GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,629
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,149
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
187 advisories
Filter by severity
Orval: Import-time RCE via query-parameter default -> zod module-level template literal
Critical
CVE-2026-72716
was published
for
orval
(npm)
Sep 2, 2026
A flaw was found in the Qute template engine, which is used by Quarkus to generate dynamic...
High
Unreviewed
CVE-2026-12894
was published
Aug 31, 2026
Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders...
High
Unreviewed
CVE-2026-82447
was published
Aug 29, 2026
Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance)
Critical
CVE-2026-55559
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows...
Critical
Unreviewed
CVE-2026-37004
was published
Aug 27, 2026
silverstripe-advancedworkflow vulnerable to remote code execution via advanced workflow email template
High
CVE-2026-54718
was published
for
symbiote/silverstripe-advancedworkflow
(Composer)
Aug 27, 2026
mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
High
GHSA-vwf3-4xxj-qg6h
was published
for
mcp-contextforge-gateway
(pip)
Aug 25, 2026
The extension passes the raw value of a form field configured as "This field contains the name of...
Critical
Unreviewed
CVE-2026-77136
was published
Aug 25, 2026
The extension passes an editor-configurable email subject string directly into a Fluid template...
High
Unreviewed
CVE-2026-77129
was published
Aug 25, 2026
The Grav Email plugin (getgrav/grav-plugin-email) before 4.2.2 renders page-editor-controlled...
High
Unreviewed
CVE-2026-75574
was published
Aug 25, 2026
Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE)
Critical
CVE-2026-59989
was published
for
phalcon/cphalcon
(Composer)
Aug 21, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
High
CVE-2026-53964
was published
for
document-merge-service
(pip)
Aug 19, 2026
Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.
Critical
Unreviewed
CVE-2026-66613
was published
Aug 19, 2026
Interpretation of untrusted input in template engine in GBIF Integrated Publishing Toolkit...
High
Unreviewed
CVE-2026-71880
was published
Aug 18, 2026
grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint,...
High
Unreviewed
CVE-2026-75829
was published
Aug 18, 2026
Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action...
High
Unreviewed
CVE-2026-72827
was published
Aug 14, 2026
CamaleonCMS 2.9.1 contains a server-side template injection vulnerability that allows...
High
Unreviewed
CVE-2026-73330
was published
Aug 12, 2026
A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier,...
Critical
Unreviewed
CVE-2026-15734
was published
Aug 7, 2026
The render-template component of ember-dynamic-render-template (addon/components/render-template...
Moderate
Unreviewed
CVE-2026-71286
was published
Aug 5, 2026
Bolt CMS renders content field values through Twig's full application-level Environment with no...
High
Unreviewed
CVE-2026-71291
was published
Aug 5, 2026
DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through...
High
Unreviewed
CVE-2026-71239
was published
Aug 5, 2026
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used...
Critical
Unreviewed
CVE-2026-48323
was published
Aug 4, 2026
@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification
Moderate
GHSA-xrmj-5g4g-8987
was published
for
@dynatrace-oss/dynatrace-mcp-server
(npm)
Jul 31, 2026
A Server-Side Template Injection (SSTI) vulnerability was identified
in the mail template...
Critical
Unreviewed
CVE-2026-9177
was published
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
High
CVE-2026-54666
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
ProTip!
Advisories are also available from the
GraphQL API