Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

118 advisories

Loading
senaite.core Vulnerable to Eval Injection and Missing Authorization Critical
CVE-2026-54569 was published for senaite.core (pip) Aug 26, 2026
snomi Credited to snomi and Volcore Volcore Volcore
dizconnectz Credited to dizconnectz and nemesifier nemesifier nemesifier
PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced High
CVE-2026-55541 was published for PraisonAI (pip) Aug 25, 2026
saisathvik1 Credited to saisathvik1
SnailSploit Credited to SnailSploit
praisonaiagents: AgentServer declares auth_token but never enforces it on any route High
CVE-2026-55528 was published for praisonaiagents (pip) Aug 25, 2026
SnailSploit Credited to SnailSploit
doanmanhducz Credited to doanmanhducz and nichoc0 nichoc0 nichoc0
fsbraun Credited to fsbraun
django CMS: Structure endpoint bypasses page-view permission Moderate
CVE-2026-54624 was published for django-cms (pip) Aug 20, 2026
Zyy0530 Credited to Zyy0530, Str1ckl4nd, 7thParkk, and mauriceng98 Str1ckl4nd Str1ckl4nd
7thParkk 7thParkk mauriceng98 mauriceng98
sour-exploit Credited to sour-exploit
Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority Moderate
CVE-2026-71317 was published for lemur (pip) Aug 18, 2026
maperu Credited to maperu
maperu Credited to maperu
legobattman Credited to legobattman and Classic298 Classic298 Classic298
Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata Moderate
CVE-2026-70487 was published for open-webui (pip) Aug 4, 2026
whyiug Credited to whyiug and Classic298 Classic298 Classic298
Open WebUI: Users denied the image-generation permission can still generate images via chat completions Moderate
CVE-2026-70484 was published for open-webui (pip) Aug 4, 2026
DavidCarliez Credited to DavidCarliez and Classic298 Classic298 Classic298
GabrielGomesAL Credited to GabrielGomesAL and Classic298 Classic298 Classic298
Foxer131 Credited to Foxer131 and Classic298 Classic298 Classic298
Open WebUI: Arena task endpoints can bypass underlying model access controls Moderate
CVE-2026-59225 was published for open-webui (pip) Jul 24, 2026
rexpository Credited to rexpository and Classic298 Classic298 Classic298
jagstack Credited to jagstack and Classic298 Classic298 Classic298
waiveyk Credited to waiveyk and Classic298 Classic298 Classic298
sfwani Credited to sfwani, DavidCarliez, and Classic298 DavidCarliez DavidCarliez
Classic298 Classic298
jagstack Credited to jagstack and Classic298 Classic298 Classic298
rexpository Credited to rexpository and Classic298 Classic298 Classic298
cjmielke Credited to cjmielke, dewankpant, and shrutilohani dewankpant dewankpant
shrutilohani shrutilohani
ProTip! Advisories are also available from the GraphQL API