarkLight1337 DarkLight1337
Netty: RedisArrayAggregator max-elements failure leaves retained partial aggregate state Moderate
CVE-2026-56818 was published for io.netty:netty-codec-redis (Maven) Aug 7, 2026
rexpository Credited to rexpository
rexpository Credited to rexpository and Classic298 Classic298 Classic298
Open WebUI: Arena task endpoints can bypass underlying model access controls Moderate
CVE-2026-59225 was published for open-webui (pip) Jul 24, 2026
rexpository Credited to rexpository and Classic298 Classic298 Classic298
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete Moderate
CVE-2026-59212 was published for open-webui (pip) Jul 24, 2026
rexpository Credited to rexpository and Classic298 Classic298 Classic298
smoke-wolf Credited to smoke-wolf, rexpository, and Classic298 rexpository rexpository
Classic298 Classic298
rexpository Credited to rexpository and Classic298 Classic298 Classic298
ImageMagick: Policy Bypass in script operation due to missing checks Low
GHSA-vghg-5jrg-2398 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ImageMagick: Policy Bypass in APNG encoder and delegates due to a missing check Low
GHSA-v3j6-27vc-7pw2 was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ImageMagick: Heap-use-after-free via XMP profile could result in a crash Low
GHSA-qh5g-q395-cx4j was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797 Moderate
GHSA-hc76-7mpc-qjqh was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
ProTip! Advisories are also available from the GraphQL API