Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6 advisories

Loading
LangGraph Checkpoint affected by RCE in "json" mode of JsonPlusSerializer High
CVE-2025-64439 was published for langgraph-checkpoint (pip) Nov 5, 2025
joernchen Credited to joernchen
graphql allows remote code execution when loading a crafted GraphQL schema Critical
CVE-2025-27407 was published for graphql (RubyGems) Mar 12, 2025
yvvdwf Credited to yvvdwf, rmosolgo, joernchen, and adarshan-gl rmosolgo rmosolgo
joernchen joernchen adarshan-gl adarshan-gl
jj vulnerable to path traversal via crafted Git repositories Critical
CVE-2024-51990 was published for jj-lib (Rust) Nov 7, 2024
joernchen Credited to joernchen and yuja yuja yuja
Dex vulnerable to Man-in-the-Middle allowing ID token capture via intercepted authorization code Critical
CVE-2022-39222 was published for github.com/dexidp/dex (Go) Oct 3, 2022
joernchen Credited to joernchen, bobcallaway, and Hayden-IO bobcallaway bobcallaway
Hayden-IO Hayden-IO
joernchen Credited to joernchen
Command Injection vulnerability in asciidoctor-include-ext Critical
CVE-2022-24803 was published for asciidoctor-include-ext (RubyGems) Mar 31, 2022
joernchen Credited to joernchen
ProTip! Advisories are also available from the GraphQL API