Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

106 advisories

Loading
Orval: Import-time RCE via query-parameter default -> zod module-level template literal Critical
CVE-2026-72716 was published for orval (npm) Sep 2, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance) Critical
CVE-2026-55559 was published for org.yamcs:yamcs-core (Maven) Aug 28, 2026
MarkLee131 Credited to MarkLee131 and manus-use manus-use manus-use
silverstripe-advancedworkflow vulnerable to remote code execution via advanced workflow email template High
CVE-2026-54718 was published for symbiote/silverstripe-advancedworkflow (Composer) Aug 27, 2026
Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE) Critical
CVE-2026-59989 was published for phalcon/cphalcon (Composer) Aug 21, 2026
nikkoenggaliano Credited to nikkoenggaliano
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes) High
CVE-2026-53964 was published for document-merge-service (pip) Aug 19, 2026
sofianeelhor Credited to sofianeelhor, c0rydoras, and tonghuaroot c0rydoras c0rydoras
tonghuaroot tonghuaroot
@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification Moderate
GHSA-xrmj-5g4g-8987 was published for @dynatrace-oss/dynatrace-mcp-server (npm) Jul 31, 2026
yotampe-pluto Credited to yotampe-pluto
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies High
CVE-2026-54666 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
swagger-typescript-api vulnerable to code injection via unescaped enum string values High
CVE-2026-54664 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template High
CVE-2026-54661 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template High
CVE-2026-54662 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
thegr1ffyn Credited to thegr1ffyn
`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field High
CVE-2026-54653 was published for datamodel-code-generator (pip) Jul 28, 2026
thegr1ffyn Credited to thegr1ffyn
`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description High
CVE-2026-54621 was published for datamodel-code-generator (pip) Jul 28, 2026
thegr1ffyn Credited to thegr1ffyn
Oh My Posh: Arbitrary command execution via template injection in the path segment High
CVE-2026-73505 was published for github.com/jandedobbeleer/oh-my-posh (Go) Jul 24, 2026
ihopenre-eng Credited to ihopenre-eng
Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer Critical
GHSA-w28w-gp39-m4p6 was published for @prompty/core (npm) Jul 24, 2026
lexdotdev Credited to lexdotdev
hash3liZer Credited to hash3liZer and eros938 eros938 eros938
Formie Hidden field defaults vulnerable to Server-Side Template Injection Critical
CVE-2026-52889 was published for verbb/formie (Composer) Jul 6, 2026
Mautic has Server-Side Template Injection (SSTI) in Theme Templates Critical
CVE-2026-9558 was published for mautic/core (Composer) Jul 2, 2026
onurcangnc Credited to onurcangnc, xfer0, Entropt, patrykgruszka, escopecz, LeuchtfeuerDigitalMarketing, and NumberOreo1 xfer0 xfer0
Entropt Entropt patrykgruszka patrykgruszka escopecz escopecz LeuchtfeuerDigitalMarketing LeuchtfeuerDigitalMarketing NumberOreo1 NumberOreo1
GeoNetwork has reflected XSS through client-side template injection High
CVE-2026-39379 was published for org.geonetwork-opensource:geonetwork (Maven) Jul 1, 2026
Timonheu Credited to Timonheu, juanluisrp, and jodygarnett juanluisrp juanluisrp
jodygarnett jodygarnett
Gogs has DoS in rendering issue index pattern Low
CVE-2026-52796 was published for gogs.io/gogs (Go) Jun 22, 2026
BaiMeow Credited to BaiMeow
Pimcore CMS Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed High
CVE-2026-11407 was published for pimcore/pimcore (Composer) Jun 17, 2026
astapc Credited to astapc
Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection resulting in Remote Code Execution Critical
CVE-2026-44181 was published for jupyter_enterprise_gateway (pip) Jun 3, 2026
ben-elttam Credited to ben-elttam and lresende lresende lresende
Apache Airflow vulnerable to Improper Neutralization of Special Elements Used in a Template Engine Critical
CVE-2026-42252 was published for apache-airflow (pip) Jun 1, 2026
compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI) High
CVE-2026-46439 was published for compliance-trestle (pip) May 28, 2026
l3tchupkt Credited to l3tchupkt
ProTip! Advisories are also available from the GraphQL API