Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,105 advisories

Loading
SiYuan MCP asset.upload Reads Arbitrary Absolute File Paths (Workspace Boundary Bypass) Moderate
GHSA-p23f-cm6q-2qp8 was published for github.com/siyuan-note/siyuan/kernel (Go) Oct 2, 2026
joysinleung Credited to joysinleung
Composer: GHSA-gjfg-22fp-rrxx fix bypass via symlinked package bin path Moderate
CVE-2026-59944 was published for composer/composer (Composer) Oct 2, 2026
DavidCarliez Credited to DavidCarliez, manus-use, and arpitjain099 manus-use manus-use
arpitjain099 arpitjain099
arpitjain099 Credited to arpitjain099
GitPython submodule update path traversal can write outside the repository Moderate
GHSA-59cr-6r3x-644w was published for GitPython (pip) Sep 30, 2026
kta1kri Credited to kta1kri
Author Arbitrary File Deletion in WEBO MCP <= 3.0.18 versions. Moderate Unreviewed
CVE-2026-97242 was published Sep 30, 2026
Editor Arbitrary File Deletion in Template Kit – Import <= 1.0.16 versions. Moderate Unreviewed
CVE-2026-96824 was published Sep 30, 2026
A weakness has been identified in PMWeb 7.x/8.x/2025.x. This issue affects some unknown... Moderate Unreviewed
CVE-2026-101082 was published Sep 28, 2026
A security flaw has been discovered in dbgate up to 7.3.1. This impacts the function... Moderate Unreviewed
CVE-2026-101068 was published Sep 28, 2026
ProTip! Advisories are also available from the GraphQL API