GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            23 advisories
        Filter by severity
        
      
      
    
                    
                      Command Injection Vulnerability in systeminformation
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-26274
                      
                      was published
                        for
                        
                          systeminformation
                        
                        (npm)
                      Dec 16, 2020 
                    
                  
                    
                      Command injection in codecov (npm package)
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-15123
                      
                      was published
                        for
                        
                          codecov
                        
                        (npm)
                      Jul 20, 2020 
                    
                  
                    
                      Prototype Pollution in systeminformation
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-26245
                      
                      was published
                        for
                        
                          systeminformation
                        
                        (npm)
                      Nov 27, 2020 
                    
                  
                    
                      OS Command Injection in node-notifier
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-7789
                      
                      was published
                        for
                        
                          node-notifier
                        
                        (npm)
                      Dec 21, 2020 
                    
                  
                    
                      Arbitrary Command Injection due to Improper Command Sanitization
                    
                      
  Moderate
                    
                
                      
                        GHSA-hxwm-x553-x359
                      
                      was published
                        for
                        
                          @npmcli/git
                        
                        (npm)
                      Aug 5, 2021 
                    
                  
                    
                      react-dev-utils OS Command Injection in function `getProcessForPort`
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-24033
                      
                      was published
                        for
                        
                          react-dev-utils
                        
                        (npm)
                      Mar 11, 2021 
                    
                  
                    
                      Command Injection in systeminformation
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-26300
                      
                      was published
                        for
                        
                          systeminformation
                        
                        (npm)
                      Oct 27, 2020 
                    
                  
                    
                      [thi.ng/egf] Potential arbitrary code execution of `#gpg`-tagged property values
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-21412
                      
                      was published
                        for
                        
                          @thi.ng/egf
                        
                        (npm)
                      Apr 6, 2021 
                    
                  
                    
                      Arbitrary Command Injection in portprocesses
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-23348
                      
                      was published
                        for
                        
                          portprocesses
                        
                        (npm)
                      Apr 6, 2021 
                    
                  
                    
                      OS Command Injection in mversion
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-7688
                      
                      was published
                        for
                        
                          mversion
                        
                        (npm)
                      May 17, 2021 
                    
                  
                    
                      OS Command Injection in ng-packagr
                    
                      
  Moderate
                    
                
                      
                        CVE-2020-7735
                      
                      was published
                        for
                        
                          ng-packagr
                        
                        (npm)
                      May 7, 2021 
                    
                  
                    
                      OS Command injection in docker-cli-js
                    
                      
  Moderate
                    
                
                      
                        CVE-2021-23732
                      
                      was published
                        for
                        
                          docker-cli-js
                        
                        (npm)
                      Dec 2, 2021 
                        •
                        
                          withdrawn
                    
                  
                    
                      Exposure of home directory through shescape on Unix with Bash
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-24725
                      
                      was published
                        for
                        
                          shescape
                        
                        (npm)
                      Mar 3, 2022 
                    
                  
                    
                      sharp vulnerable to Command Injection in post-installation over build environment
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-29256
                      
                      was published
                        for
                        
                          sharp
                        
                        (npm)
                      Jun 1, 2022 
                    
                  
                    
                      Snyk plugins vulnerable to Command Injection
                    
                      
  Moderate
                    
                
                      
                        CVE-2022-22984
                      
                      was published
                        for
                        
                          @snyk/snyk-cocoapods-plugin
                        
                        (npm)
                      Nov 30, 2022 
                    
                  
                    
                      chromedriver Command Injection vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-26156
                      
                      was published
                        for
                        
                          chromedriver
                        
                        (npm)
                      Nov 9, 2023 
                    
                  
                    
                      Renovate vulnerable to arbitrary command injection via helmv3 manager and registryAliases
                    
                      
  Moderate
                    
                
                      
                        GHSA-rqgv-292v-5qgr
                      
                      was published
                        for
                        
                          renovate
                        
                        (npm)
                      Apr 23, 2024 
                    
                  
                    
                      ggit is vulnerable to Command Injection via the fetchTags(branch) API
                    
                      
  Moderate
                    
                
                      
                        CVE-2024-21532
                      
                      was published
                        for
                        
                          ggit
                        
                        (npm)
                      Oct 8, 2024 
                    
                  
                    
                      iOS Simulator MCP Command Injection allowed via exec API
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-52573
                      
                      was published
                        for
                        
                          ios-simulator-mcp
                        
                        (npm)
                      Jun 26, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API