GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
12,672 advisories
Filter by severity
TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop
High
GHSA-7q9c-hpx7-9cwm
was published
for
@typespec/spector
(npm)
Sep 4, 2026
SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers
High
CVE-2026-72793
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers
High
CVE-2026-72795
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf
High
CVE-2026-72794
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns
High
CVE-2026-72798
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 4, 2026
SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
High
CVE-2026-63735
was published
for
surrealdb
(Rust)
Sep 4, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
CVE-2026-75911
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
CVE-2026-75858
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
CVE-2026-75912
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: js_execution leaks parent environment to model context via missing env scrub
High
CVE-2026-75915
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval
High
CVE-2026-75913
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)
High
CVE-2026-75857
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
High
CVE-2026-75859
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes
High
CVE-2026-75914
was published
for
codewhale
(npm)
Sep 4, 2026
SiYuan: Encrypted-notebook key-derivation material and wrapped notebook keys disclosed to anonymous readers, enabling offline master-password cracking
High
CVE-2026-72801
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents
High
CVE-2026-72804
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Second-order SSTI to arbitrary SQL via attribute-view template column (queryBlocks): malicious imported package executes SQL on victim kernel
High
CVE-2026-72807
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy
High
CVE-2026-72809
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Publish-boundary bypass via WebSocket broadcast: anonymous readers receive a live unfiltered feed of all edits including protected/forbidden documents (publish mode)
High
CVE-2026-72810
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode)
High
GHSA-7j72-f6wg-cxw6
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered
High
CVE-2026-68586
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
SiYuan: Full-content disclosure of publish-disabled documents via getHeading*Transaction endpoints (publish mode): reader-reachable rendered DOM with no publish-access check
High
CVE-2026-68587
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
toml-node: Prototype Pollution Leads to `Object.prototype` Corruption via `__proto__` Key-Path Desynchronization
High
CVE-2026-63376
was published
for
toml
(npm)
Sep 3, 2026
SiYuan: Path Traversal via unvalidated avID in RenderAttributeView/AV read endpoints : reader-reachable cross-scope attribute-view disclosure
High
CVE-2026-69086
was published
for
github.com/siyuan-note/siyuan/kernel
(Go)
Sep 3, 2026
ProTip!
Advisories are also available from the
GraphQL API