GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
106 advisories
Filter by severity
Orval: Import-time RCE via query-parameter default -> zod module-level template literal
Critical
CVE-2026-72716
was published
for
orval
(npm)
Sep 2, 2026
Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance)
Critical
CVE-2026-55559
was published
for
org.yamcs:yamcs-core
(Maven)
Aug 28, 2026
silverstripe-advancedworkflow vulnerable to remote code execution via advanced workflow email template
High
CVE-2026-54718
was published
for
symbiote/silverstripe-advancedworkflow
(Composer)
Aug 27, 2026
mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
High
GHSA-vwf3-4xxj-qg6h
was published
for
mcp-contextforge-gateway
(pip)
Aug 25, 2026
Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE)
Critical
CVE-2026-59989
was published
for
phalcon/cphalcon
(Composer)
Aug 21, 2026
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
High
CVE-2026-53964
was published
for
document-merge-service
(pip)
Aug 19, 2026
@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification
Moderate
GHSA-xrmj-5g4g-8987
was published
for
@dynatrace-oss/dynatrace-mcp-server
(npm)
Jul 31, 2026
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
High
CVE-2026-54666
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped enum string values
High
CVE-2026-54664
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
High
CVE-2026-54661
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
High
CVE-2026-54662
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field
High
CVE-2026-54654
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field
High
CVE-2026-54653
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description
High
CVE-2026-54621
was published
for
datamodel-code-generator
(pip)
Jul 28, 2026
Oh My Posh: Arbitrary command execution via template injection in the path segment
High
CVE-2026-73505
was published
for
github.com/jandedobbeleer/oh-my-posh
(Go)
Jul 24, 2026
Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
Critical
GHSA-w28w-gp39-m4p6
was published
for
@prompty/core
(npm)
Jul 24, 2026
YesWiki: Authenticated (Admin) Server-Side Template Injection to Remote Code Execution via Bazar Semantic Templates
High
CVE-2026-52762
was published
for
yeswiki/yeswiki
(Composer)
Jul 9, 2026
Formie Hidden field defaults vulnerable to Server-Side Template Injection
Critical
CVE-2026-52889
was published
for
verbb/formie
(Composer)
Jul 6, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates
Critical
CVE-2026-9558
was published
for
mautic/core
(Composer)
Jul 2, 2026
GeoNetwork has reflected XSS through client-side template injection
High
CVE-2026-39379
was published
for
org.geonetwork-opensource:geonetwork
(Maven)
Jul 1, 2026
Gogs has DoS in rendering issue index pattern
Low
CVE-2026-52796
was published
for
gogs.io/gogs
(Go)
Jun 22, 2026
Pimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed
High
CVE-2026-11407
was published
for
pimcore/pimcore
(Composer)
Jun 17, 2026
Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection resulting in Remote Code Execution
Critical
CVE-2026-44181
was published
for
jupyter_enterprise_gateway
(pip)
Jun 3, 2026
Apache Airflow vulnerable to Improper Neutralization of Special Elements Used in a Template Engine
Critical
CVE-2026-42252
was published
for
apache-airflow
(pip)
Jun 1, 2026
compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI)
High
CVE-2026-46439
was published
for
compliance-trestle
(pip)
May 28, 2026
ProTip!
Advisories are also available from the
GraphQL API