GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,518
Maven
5,000+
npm
5,000+
NuGet
911
pip
4,758
Pub
13
RubyGems
1,036
Rust
1,228
Swift
53
Unreviewed advisories
All unreviewed
5,000+
76 advisories
Filter by severity
MCP Server Kubernetes has an Argument Injection in port_forward tool via space-splitting
High
CVE-2026-39884
was published
for
mcp-server-kubernetes
(npm)
Apr 14, 2026
SSH/SCP option injection allowing local RCE in @aiondadotcom/mcp-ssh
High
GHSA-p4h8-56qp-hpgv
was published
for
@aiondadotcom/mcp-ssh
(npm)
Apr 14, 2026
PraisonAI Vulnerable to Argument Injection into Cloud Run Environment Variables via Unsanitized Comma in gcloud --set-env-vars
High
CVE-2026-40113
was published
for
PraisonAI
(pip)
Apr 10, 2026
skilleton has improper input handling in repository/path processing
Moderate
GHSA-5g3j-89fr-r2vp
was published
for
skilleton
(npm)
Apr 8, 2026
File Browser has a Command Injection via Hook Runner
High
CVE-2026-35585
was published
for
github.com/filebrowser/filebrowser/v2
(Go)
Apr 8, 2026
Roundcube Webmail: Unsanitized IMAP SEARCH command arguments
Low
CVE-2026-35538
was published
for
roundcube/roundcubemail
(Composer)
Apr 3, 2026
Electron: Renderer command-line switch injection via undocumented commandLineSwitches webPreference
High
CVE-2026-34769
was published
for
electron
(npm)
Apr 3, 2026
Duplicate Advisory: OpenClaw's Node system.run approval hardening wrapper semantic drift can execute unintended local scripts
Moderate
GHSA-g87j-gm7p-6vw2
was published
for
openclaw
(npm)
Mar 19, 2026
•
withdrawn
Gogs: Release tag option injection in release deletion
High
CVE-2026-26194
was published
for
gogs.io/gogs
(Go)
Mar 5, 2026
OpenClaw's Node system.run approval hardening wrapper semantic drift can execute unintended local scripts
Moderate
CVE-2026-29608
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw has Windows system.run approval mismatch on cmd.exe /c trailing arguments
High
CVE-2026-22168
was published
for
openclaw
(npm)
Mar 2, 2026
OpenClaw has an exec allowlist bypass via command substitution/backticks inside double quotes
High
CVE-2026-28470
was published
for
openclaw
(npm)
Feb 17, 2026
Weblate has an argument injection in management console
Moderate
CVE-2026-24126
was published
for
Weblate
(pip)
Feb 17, 2026
Symfony's incorrect argument escaping under MSYS2/Git Bash can lead to destructive file operations on Windows
Moderate
CVE-2026-24739
was published
for
symfony/process
(Composer)
Jan 28, 2026
mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files
Moderate
CVE-2025-68144
was published
for
mcp-server-git
(pip)
Dec 17, 2025
Cloudinary Node SDK is vulnerable to Arbitrary Argument Injection through parameters that include an ampersand
High
CVE-2025-12613
was published
for
cloudinary
(npm)
Nov 10, 2025
tracexec has `env` command argument injection via environment variables starting with dash in traced exec events
Low
GHSA-6fgx-x7m2-74qm
was published
for
tracexec
(Rust)
Oct 13, 2025
go-mail has insufficient address encoding when passing mail addresses to the SMTP client
High
CVE-2025-59937
was published
for
github.com/wneessen/go-mail
(Go)
Sep 29, 2025
@conventional-changelog/git-client has Argument Injection vulnerability
Moderate
CVE-2025-59433
was published
for
@conventional-changelog/git-client
(npm)
Sep 22, 2025
filebrowser Allows Shell Commands to Spawn Other Commands
High
CVE-2025-52903
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 27, 2025
DevDojo Voyager Argument Injection vulnerability
Critical
CVE-2025-32931
was published
for
tcg/voyager
(Composer)
Apr 14, 2025
Matrix IRC Bridge allows IRC command injection to own puppeted user
Low
CVE-2025-27146
was published
for
matrix-appservice-irc
(npm)
Feb 25, 2025
go-git has an Argument Injection via the URL field
Critical
CVE-2025-21613
was published
for
github.com/go-git/go-git/v5
(Go)
Jan 6, 2025
Gogs has an argument Injection in the built-in SSH server
Critical
CVE-2024-39930
was published
for
gogs.io/gogs
(Go)
Dec 23, 2024
Gogs allows argument Injection when tagging new releases
High
CVE-2024-39933
was published
for
gogs.io/gogs
(Go)
Dec 23, 2024
ProTip!
Advisories are also available from the
GraphQL API