Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

5,919 advisories

Loading
Unauthenticated Content Injection in Boutique <= 2.3.3 versions. Moderate Unreviewed
CVE-2026-62098 was published Oct 10, 2026
Unauthenticated Remote Code Execution (RCE) in Everest Backup <= 2.3.13 versions. High Unreviewed
CVE-2026-39802 was published Oct 10, 2026
Tina: Code injection via unescaped Git branch name in generated client source High
CVE-2026-108259 was published for @tinacms/cli (npm) Oct 9, 2026
canhieu Credited to canhieu
Nginx UI: Authenticated Remote Code Execution via Backup Restore App Config Overwrite Critical
CVE-2026-107806 was published for github.com/0xJacky/Nginx-UI (Go) Oct 9, 2026
mamdouhmahfouz Credited to mamdouhmahfouz
PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source High
CVE-2026-61433 was published for praisonai (pip) Oct 8, 2026
rexpository Credited to rexpository
Handlebars: JavaScript Injection via AST Type Confusion in compile (bypass of CVE-2026-33937) Critical
CVE-2026-106446 was published for handlebars (npm) Oct 8, 2026
ndelphit Credited to ndelphit, bhaswanthc, dinhvaren, jmoritzc53, n0tra4e, hibrian827, sondt99, nikolakojic-rasit, Ahmed-Elmahgob, vk-can, PellaML, shenhuanageshei, kagebunsher, kustundag, ffasterss, and sanmatte bhaswanthc bhaswanthc
dinhvaren dinhvaren jmoritzc53 jmoritzc53 n0tra4e n0tra4e hibrian827 hibrian827 sondt99 sondt99 nikolakojic-rasit nikolakojic-rasit Ahmed-Elmahgob Ahmed-Elmahgob vk-can vk-can PellaML PellaML shenhuanageshei shenhuanageshei kagebunsher kagebunsher kustundag kustundag ffasterss ffasterss sanmatte sanmatte
PraisonAI: Plugin Auto-Discovery Executes Arbitrary Python Files Without Verification High
CVE-2026-61446 was published for praisonaiagents (pip) Oct 8, 2026
anushkavirgaonkar Credited to anushkavirgaonkar
PraisonAI: CodeAgent Executes LLM-Generated Code Without Sandboxing and Leaks All Environment Secrets Critical
CVE-2026-61447 was published for praisonaiagents (pip) Oct 8, 2026
anushkavirgaonkar Credited to anushkavirgaonkar
Ghost: Remote Code Execution via Bookmark Card Images High
CVE-2026-105642 was published for ghost (npm) Oct 7, 2026
rafabd1 Credited to rafabd1
Payload: Remote Code Execution through first-register High
CVE-2026-105858 was published for payload (npm) Oct 7, 2026
Zerotistic Credited to Zerotistic
Payload Form Builder has an RCE issue Critical
CVE-2026-105857 was published for @payloadcms/plugin-form-builder (npm) Oct 7, 2026
Zerotistic Credited to Zerotistic
Ghost: Remote Code Execution via Theme Translation Files High
CVE-2026-105677 was published for ghost (npm) Oct 7, 2026
Alemmi Credited to Alemmi, Tomer-PL, and msegoviag Tomer-PL Tomer-PL
msegoviag msegoviag
Hydra logging configuration permits unsafe callable resolution High
CVE-2026-106441 was published for hydra-core (pip) Oct 7, 2026
hash3liZer Credited to hash3liZer and eros938 eros938 eros938
ProTip! Advisories are also available from the GraphQL API