GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
74
GitHub Actions
54
Go
4,087
Maven
5,000+
npm
5,000+
NuGet
994
pip
5,000+
Pub
13
RubyGems
1,095
Rust
1,414
Swift
61
Unreviewed advisories
All unreviewed
5,000+
19 advisories
Filter by severity
Improper Neutralization of Argument Delimiters in a Decompiling Package Process in APKLeaks
Critical
CVE-2021-21386
was published
for
APKLeaks
(pip)
Jan 21, 2022
Apache Airflow ODBC Provider Argument Injection vulnerability
High
CVE-2023-34395
was published
for
apache-airflow-providers-odbc
(pip)
Jun 27, 2023
Code execution in Embedchain
Critical
CVE-2024-23731
was published
for
embedchain
(pip)
Jan 21, 2024
Header injection possible in Django
Moderate
CVE-2021-32052
was published
for
Django
(pip)
Jun 9, 2021
Arbitrary command execution on Windows via qutebrowserurl: URL handler
High
CVE-2021-41146
was published
for
qutebrowser
(pip)
Oct 22, 2021
Poetry Argument Injection can lead to Local Code Execution
High
CVE-2022-36069
was published
for
poetry
(pip)
Sep 16, 2022
Argument injection in python-libnmap
Critical
CVE-2022-30284
was published
for
python-libnmap
(pip)
May 6, 2022
Codecov does not sanitize gcov arguments
High
CVE-2019-10800
was published
for
codecov
(pip)
Jul 14, 2022
Improper Neutralization of Special Elements used in a Command ('Command Injection') in Weblate
High
CVE-2022-23915
was published
for
Weblate
(pip)
Mar 4, 2022
mcp-server-git argument injection in git_diff and git_checkout functions allows overwriting local files
Moderate
CVE-2025-68144
was published
for
mcp-server-git
(pip)
Dec 17, 2025
Weblate has an argument injection in management console
Moderate
CVE-2026-24126
was published
for
Weblate
(pip)
Feb 17, 2026
PraisonAI Vulnerable to Argument Injection into Cloud Run Environment Variables via Unsanitized Comma in gcloud --set-env-vars
High
CVE-2026-40113
was published
for
PraisonAI
(pip)
Apr 10, 2026
GitPython: Unsafe option check validates multi_options before shlex.split transformation
High
CVE-2026-42284
was published
for
GitPython
(pip)
Apr 25, 2026
dbt MCP Server has an Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parameters
Moderate
CVE-2026-44968
was published
for
dbt-mcp
(pip)
May 14, 2026
ArchiveBox Vulnerable to RCE via unvalidated per-crawl config overrides in AddView
Critical
CVE-2026-42601
was published
for
archivebox
(pip)
May 4, 2026
JupyterLab has an Extension Manager API/GUI Policy Discrepancy, allowing 3rd party (malicious) extensions install via POST request
High
CVE-2026-42266
was published
for
jupyterlab
(pip)
May 5, 2026
Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args
Critical
GHSA-r253-r9jw-qg44
was published
for
crawl4ai
(pip)
Jun 18, 2026
Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()
High
CVE-2026-12530
was published
for
bedrock-agentcore
(pip)
Jun 19, 2026
ProTip!
Advisories are also available from the
GraphQL API