Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

97 advisories

Loading
de3erve-hunter Credited to de3erve-hunter, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion Moderate
CVE-2026-54015 was published for open-webui (pip) Jun 17, 2026
0xEr3n Credited to 0xEr3n, Classic298, and 5yu4n Classic298 Classic298
5yu4n 5yu4n
Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion High
CVE-2026-54012 was published for open-webui (pip) Jun 17, 2026
0xEr3n Credited to 0xEr3n, 5yu4n, and Classic298 5yu4n 5yu4n
Classic298 Classic298
Open WebUI: Forged chat-file link allows cross-user file read and deletion High
CVE-2026-54010 was published for open-webui (pip) Jun 17, 2026
0xEr3n Credited to 0xEr3n, 5yu4n, Classic298, and oxsignal 5yu4n 5yu4n
Classic298 Classic298 oxsignal oxsignal
DIRAC: SQL injection and lack of access control in PilotManager service High
GHSA-7xw9-549r-8jrc was published for DIRAC (pip) Jul 13, 2026
sfayer Credited to sfayer
vantage6 node has an Improper Access Control issue Moderate
CVE-2026-54533 was published for vantage6 (pip) Jun 5, 2026
LoLLMs is vulnerable to Improper Access Control through weak secret key Critical
CVE-2026-1114 was published for lollms (pip) Apr 7, 2026
PinkDraconian Credited to PinkDraconian
BoxLite: Permission Bypass Allows Modification of Read-Only Files Critical
CVE-2026-46695 was published for @boxlite-ai/boxlite (Go) May 21, 2026
XlabAITeam Credited to XlabAITeam, keenanwgn, and A7um keenanwgn keenanwgn
A7um A7um
motionEye has an Arbitrary File Read via Path Traversal in Picture/Movie Preview Endpoint Moderate
CVE-2026-31978 was published for motioneye (pip) Jun 22, 2026
Neosprings Credited to Neosprings, blue-pho3nix, and MichaIng blue-pho3nix blue-pho3nix
MichaIng MichaIng
OpenCTI May Bypass Introspection Restriction Moderate
CVE-2024-37155 was published for pycti (pip) Jun 22, 2026
R-s0n Credited to R-s0n
Langflow: DoS Through Lack of File Size Restriction via Deprecated Unauthenticated File Upload API Moderate
CVE-2026-6596 was published for langflow-base (pip) Apr 20, 2026
ventusfortis Credited to ventusfortis
Weblate has Systematic User and Project Enumeration via Broken Authorization in REST API (IDOR) Moderate
CVE-2025-67715 was published for Weblate (pip) Dec 15, 2025
naxus-audit Credited to naxus-audit and nijel nijel nijel
langflow has Unauthenticated IDOR on Image Downloads High
CVE-2026-33484 was published for langflow (pip) Mar 20, 2026
akshatgit Credited to akshatgit, abhinavagarwal07, and andifilhohub abhinavagarwal07 abhinavagarwal07
andifilhohub andifilhohub
Langflow has an Arbitrary File Write (RCE) via v2 API Critical
CVE-2026-33309 was published for langflow (pip) Mar 19, 2026
akshatgit Credited to akshatgit, abhinavagarwal07, Jkavia, and andifilhohub abhinavagarwal07 abhinavagarwal07
Jkavia Jkavia andifilhohub andifilhohub
Gradio has an Open Redirect in its OAuth Flow Moderate
CVE-2026-28415 was published for gradio (pip) Mar 1, 2026
logicx24 Credited to logicx24
PraisonAI Platform: Missing role checks let any workspace member become owner and control workspace membership High
CVE-2026-47405 was published for praisonai-platform (pip) May 29, 2026
beanduan22 Credited to beanduan22
PraisonAI Platform workspace-scoped routes allow cross-workspace object access by global object ID High
CVE-2026-47399 was published for praisonai-platform (pip) May 29, 2026
beanduan22 Credited to beanduan22
beanduan22 Credited to beanduan22
Wachizungu Credited to Wachizungu
adrianosela Credited to adrianosela, Alex-ley-scrub, and icarocd Alex-ley-scrub Alex-ley-scrub
icarocd icarocd
vi11ain Credited to vi11ain
ProTip! Advisories are also available from the GraphQL API