Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

9,925 advisories

Loading
SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass) Moderate
GHSA-p23f-cm6q-2qp8 was published for github.com/siyuan-note/siyuan/kernel (Go) Oct 2, 2026
joysinleung Credited to joysinleung
Vibe-Trading file-read tools expose arbitrary server-readable files High
GHSA-5rmq-chc7-m22f was published for vibe-trading-ai (pip) Oct 2, 2026
lemi9090 Credited to lemi9090
Composer: GHSA-gjfg-22fp-rrxx fix bypass via symlinked package bin path Moderate
CVE-2026-59944 was published for composer/composer (Composer) Oct 2, 2026
DavidCarliez Credited to DavidCarliez, manus-use, and arpitjain099 manus-use manus-use
arpitjain099 arpitjain099
Dulwich: Arbitrary File Write (RCE) on Windows via Unvalidated Drive Letters in Tree Paths High
GHSA-8mcx-5rqc-vhmf was published for dulwich (pip) Oct 2, 2026
LukeBanto Credited to LukeBanto and jelmer jelmer jelmer
Dulwich: Symlink directory traversal in filter-branch index_filter via cross-commit state persistence High
GHSA-5fqc-mrg8-w798 was published for dulwich (pip) Oct 2, 2026
manus-use Credited to manus-use and jelmer jelmer jelmer
manus-use Credited to manus-use and jelmer jelmer jelmer
arpitjain099 Credited to arpitjain099
ProTip! Advisories are also available from the GraphQL API