GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,968
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,038
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
177 advisories
Filter by severity
Jenkins Azure CLI Plugin does not restrict the commands it executes
High
CVE-2025-64140
was published
for
org.jenkins-ci.plugins:azure-cli
(Maven)
Oct 29, 2025
Kottster app reinitialization can be re-triggered allowing command injection in development mode
High
CVE-2025-62713
was published
for
@kottster/server
(npm)
Oct 23, 2025
Netty has SMTP Command Injection Vulnerability that Allows Email Forgery
High
CVE-2025-59419
was published
for
io.netty:netty-codec-smtp
(Maven)
Oct 15, 2025
n8n: Execute Command Node Allows Authenticated Users to Run Arbitrary Commands on Host
High
GHSA-365g-vjw2-grx8
was published
for
n8n
(npm)
Oct 9, 2025
Argument injection vulnerability in SonarQube Scan Action
High
CVE-2025-59844
was published
for
SonarSource/sonarqube-scan-action
(GitHub Actions)
Sep 26, 2025
`git-comiters` Command Injection vulnerability
High
CVE-2025-59831
was published
for
git-commiters
(npm)
Sep 22, 2025
Flowise has unsandboxed remote code execution via Custom MCP
High
GHSA-6933-jpx5-q87q
was published
for
flowise
(npm)
Sep 15, 2025
Claude Code vulnerable to arbitrary code execution caused by maliciously configured git email
High
CVE-2025-59041
was published
for
@anthropic-ai/claude-code
(npm)
Sep 10, 2025
OctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File Upload
High
CVE-2025-58180
was published
for
octoprint
(pip)
Sep 9, 2025
Claude Code's Permissive Default Allowlist Enables Unauthorized File Read and Network Exfiltration in Claude Code
High
CVE-2025-55284
was published
for
@anthropic-ai/claude-code
(npm)
Aug 18, 2025
OliveTin OS Command Injection vulnerability
High
CVE-2025-50946
was published
for
github.com/OliveTin/OliveTin
(Go)
Aug 13, 2025
Claude Code echo command allowed bypass of user approval prompt for command execution
High
CVE-2025-54795
was published
for
@anthropic-ai/claude-code
(npm)
Aug 4, 2025
Withdrawn Advisory: bun vulnerable to OS Command Injection
High
CVE-2025-8022
was published
for
bun
(npm)
Jul 23, 2025
•
withdrawn
Withdrawn Advisory: Thor can construct an unsafe shell command from library input.
High
CVE-2025-54314
was published
for
thor
(RubyGems)
Jul 20, 2025
•
withdrawn
GitHub Kanban MCP Server vulnerable to Command Injection
High
CVE-2025-53818
was published
for
@sunwood-ai-labs/github-kanban-mcp-server
(npm)
Jul 15, 2025
HaxCMS-PHP Command Injection Vulnerability
High
CVE-2025-49141
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jun 9, 2025
LLama-Index CLI OS command injection vulnerability
High
CVE-2025-1753
was published
for
llama-index-cli
(pip)
May 28, 2025
motionEye vulnerable to RCE in add_camera Function Due to unsafe command execution
High
CVE-2025-47782
was published
for
motioneye
(pip)
May 15, 2025
OPA server Data API HTTP path injection of Rego
High
CVE-2025-46569
was published
for
github.com/open-policy-agent/opa
(Go)
May 1, 2025
Whoogle allows attackers to execute arbitrary code via supplying a crafted search query
High
CVE-2024-53305
was published
for
whoogle-search
(pip)
Apr 16, 2025
jupyterlab-git has a command injection vulnerability in "Open Git Repository in Terminal"
High
CVE-2025-30370
was published
for
jupyterlab-git
(pip)
Apr 4, 2025
SFTPGo has insufficient sanitization of user provided rsync command
High
CVE-2025-24366
was published
for
github.com/drakkan/sftpgo
(Go)
Feb 7, 2025
virtualenv allows command injection through activation scripts for a virtual environment
High
CVE-2024-53899
was published
for
virtualenv
(pip)
Nov 24, 2024
LLama Factory Remote OS Command Injection Vulnerability
High
CVE-2024-52803
was published
for
llamafactory
(pip)
Nov 21, 2024
Zoraxy has an authenticated command injection in the Web SSH feature
High
CVE-2024-52010
was published
for
github.com/tobychui/zoraxy
(Go)
Nov 12, 2024
ProTip!
Advisories are also available from the
GraphQL API