GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,714
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,151
Rust
1,567
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
21 advisories
Filter by severity
Command Injection in ascii-art
Low
GHSA-9hqj-38j2-5jgm
was published
for
ascii-art
(npm)
Sep 1, 2020
Environment Variable Injection in GitHub Actions
Low
CVE-2020-15228
was published
for
@actions/core
(npm)
Oct 1, 2020
Improper Neutralization of Special Elements used in a Command ('Command Injection') in @floffah/build
Low
GHSA-jcgr-9698-82jx
was published
for
@floffah/build
(npm)
May 28, 2021
Command injection in @diez/generation
Low
CVE-2021-32830
was published
for
@diez/generation
(npm)
Sep 2, 2021
Imperative CLI vulnerable to Command Injection
Low
CVE-2021-4326
was published
for
@zowe/imperative
(npm)
Mar 1, 2023
sshproxy vulnerable to SSH option injection
Low
CVE-2024-34713
was published
for
github.com/cea-hpc/sshproxy
(Go)
May 14, 2024
Matrix IRC Bridge allows IRC command injection to own puppeted user
Low
CVE-2025-27146
was published
for
matrix-appservice-irc
(npm)
Feb 25, 2025
AWorld OS Command Injection vulnerability
Low
CVE-2025-4032
was published
for
aworld
(pip)
Apr 28, 2025
Terraform WinDNS Provider improperly sanitizes input variables in `windns_record`
Low
CVE-2025-46735
was published
for
github.com/nrkno/terraform-provider-windns
(Go)
May 6, 2025
Ackites KillWxapkg vulnerable to OS Command Injection
Low
CVE-2025-5030
was published
for
github.com/Ackites/KillWxapkg
(Go)
May 21, 2025
wong2 mcp-cli Command Injection Vulnerability
Low
CVE-2025-9262
was published
for
@wong2/mcp-cli
(npm)
Aug 21, 2025
PyPI publish GitHub Action vulnerable to injectable expression expansions in action steps
Low
GHSA-vxmw-7h4f-hqxh
was published
for
pypa/gh-action-pypi-publish
(GitHub Actions)
Sep 4, 2025
MCPHub's ServerController is vulnerable to Command Injection
Low
CVE-2025-11285
was published
for
@samanhappy/mcphub
(npm)
Oct 5, 2025
tracexec has `env` command argument injection via environment variables starting with dash in traced exec events
Low
GHSA-6fgx-x7m2-74qm
was published
for
tracexec
(Rust)
Oct 13, 2025
xcode-mcp-server vulnerable to Command Injection
Low
CVE-2026-2178
was published
for
xcode-mcp-server
(npm)
Feb 8, 2026
Bitcoinrb Vulnerable to Command injection via RPC
Low
GHSA-q66h-m87m-j2q6
was published
for
bitcoinrb
(RubyGems)
Feb 10, 2026
ImageMagick: SVG-to-MVG Command Injection via coders/svg.c
Low
GHSA-xpg8-7m6m-jf56
was published
for
Magick.NET-Q16-AnyCPU
(NuGet)
Feb 25, 2026
@elgentos/magento2-dev-mcp vulnerable to command injection
Low
CVE-2026-5603
was published
for
@elgentos/magento2-dev-mcp
(npm)
Apr 6, 2026
@nor2/heim-mcp vulnerable to command injection
Low
CVE-2026-5602
was published
for
@nor2/heim-mcp
(npm)
Apr 6, 2026
yii2-mcp-server has a Command Injection Issue
Low
CVE-2026-7600
was published
for
yii2-mcp-server
(npm)
May 2, 2026
ProTip!
Advisories are also available from the
GraphQL API