Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

38 advisories

Loading
Jupyter Server: 5xx request logging leaks token-bearing Referer header values High
CVE-2026-86049 was published for jupyter_server (pip) Sep 17, 2026
DavidCarliez Credited to DavidCarliez, Yann-P, and krassowski Yann-P Yann-P
krassowski krassowski
Grav: Stored CSS injection via Markdown image resize() bypasses prior media style sanitizers in Grav Moderate
CVE-2026-58657 was published for getgrav/grav (Composer) Sep 16, 2026
DavidCarliez Credited to DavidCarliez
Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty Low
GHSA-rf68-8gjr-36q7 was published for github.com/nezhahq/nezha (Go) Sep 15, 2026
DavidCarliez Credited to DavidCarliez
FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix High
CVE-2026-59973 was published for @frontmcp/adapters (npm) Sep 11, 2026
DavidCarliez Credited to DavidCarliez
Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation High
CVE-2026-59161 was published for github.com/xuri/excelize (Go) Sep 10, 2026
DavidCarliez Credited to DavidCarliez
Excelize: Negative shared-string index causes panic in GetCellValue and GetRows Moderate
CVE-2026-59162 was published for github.com/xuri/excelize (Go) Sep 10, 2026
DavidCarliez Credited to DavidCarliez
Prowler: Stored XSS in HTML reports through unescaped cloud resource tags Moderate
CVE-2026-73262 was published for prowler (pip) Sep 8, 2026
DavidCarliez Credited to DavidCarliez and jfagoagas jfagoagas jfagoagas
Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript High
CVE-2026-55596 was published for @platejs/media (npm) Aug 25, 2026
DavidCarliez Credited to DavidCarliez
MobSF has SSRF port restriction bypass in assetlinks_check Low
CVE-2026-68927 was published for mobsf (pip) Aug 18, 2026
DavidCarliez Credited to DavidCarliez
Pig-Tail Credited to Pig-Tail, sec-reex, and DavidCarliez sec-reex sec-reex
DavidCarliez DavidCarliez
Ghost: Server-Side Request Forgery in Image Fetching Moderate
CVE-2026-70591 was published for ghost (npm) Aug 4, 2026
koyokr Credited to koyokr and DavidCarliez DavidCarliez DavidCarliez
Open WebUI: Users denied the image-generation permission can still generate images via chat completions Moderate
CVE-2026-70484 was published for open-webui (pip) Aug 4, 2026
DavidCarliez Credited to DavidCarliez and Classic298 Classic298 Classic298
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests Moderate
GHSA-v6w6-358x-2433 was published for github.com/cloudreve/Cloudreve/v3 (Go) Jul 24, 2026
DavidCarliez Credited to DavidCarliez
Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored Moderate
CVE-2026-62323 was published for github.com/cloudreve/Cloudreve/v3 (Go) Jul 24, 2026
DavidCarliez Credited to DavidCarliez
Budibase: DNS rebinding SSRF bypasses remain in OpenAPI import and REST query execution High
GHSA-xg5g-26x8-cvf4 was published for @budibase/server (npm) Jul 24, 2026
DavidCarliez Credited to DavidCarliez
DavidCarliez Credited to DavidCarliez
open-webui terminal proxy path traversal guard bypass via 9x encoded traversal High
CVE-2026-59221 was published for open-webui (pip) Jul 24, 2026
DavidCarliez Credited to DavidCarliez and Classic298 Classic298 Classic298
Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials High
CVE-2026-55502 was published for github.com/cloudreve/Cloudreve/v3 (Go) Jul 24, 2026
DavidCarliez Credited to DavidCarliez
DavidCarliez Credited to DavidCarliez and Classic298 Classic298 Classic298
sfwani Credited to sfwani, DavidCarliez, and Classic298 DavidCarliez DavidCarliez
Classic298 Classic298
DavidCarliez Credited to DavidCarliez
File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope Moderate
CVE-2026-55668 was published for github.com/filebrowser/filebrowser/v2 (Go) Jul 20, 2026
DavidCarliez Credited to DavidCarliez, riodrwn, and hacdias riodrwn riodrwn
hacdias hacdias
Koel has SSRF through Authenticated Subsonic podcast feed URLs Moderate
GHSA-8q6q-m837-fv64 was published for phanan/koel (Composer) Jul 15, 2026
DavidCarliez Credited to DavidCarliez
DavidCarliez Credited to DavidCarliez
Kite has an authenticated cluster RBAC bypass in /api/v1/overview Moderate
CVE-2026-53487 was published for github.com/zxh326/kite (Go) Jul 7, 2026
DavidCarliez Credited to DavidCarliez
ProTip! Advisories are also available from the GraphQL API