Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

50 advisories

Loading
sondt99 Credited to sondt99, dungNHVhust, and sai-sh dungNHVhust dungNHVhust
sai-sh sai-sh
CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes High
CVE-2026-75914 was published for codewhale (npm) Sep 4, 2026
fg0x0 Credited to fg0x0
Prompty: Arbitrary file read via file reference expansion High
CVE-2026-53598 was published for @prompty/core (npm) Jul 17, 2026
wnsgurd90-keke Credited to wnsgurd90-keke
Rattler vulnerable to package cache path traversal via conda package build string Moderate
CVE-2026-53956 was published for py_rattler (pip) Jul 9, 2026
chmod: --preserve-root bypassed by any path that resolves to root (e.g. /../) High
CVE-2026-35338 was published for uu_chmod (Rust) Jul 6, 2026
mise HTTP backend uses raw version path for install symlink destination Moderate
CVE-2026-54557 was published for mise (Rust) Jun 23, 2026
mosskappa Credited to mosskappa
SurrealDB: Arbitrary file read via DEFINE ANALYZER mapper() filter High
GHSA-cc8f-fcx3-gpjr was published for surrealdb (Rust) Jun 19, 2026
kah-ja Credited to kah-ja
yannsar Credited to yannsar
Routinator has cache path traversal when processing the module component of rsync URIs High
CVE-2026-49233 was published for routinator (Rust) Jun 8, 2026
skillctl: Path traversal and symlink-follow in skillctl allow arbitrary file disclosure and deletion High
GHSA-wx3m-whqv-xv47 was published for skillctl (Rust) Jun 5, 2026
rattler has an entry-point path traversal in noarch:python install (arbitrary file write) Moderate
CVE-2026-47425 was published for py-rattler (pip) Jun 1, 2026
berkant-koc Credited to berkant-koc
uv is vulnerable to arbitrary file write through entry point names Moderate
GHSA-4gg8-gxpx-9rph was published for uv (pip) May 29, 2026
zsol Credited to zsol and zanieb zanieb zanieb
Shamefile has an arbitrary file read via shamefile.yaml in shame next Moderate
CVE-2026-47144 was published for shamefile (npm) May 28, 2026
BKDDFS Credited to BKDDFS
Boxlite: Path Traversal Vulnerability Leads to Arbitrary File Write on the Host Critical
CVE-2026-46703 was published for @boxlite-ai/boxlite (Go) May 21, 2026
XlabAITeam Credited to XlabAITeam, keenanwgn, and A7um keenanwgn keenanwgn
A7um A7um
N0zoM1z0 Credited to N0zoM1z0
gix and gitoxide's symlinked .gitmodules are followed and parsed from outside of the repository High
GHSA-pg4w-g64p-qwhj was published for gitoxide (Rust) May 5, 2026
N0zoM1z0 Credited to N0zoM1z0
kodareef5 Credited to kodareef5
Duplicate Advisory: uutils coreutils has a Path Traversal issue Moderate
GHSA-vchc-9ggh-3236 was published for coreutils (Rust) Apr 22, 2026 • withdrawn
Duplicate Advisory: uutils coreutils allows users to bypass the --preserve-root safety mechanism High
GHSA-9gqx-53gp-c8g3 was published for coreutils (Rust) Apr 22, 2026 • withdrawn
Salvo has a Path Traversal in salvo-proxy::encode_url_path allows API Gateway Bypass High
CVE-2026-33242 was published for salvo (Rust) Mar 19, 2026
tomasilluminati Credited to tomasilluminati
ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink High
CVE-2026-32232 was published for zeptoclaw (Rust) Mar 12, 2026
zpbrent Credited to zpbrent
ProTip! Advisories are also available from the GraphQL API