Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

750 advisories

Loading
Xinference vulnerable to remote code execution via unsafe `eval()` in Llama3 tool-call parsing Critical
CVE-2026-61539 was published for xinference (pip) Aug 21, 2026
XlabAITeam Credited to XlabAITeam, keenanwgn, and A7um keenanwgn keenanwgn
A7um A7um
surfio has an out-of-bounds read Critical
CVE-2026-55211 was published for surfio (pip) Aug 18, 2026
oddmunds Credited to oddmunds
oddmunds Credited to oddmunds
freeman-bb Credited to freeman-bb, y011d4, ibondarenko1, h1-mrz, and th3cyb3rc0p y011d4 y011d4
ibondarenko1 ibondarenko1 h1-mrz h1-mrz th3cyb3rc0p th3cyb3rc0p
manus-use Credited to manus-use and BarakSrour BarakSrour BarakSrour
Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules) Critical
CVE-2026-67429 was published for flyto-core (pip) Jul 30, 2026
kaimandalic Credited to kaimandalic
Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding Critical
CVE-2026-64825 was published for homeassistant (pip) Jul 21, 2026
PercevalFox Credited to PercevalFox
patchmyday Credited to patchmyday
LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests Critical
CVE-2026-61736 was published for lightrag-hku (pip) Jul 20, 2026
MaramHarsha Credited to MaramHarsha
DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval Critical
CVE-2026-61667 was published for DIRAC (pip) Jul 13, 2026
sfayer Credited to sfayer
DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input Critical
CVE-2026-45579 was published for DIRAC (pip) Jul 13, 2026
sfayer Credited to sfayer
mcp-server-kubernetes argument injection can expose Kubernetes cluster credentials Critical
CVE-2026-61459 was published for mcp-server-kubernetes (pip) Jul 10, 2026
PercevalFox Credited to PercevalFox
YLChen-007 Credited to YLChen-007
fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection Critical
CVE-2026-52830 was published for fast-mcp-telegram (pip) Jul 2, 2026
DavidCarliez Credited to DavidCarliez
mcp-memory-service: Missing Authentication on Document API Endpoints Allows Unauthenticated Memory Read/Write/Delete Critical
CVE-2026-50027 was published for mcp-memory-service (pip) Jul 2, 2026
EQSTLab Credited to EQSTLab
mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind Critical
CVE-2026-49257 was published for mcp-pinot-server (pip) Jun 26, 2026
raysabee Credited to raysabee and PeledTomer1 PeledTomer1 PeledTomer1
semantic-router exposed to compromised litellm wheel (CVE-2026-42208) via unbounded transitive pin Critical
GHSA-98x5-vq43-vc5p was published for semantic-router (pip) Jun 26, 2026
jamescalam Credited to jamescalam
Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication Critical
CVE-2026-48797 was published for @mcptoolshop/backpropagate (npm) Jun 26, 2026
Lemur: ACME SSRF + creator-equality IDOR lead to AWS IAM/PKI compromise Critical
CVE-2026-55166 was published for lemur (pip) Jun 25, 2026
im-rootkid Credited to im-rootkid
motionEye Partial Authentication Bypass: Unauthenticated Admin Credential Theft via Path Traversal Critical
GHSA-phv5-334h-mxcw was published for motioneye (pip) Jun 23, 2026
pizza-power Credited to pizza-power and MichaIng MichaIng MichaIng
motionEye: LFI → pass‑the‑hash admin → unsafe restore → unauth action exec (RCE) Critical
GHSA-qxvg-h7q2-hcxh was published for motioneye (pip) Jun 23, 2026
C4spr0x1A Credited to C4spr0x1A and MichaIng MichaIng MichaIng
motionEye: Authentication possible via password hash Critical
CVE-2026-46488 was published for motioneye (pip) Jun 22, 2026
FireByteApplications Credited to FireByteApplications, 0xLynk, dimashn04, C4spr0x1A, sighnwaive, MichaIng, Marijn0, and zagrim 0xLynk 0xLynk
dimashn04 dimashn04 C4spr0x1A C4spr0x1A sighnwaive sighnwaive MichaIng MichaIng Marijn0 Marijn0 zagrim zagrim
Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit Critical
CVE-2026-55447 was published for langflow (pip) Jun 19, 2026
vbCrLf Credited to vbCrLf, AntonioABLima, andifilhohub, erichare, and Adam-Aghili AntonioABLima AntonioABLima
andifilhohub andifilhohub erichare erichare Adam-Aghili Adam-Aghili
ProTip! Advisories are also available from the GraphQL API