GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
151 advisories
Filter by severity
YesWiki vulnerable to unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action
Critical
CVE-2026-52766
was published
for
yeswiki/yeswiki
(Composer)
Jul 9, 2026
turso-cli persists Turso platform JWT with world-readable (0o644) file permissions
Moderate
CVE-2026-48790
was published
for
github.com/tursodatabase/turso-cli
(Go)
Jun 26, 2026
nextflow auth login command has incorrect default permissions
Moderate
CVE-2026-48722
was published
for
io.nextflow:nextflow
(Maven)
Jun 25, 2026
OpenClaw: Config recovery could restore openclaw.json with broad file permissions
Moderate
CVE-2026-53856
was published
for
openclaw
(npm)
Jun 18, 2026
Hermes Agent creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644)
Moderate
CVE-2026-53870
was published
for
hermes-agent
(pip)
Jun 17, 2026
Nuxt dev server vite-node IPC socket is world-connectable on Linux
Moderate
GHSA-534h-c3cw-v3h9
was published
for
nuxt
(npm)
Jun 16, 2026
Apache ActiveMQ has an Incorrect Default Permissions vulnerability
High
CVE-2026-49157
was published
for
org.apache.activemq:apache-activemq
(Maven)
Jun 1, 2026
Spring AI: ChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakage
High
CVE-2026-41712
was published
for
org.springframework.ai:spring-ai-advisors-vector-store
(Maven)
May 12, 2026
openclaw-claude-bridge: sandbox is not effective - `--allowed-tools ""` does not restrict available tools
Moderate
CVE-2026-39398
was published
for
openclaw-claude-bridge
(npm)
Apr 8, 2026
Claude SDK for Python has Insecure Default File Permissions in Local Filesystem Memory Tool
Moderate
CVE-2026-34450
was published
for
anthropic
(pip)
Apr 1, 2026
Capgo CLI: symlink-following local secret writes enable arbitrary file overwrite + world-readable credentials (0600 missing)
High
GHSA-8mpm-q7mh-8fvh
was published
for
@capgo/cli
(npm)
Mar 18, 2026
OpenClaw session transcript files were created without forced user-only permissions
Moderate
CVE-2026-33572
was published
for
openclaw
(npm)
Mar 16, 2026
.NET Elevation of Privilege Vulnerability
High
CVE-2026-26131
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Mar 11, 2026
Duplicate Advisory: Microsoft Security Advisory CVE-2026-26131 – .NET Elevation of Privilege Vulnerability
High
GHSA-387c-qmrw-59qv
was published
for
Microsoft.NetCore.App.Runtime.linux-arm
(NuGet)
Mar 10, 2026
•
withdrawn
AWS CLI: cli_history database does not restrict file permissions on Unix systems
Moderate
GHSA-747p-wmpv-9c78
was published
for
awscli
(pip)
Feb 27, 2026
AutoGPT is Vulnerable to RCE via Disabled Block Execution
High
CVE-2026-24780
was published
for
agpt
(pip)
Jan 29, 2026
Pepr Has Overly Permissive RBAC ClusterRole in Admin Mode
Low
CVE-2026-23634
was published
for
pepr
(npm)
Jan 15, 2026
Mattermost allows other users to determine when users had read channels via channel member objects
Low
CVE-2025-55074
was published
for
github.com/mattermost/mattermost-server
(Go)
Nov 18, 2025
XWiki AdminTools application doesn't set permissions on the AdminTools space
Moderate
CVE-2025-54990
was published
for
com.xwiki.admintools:application-admintools
(Maven)
Nov 18, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes
Moderate
CVE-2025-64436
was published
for
kubevirt.io/kubevirt
(Go)
Nov 6, 2025
Dragonfly's directories created via os.MkdirAll are not checked for permissions
Low
CVE-2025-59349
was published
for
d7y.io/dragonfly/v2
(Go)
Sep 17, 2025
Apache DolphinScheduler Incorrect Default Permissions Vulnerability
Low
CVE-2024-43166
was published
for
org.apache.dolphinscheduler:dolphinscheduler
(Maven)
Sep 3, 2025
operator-sdk: privilege escalation due to incorrect permissions of /etc/passwd
Moderate
CVE-2025-7195
was published
for
github.com/operator-framework/operator-sdk
(Go)
Aug 7, 2025
melange's world-writable permissions expose SBOM files to potential image tampering
Moderate
CVE-2025-54059
was published
for
chainguard.dev/melange
(Go)
Jul 18, 2025
apko is vulnerable to attack through incorrect permissions in /etc/ld.so.cache and other files
High
CVE-2025-53945
was published
for
chainguard.dev/apko
(Go)
Jul 18, 2025
ProTip!
Advisories are also available from the
GraphQL API