Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

10,039 advisories

Loading
Shiny for Python has path traversal in bookmark restore Moderate
CVE-2026-108258 was published for shiny (pip) Oct 9, 2026
0xRenSec Credited to 0xRenSec
Contao: Path traversal in the images controller Moderate
CVE-2026-107844 was published for contao/core-bundle (Composer) Oct 9, 2026
HDWSec Credited to HDWSec
skeletonsec Credited to skeletonsec
Banks: Symlink traversal and arbitrary file disclosure/overwrite in DirectoryPromptRegistry Moderate
CVE-2026-107716 was published for banks (pip) Oct 8, 2026
jankesec Credited to jankesec
PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool Calls Critical
CVE-2026-61445 was published for praisonai (pip) Oct 8, 2026
anushkavirgaonkar Credited to anushkavirgaonkar
rexpository Credited to rexpository
datamodel-code-generator: Protobuf weak-import path traversal allows files to be written outside the temporary directory High
CVE-2026-107377 was published for datamodel-code-generator (pip) Oct 8, 2026
alex131125 Credited to alex131125
PraisonAI: Project custom command templates can read outside-workspace files into model prompts Moderate
CVE-2026-60088 was published for praisonai (pip) Oct 8, 2026
rexpository Credited to rexpository
PraisonAI: SkillTools Executes Scripts Without Path Containment Validation High
CVE-2026-61443 was published for praisonaiagents (pip) Oct 8, 2026
anushkavirgaonkar Credited to anushkavirgaonkar
PraisonAI: FastContext path resolution permits absolute and traversal reads outside the workspace Moderate
CVE-2026-61432 was published for praisonaiagents (pip) Oct 8, 2026
rexpository Credited to rexpository
ProTip! Advisories are also available from the GraphQL API