Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,558 advisories

Loading
Yanchon918s Credited to Yanchon918s and sanketsudake sanketsudake sanketsudake
AWS CLI: Overly permissive File Permissions Moderate
CVE-2026-13769 was published for awscli (pip) Jul 24, 2026
Gitea: Permanent Fork PR Workflow Approval Gate Bypass High
CVE-2026-58424 was published for code.gitea.io/gitea (Go) Jul 21, 2026
prakhar0x01 Credited to prakhar0x01
Gitea: draft release attachment disclosure via missing web authorization Moderate
CVE-2026-58432 was published for code.gitea.io/gitea (Go) Jul 21, 2026
z3r0s6 Credited to z3r0s6
Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files Moderate
CVE-2026-59946 was published for composer/composer (Composer) Jul 20, 2026
iliaal Credited to iliaal
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store High
CVE-2026-54447 was published for garminconnect (pip) Jul 15, 2026
EQSTLab Credited to EQSTLab and 232-323 232-323 232-323
mknod: Device nodes created mislabeled on SELinux, with broken cleanup (remove_dir on a node) Low
CVE-2026-35361 was published for uu_mknod (Rust) Jul 6, 2026
mkfifo: permissions of an existing file are changed after FIFO creation fails High
CVE-2026-35341 was published for uu_mkfifo (Rust) Jul 6, 2026
Decompress: Archive extraction can create files and links outside of the target directory Critical
CVE-2026-53486 was published for @xhmikosr/decompress (npm) Jul 6, 2026
XhmikosR Credited to XhmikosR
mkdir: -m exposes directory with umask perms before chmod (race window) Low
CVE-2026-35353 was published for uu_mkdir (Rust) Jul 6, 2026
Steeltoe: TLS private keys written to /tmp with default permissions, never deleted Moderate
CVE-2026-50267 was published for Steeltoe.Configuration.Abstractions (NuGet) Jul 2, 2026
OpenClaw: memory-wiki ingest could read local files with operator.write scope Moderate
GHSA-p2fh-f5fc-44hr was published for openclaw (npm) Jul 2, 2026
Blee72 Credited to Blee72
Kahi has privilege-drop and socket/log permission issues High
GHSA-55f6-4pr5-c7m5 was published for github.com/kahiteam/kahi (Go) Jun 30, 2026
ProTip! Advisories are also available from the GraphQL API