GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,866
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,587
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
34 advisories
Filter by severity
JupyterLab: Argument injection in JupyterLab extension uninstall exposes server-readable files and internal URLs
Moderate
CVE-2026-102904
was published
for
jupyterlab
(pip)
Oct 1, 2026
JupyterLab: Cross-site scripting (XSS) in JupyterLab via notebook cells pasted from the system clipboard
High
CVE-2026-102831
was published
for
jupyterlab
(pip)
Oct 1, 2026
vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reservation
Moderate
CVE-2026-69147
was published
for
vllm
(pip)
Sep 17, 2026
vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
Moderate
CVE-2026-71486
was published
for
vllm
(pip)
Sep 4, 2026
praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets
High
CVE-2026-55523
was published
for
praisonaiagents
(pip)
Aug 25, 2026
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code
High
CVE-2026-55522
was published
for
PraisonAI
(pip)
Aug 25, 2026
vLLM: Completion prompt lists fan out into unbounded engine requests
Moderate
CVE-2026-73559
was published
for
vllm
(pip)
Aug 13, 2026
Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path missing the role check
Moderate
CVE-2026-70490
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Arena task endpoints can bypass underlying model access controls
Moderate
CVE-2026-59225
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete
Moderate
CVE-2026-59212
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)
High
CVE-2026-59224
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
Low
CVE-2026-59226
was published
for
open-webui
(pip)
Jul 24, 2026
JupyterLab: PyPI extension blocklist package-name canonicalization bypass
Moderate
CVE-2026-73416
was published
for
jupyterlab
(pip)
Jul 22, 2026
JupyterLab PluginManager lock-rule enforcement bypass
Moderate
GHSA-h5v5-8746-g7mm
was published
for
jupyterlab
(pip)
Jul 22, 2026
vLLM: Speech-to-text upload size limit is enforced after full UploadFile read
Moderate
CVE-2026-55646
was published
for
vllm
(pip)
Jul 17, 2026
PraisonAI SandlockSandbox falls back to unrestricted subprocess execution when Landlock is unavailable
High
CVE-2026-57144
was published
for
praisonai
(pip)
Jun 18, 2026
PraisonAI A2U incomplete authentication fix leaves current serve command unauthenticated by default
High
CVE-2026-57146
was published
for
praisonai
(pip)
Jun 18, 2026
PraisonAI recipe workflow policy can be bypassed by declaring and YAML-approving dangerous tools outside TEMPLATE.yaml
High
CVE-2026-57142
was published
for
praisonai
(pip)
Jun 18, 2026
PraisonAI GitHub template cache path traversal allows outside-cache file write and directory deletion
High
CVE-2026-57113
was published
for
praisonai
(pip)
Jun 18, 2026
PraisonAI Code agent tools fail open without a workspace boundary
High
CVE-2026-56839
was published
for
praisonai
(pip)
Jun 18, 2026
PraisonAI: AgentOS remains unauthenticated after incomplete fix version and allows remote agent invocation
Critical
CVE-2026-57116
was published
for
praisonai
(pip)
Jun 18, 2026
PraisonAI AgentTeam.launch exposes unauthenticated remote agent listing and invocation endpoints
Critical
CVE-2026-57118
was published
for
praisonaiagents
(pip)
Jun 18, 2026
PraisonAI: Jobs webhook SSRF protection bypass via DNS rebinding
High
CVE-2026-57114
was published
for
praisonai
(pip)
Jun 18, 2026
PraisonAI: SpiderTools redirect-target SSRF protection bypass
Moderate
CVE-2026-57115
was published
for
praisonaiagents
(pip)
Jun 18, 2026
PraisonAI: Compute-bridged file tools allow shell command injection
High
CVE-2026-57117
was published
for
praisonai
(pip)
Jun 18, 2026
ProTip!
Advisories are also available from the
GraphQL API