Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,587 advisories

Loading
open-multi-agent (@open-multi-agent/core) 1.5.0 through 1.21.2 contains a link following... Moderate Unreviewed
CVE-2026-108600 was published Oct 10, 2026
Nginx UI: Backup restore follows crafted symlinks into the live Nginx configuration path before restore flags are applied High
CVE-2026-107810 was published for github.com/0xJacky/Nginx-UI (Go) Oct 9, 2026
Vincent550102 Credited to Vincent550102
Banks: Symlink traversal and arbitrary file disclosure/overwrite in DirectoryPromptRegistry Moderate
CVE-2026-107716 was published for banks (pip) Oct 8, 2026
jankesec Credited to jankesec
Backstage has iImproper filesystem validation in Bitbucket pull-request scaffolder actions High
CVE-2026-106486 was published for @backstage/plugin-scaffolder-backend-module-bitbucket-cloud (npm) Oct 7, 2026
Backstage: Improper task state validation in Scaffolder backend High
CVE-2026-106500 was published for @backstage/plugin-scaffolder-backend (npm) Oct 7, 2026
Backstage has potential file exposure through local TechDocs publisher Moderate
CVE-2026-106508 was published for @backstage/plugin-techdocs-node (npm) Oct 7, 2026
Composer: GHSA-gjfg-22fp-rrxx fix bypass via symlinked package bin path Moderate
CVE-2026-59944 was published for composer/composer (Composer) Oct 2, 2026
DavidCarliez Credited to DavidCarliez, manus-use, and arpitjain099 manus-use manus-use
arpitjain099 arpitjain099
Dulwich: Symlink write-through in checkout(paths=[]) via raw os.open bypasses all symlink protections High
GHSA-8w8g-wq8h-fq33 was published for dulwich (pip) Oct 2, 2026
manus-use Credited to manus-use and jelmer jelmer jelmer
Dulwich: Symlink directory traversal in filter-branch index_filter via cross-commit state persistence High
GHSA-5fqc-mrg8-w798 was published for dulwich (pip) Oct 2, 2026
manus-use Credited to manus-use and jelmer jelmer jelmer
manus-use Credited to manus-use and jelmer jelmer jelmer
Tornado: StaticFileHandler follows symlinks outside static root (path traversal) High
GHSA-c2m8-h5v5-343r was published for tornado (pip) Sep 30, 2026
Yasha-ops Credited to Yasha-ops and iaohkut-from-NightWolf-Team iaohkut-from-NightWolf-Team iaohkut-from-NightWolf-Team
@xhmikosr/decompress: Path traversal via symlink chain Critical
CVE-2026-101894 was published for @xhmikosr/decompress (npm) Sep 29, 2026
umar0x Credited to umar0x and XhmikosR XhmikosR XhmikosR
ProTip! Advisories are also available from the GraphQL API