Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

189 advisories

Loading
RestrictedPython guard hooks can be shadowed via positional-only arguments High
CVE-2026-55830 was published for RestrictedPython (pip) Aug 28, 2026
Neroli-realy Credited to Neroli-realy, dataflake, and taisehub dataflake dataflake
taisehub taisehub
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0 High
CVE-2026-52776 was published for compliance-trestle (pip) Aug 12, 2026
tonghuaroot Credited to tonghuaroot
Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts Moderate
GHSA-957r-qf9p-67xw was published for craftcms/cms (Composer) Aug 6, 2026
je-lv Credited to je-lv
Ghost: Private IP filtering bypass to make server-side requests to internal services Moderate
CVE-2026-53944 was published for ghost (npm) Aug 4, 2026
l3tchupkt Credited to l3tchupkt
Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE Critical
CVE-2026-70470 was published for flowise (npm) Aug 4, 2026
fg0x0 Credited to fg0x0
leoelsolh Credited to leoelsolh
NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass Moderate
CVE-2026-52888 was published for @nocobase/plugin-collection-sql (npm) Jul 28, 2026
lucquach Credited to lucquach
manus-use Credited to manus-use
MoonFuji Credited to MoonFuji
GitPython: Command Injection via git long-option prefix abbreviation bypass of CVE-2026-42215 blocklist High
GHSA-2f96-g7mh-g2hx was published for GitPython (pip) Jul 21, 2026
hackkim Credited to hackkim and abhiprd2000 abhiprd2000 abhiprd2000
SVGO removeScripts plugin leaves some executable scripts intact High
CVE-2026-73650 was published for svgo (npm) Jul 21, 2026
Admu-Dev Credited to Admu-Dev
DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements. Low
GHSA-c2j3-45gr-mqc4 was published for dompurify (npm) Jul 21, 2026
Rikuxx0 Credited to Rikuxx0
connorshea Credited to connorshea
ProTip! Advisories are also available from the GraphQL API