Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

60 advisories

Loading
GitHub CLI: GitHub Actions log output in `gh run view` allows terminal escape sequence injection Low
CVE-2026-45803 was published for github.com/cli/cli (Go) May 19, 2026
Shescape: Shell injection via unescaped parentheses on Windows with CMD Critical
CVE-2026-73414 was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data Moderate
CVE-2026-73506 was published for github.com/jandedobbeleer/oh-my-posh (Go) Jul 24, 2026
ihopenre-eng Credited to ihopenre-eng
Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI Moderate
CVE-2026-54162 was published for github.com/alexandre-daubois/ember (Go) Aug 20, 2026
alexandre-daubois Credited to alexandre-daubois
pickem vulnerable to terminal escape-sequence injection via unsanitized item text High
GHSA-8qx3-8gm5-9cj2 was published for pickem (npm) Aug 25, 2026
ProTip! Advisories are also available from the GraphQL API