GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
118 advisories
Filter by severity
senaite.core Vulnerable to Eval Injection and Missing Authorization
Critical
CVE-2026-54569
was published
for
senaite.core
(pip)
Aug 26, 2026
OpenWISP IPAM has broken object-level authorization: ExportSubnetView lets a member of one organization export another organization's subnet and all its IP addresses
Moderate
GHSA-x287-5c68-36wp
was published
for
openwisp-ipam
(pip)
Aug 26, 2026
PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced
High
CVE-2026-55541
was published
for
PraisonAI
(pip)
Aug 25, 2026
praisonaiagents: ast_grep_rewrite rewrites arbitrary files without the @require_approval gate enforced on every sibling mutation tool
Moderate
CVE-2026-55530
was published
for
praisonaiagents
(pip)
Aug 25, 2026
praisonaiagents: AgentServer declares auth_token but never enforces it on any route
High
CVE-2026-55528
was published
for
praisonaiagents
(pip)
Aug 25, 2026
django CMS: Missing authorization in `render_object_structure` discloses non-PageContent placeholder structure to low-privileged staff
Moderate
CVE-2026-61663
was published
for
django-cms
(pip)
Aug 20, 2026
django CMS: Broken access control in page *Duplicate* allows reading the content of any page (cross-site / restriction bypass)
Moderate
CVE-2026-63003
was published
for
django-cms
(pip)
Aug 20, 2026
django CMS: Structure endpoint bypasses page-view permission
Moderate
CVE-2026-54624
was published
for
django-cms
(pip)
Aug 20, 2026
Lemur: Missing authorization check on POST /certificates/<id>/export for plugins with requires_key = False
Moderate
CVE-2026-71322
was published
for
lemur
(pip)
Aug 18, 2026
Lemur: Sub-CA creation never checks `AuthorityPermission` on the parent authority
Moderate
CVE-2026-71317
was published
for
lemur
(pip)
Aug 18, 2026
Lemur: Unchecked `replaces[]` lets any user silence notifications and hijack auto-rotation for arbitrary certificates
High
CVE-2026-71308
was published
for
lemur
(pip)
Aug 18, 2026
Lemur: Authenticated low-privilege users can read plaintext destination credentials (SFTP password / private-key passphrase) via the destinations API
High
CVE-2026-71307
was published
for
lemur
(pip)
Aug 18, 2026
GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data
High
CVE-2026-55178
was published
for
@geolens/sdk
(npm)
Aug 18, 2026
Open WebUI: A folder write-collaborator can permanently delete the owner's chats by deleting a shared subfolder
High
CVE-2026-70494
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge metadata
Moderate
CVE-2026-70487
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Users denied the image-generation permission can still generate images via chat completions
Moderate
CVE-2026-70484
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Any authenticated user can cancel another user's chat generation via the chat delete endpoint
Low
CVE-2026-70483
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Any member with write access to a standard channel can edit or delete other members' messages
Moderate
CVE-2026-70481
was published
for
open-webui
(pip)
Aug 4, 2026
Open WebUI: Arena task endpoints can bypass underlying model access controls
Moderate
CVE-2026-59225
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)
Moderate
CVE-2026-59217
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
High
CVE-2026-59216
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Cross-channel message overwrite via chat completion API (single-model and multimodel message_ids)
High
CVE-2026-59714
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission
Moderate
CVE-2026-59227
was published
for
open-webui
(pip)
Jul 24, 2026
Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation
Low
CVE-2026-59226
was published
for
open-webui
(pip)
Jul 24, 2026
MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks
High
CVE-2026-52870
was published
for
mcp
(pip)
Jul 16, 2026
ProTip!
Advisories are also available from the
GraphQL API