GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
49
Go
3,479
Maven
5,000+
npm
5,000+
NuGet
886
pip
4,740
Pub
13
RubyGems
1,031
Rust
1,225
Swift
53
Unreviewed advisories
All unreviewed
5,000+
8,159 advisories
Filter by severity
OpenClaw Canvas Path Traversal Information Disclosure Vulnerability. This vulnerability allows...
Moderate
Unreviewed
CVE-2026-3689
was published
Apr 11, 2026
Daptin has Unauthenticated Path Traversal and Zip Slip
Critical
GHSA-9cp7-j3f8-p5jx
was published
for
github.com/daptin/daptin
(Go)
Apr 10, 2026
gramps-webapi: Zip Slip Path Traversal in Media Archive Import
Critical
CVE-2026-40258
was published
for
gramps-webapi
(pip)
Apr 10, 2026
Rembg has a Path Traversal via Custom Model Loading
Moderate
CVE-2026-40086
was published
for
rembg
(pip)
Apr 10, 2026
xrootd has path traversal in directory listing that allows access to the parent directory via trailing ".." pattern
Moderate
GHSA-vj8v-p5vw-m6v5
was published
for
xrootd
(pip)
Apr 10, 2026
uv vulnerable to arbitrary file deletion through RECORD entries
Low
GHSA-pjjw-68hj-v9mw
was published
for
uv
(pip)
Apr 10, 2026
Saltcorn has an Unauthenticated Path Traversal in sync endpoints, allowing arbitrary file write and directory read
High
CVE-2026-40163
was published
for
@saltcorn/server
(npm)
Apr 10, 2026
PraisonAI vulnerable to arbitrary file write via path traversal in `praisonai recipe unpack`
Critical
CVE-2026-40157
was published
for
PraisonAI
(pip)
Apr 10, 2026
PraisonAIAgents: Path Traversal via Unvalidated Glob Pattern in list_files Bypasses Workspace Boundary
Moderate
CVE-2026-40152
was published
for
praisonaiagents
(pip)
Apr 10, 2026
Helm Chart extraction output directory collapse via `Chart.yaml` name dot-segment
Moderate
CVE-2026-35206
was published
for
helm.sh/helm/v3
(Go)
Apr 10, 2026
Helm has a path traversal in plugin metadata version enables arbitrary file write outside Helm plugin directory
High
CVE-2026-35204
was published
for
helm.sh/helm/v4
(Go)
Apr 10, 2026
FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file...
Critical
Unreviewed
CVE-2026-6057
was published
Apr 10, 2026
A vulnerability was determined in Tenda i6 1.0.0.7(2204). Affected by this issue is the function...
Moderate
Unreviewed
CVE-2026-6024
was published
Apr 10, 2026
A flaw has been found in zhayujie chatgpt-on-wechat CowAgent up to 2.0.4. This affects the...
Moderate
Unreviewed
CVE-2026-5998
was published
Apr 10, 2026
The Perfmatters plugin for WordPress is vulnerable to arbitrary file overwrite via path traversal...
High
Unreviewed
CVE-2026-4351
was published
Apr 10, 2026
A vulnerability was detected in Tenda CH22 1.0.0.6(468). This issue affects the function...
Moderate
Unreviewed
CVE-2026-5962
was published
Apr 9, 2026
A vulnerability was determined in Tenda i12 1.0.0.11(3862). The impacted element is an unknown...
Moderate
Unreviewed
CVE-2026-5849
was published
Apr 9, 2026
A weakness has been identified in Tenda i3 1.0.0.6(2204). The affected element is the function...
Moderate
Unreviewed
CVE-2026-5841
was published
Apr 9, 2026
ALEAPP (Android Logs Events And Protobuf Parser) through 3.4.0 contains a path traversal...
High
Unreviewed
CVE-2026-40027
was published
Apr 9, 2026
The Sleuth Kit through 4.14.0 contains a path traversal vulnerability in tsk_recover that allows...
High
Unreviewed
CVE-2026-40024
was published
Apr 9, 2026
The MW WP Form plugin for WordPress is vulnerable to Arbitrary File Move/Read in all versions up...
High
Unreviewed
CVE-2026-5436
was published
Apr 8, 2026
AGiXT Vulnerable to Path Traversal in safe_join()
High
CVE-2026-39981
was published
for
agixt
(pip)
Apr 8, 2026
PraisonAI has Memory State Leakage and Path Traversal in MultiAgent Context Handling
Moderate
GHSA-766v-q9x3-g744
was published
for
praisonaiagents
(pip)
Apr 8, 2026
quarkus-openapi-generator extension has Zip Slip Path Traversal in ApicurioCodegenWrapper class
Moderate
CVE-2026-40180
was published
for
io.quarkiverse.openapi.generator:quarkus-openapi-generator
(Maven)
Apr 8, 2026
Improper Limitation of a Pathname to a Restricted Directory (CWE-22) in Logstash can lead to...
High
Unreviewed
CVE-2026-33466
was published
Apr 8, 2026
ProTip!
Advisories are also available from the
GraphQL API