GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
1,587 advisories
Filter by severity
open-multi-agent (@open-multi-agent/core) 1.5.0 through 1.21.2 contains a link following...
Moderate
Unreviewed
CVE-2026-108600
was published
Oct 10, 2026
phi 0.1.1 through 0.28.4 contains an improper link resolution vulnerability that allows malicious...
Moderate
Unreviewed
CVE-2026-108599
was published
Oct 10, 2026
A flaw was found in busybox. The tar applet's deferred link-creation handling for symlink and...
Moderate
Unreviewed
CVE-2026-108119
was published
Oct 9, 2026
Nginx UI: Backup restore follows crafted symlinks into the live Nginx configuration path before restore flags are applied
High
CVE-2026-107810
was published
for
github.com/0xJacky/Nginx-UI
(Go)
Oct 9, 2026
A flaw was found in ansible-core. When installing a collection with
`ansible-galaxy collection...
High
Unreviewed
CVE-2026-89091
was published
Oct 9, 2026
Banks: Symlink traversal and arbitrary file disclosure/overwrite in DirectoryPromptRegistry
Moderate
CVE-2026-107716
was published
for
banks
(pip)
Oct 8, 2026
Intego Antivirus for Windows through 3.0.0.1 contains a link following vulnerability in its...
High
Unreviewed
CVE-2026-107707
was published
Oct 8, 2026
Improper link resolution and external control of file paths in the administrative command-line...
Moderate
Unreviewed
CVE-2026-107578
was published
Oct 8, 2026
Backstage has iImproper filesystem validation in Bitbucket pull-request scaffolder actions
High
CVE-2026-106486
was published
for
@backstage/plugin-scaffolder-backend-module-bitbucket-cloud
(npm)
Oct 7, 2026
Backstage: Improper task state validation in Scaffolder backend
High
CVE-2026-106500
was published
for
@backstage/plugin-scaffolder-backend
(npm)
Oct 7, 2026
Backstage has potential file exposure through local TechDocs publisher
Moderate
CVE-2026-106508
was published
for
@backstage/plugin-techdocs-node
(npm)
Oct 7, 2026
Composer: GHSA-gjfg-22fp-rrxx fix bypass via symlinked package bin path
Moderate
CVE-2026-59944
was published
for
composer/composer
(Composer)
Oct 2, 2026
Dulwich: Symlink write-through in checkout(paths=[]) via raw os.open bypasses all symlink protections
High
GHSA-8w8g-wq8h-fq33
was published
for
dulwich
(pip)
Oct 2, 2026
Dulwich: Symlink directory traversal in filter-branch index_filter via cross-commit state persistence
High
GHSA-5fqc-mrg8-w798
was published
for
dulwich
(pip)
Oct 2, 2026
Dulwich: Symlink directory traversal in stash pop allows arbitrary file write via intermediate directory symlinks
High
GHSA-cm62-gvxx-vmxx
was published
for
dulwich
(pip)
Oct 2, 2026
Tornado before 6.5.9 contains a path traversal vulnerability in StaticFileHandler that follows...
High
Unreviewed
CVE-2026-103263
was published
Oct 1, 2026
Tornado: StaticFileHandler follows symlinks outside static root (path traversal)
High
GHSA-c2m8-h5v5-343r
was published
for
tornado
(pip)
Sep 30, 2026
Image Scanner Driver for Linux contains a link following vulnerability. An attacker who can log...
Moderate
Unreviewed
CVE-2026-81310
was published
Sep 30, 2026
@xhmikosr/decompress: Path traversal via symlink chain
Critical
CVE-2026-101894
was published
for
@xhmikosr/decompress
(npm)
Sep 29, 2026
TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path...
High
Unreviewed
CVE-2026-92371
was published
Sep 29, 2026
Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata...
High
Unreviewed
CVE-2026-100838
was published
Sep 27, 2026
Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data...
Critical
Unreviewed
CVE-2026-100716
was published
Sep 26, 2026
Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP...
High
Unreviewed
CVE-2026-100715
was published
Sep 26, 2026
Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js...
High
Unreviewed
CVE-2026-100690
was published
Sep 26, 2026
Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink...
High
Unreviewed
CVE-2026-100692
was published
Sep 26, 2026
ProTip!
Advisories are also available from the
GraphQL API