GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,656
Maven
5,000+
npm
4,284
NuGet
760
pip
4,069
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
622 advisories
Filter by severity
AstrBot contains a directory traversal vulnerability
High
CVE-2025-57698
was published
for
AstrBot
(pip)
Nov 7, 2025
Dosage vulnerable to a Directory Traversal through crafted HTTP responses
High
CVE-2025-64184
was published
for
dosage
(pip)
Nov 4, 2025
Keras keras.utils.get_file API is vulnerable to a path traversal attack
High
CVE-2025-12060
was published
for
keras
(pip)
Oct 30, 2025
MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability
High
CVE-2025-11201
was published
for
mlflow
(pip)
Oct 29, 2025
Docker Compose Vulnerable to Path Traversal via OCI Artifact Layer Annotations
High
CVE-2025-62725
was published
for
github.com/docker/compose/v2
(Go)
Oct 27, 2025
Argo Workflow has a Zipslip Vulnerability
High
CVE-2025-62156
was published
for
github.com/argoproj/argo-workflows/v3
(Go)
Oct 14, 2025
Flowise is vulnerable to arbitrary file exposure through its ReadFileTool
High
GHSA-j44m-5v8f-gc9c
was published
for
flowise
(npm)
Oct 10, 2025
LLaMA Factory's Chat API Contains Critical SSRF and LFI Vulnerabilities
High
CVE-2025-61784
was published
for
llamafactory
(pip)
Oct 7, 2025
Canonical LXD Path Traversal Vulnerability in Instance Log File Retrieval Function
High
CVE-2025-54293
was published
for
github.com/canonical/lxd
(Go)
Oct 2, 2025
tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball
High
CVE-2025-59343
was published
for
tar-fs
(npm)
Sep 24, 2025
Mattermost Path Traversal vulnerability
High
CVE-2025-9079
was published
for
github.com/mattermost/mattermost-server
(Go)
Sep 19, 2025
xml2rfc is vulnerable to arbitrary file reads through prepped files
High
CVE-2025-11059
was published
for
xml2rfc
(pip)
Sep 10, 2025
MONAI does not prevent path traversal, potentially leading to arbitrary file writes
High
CVE-2025-58755
was published
for
monai
(pip)
Sep 9, 2025
podman kube play symlink traversal vulnerability
High
CVE-2025-9566
was published
for
github.com/containers/podman/v4
(Go)
Sep 4, 2025
Soft Serve vulnerable to arbitrary file writing through SSH API
High
CVE-2025-58355
was published
for
github.com/charmbracelet/soft-serve
(Go)
Sep 2, 2025
Harness Allows Arbitrary File Write in Gitness LFS server
High
CVE-2025-58158
was published
for
github.com/harness/gitness
(Go)
Aug 29, 2025
xml2rfc has an arbitrary file read vulnerability
High
CVE-2025-11058
was published
for
xml2rfc
(pip)
Aug 26, 2025
Copier's safe template has arbitrary filesystem read/write access
High
CVE-2025-55201
was published
for
copier
(pip)
Aug 18, 2025
Withdrawn Advisory: Python-Future Module Arbitrary Code Execution via Unintended Import of test.py
High
CVE-2025-50817
was published
for
future
(pip)
Aug 14, 2025
•
withdrawn
RatPanel can perform remote command execution without authorization
High
CVE-2025-53534
was published
for
github.com/tnborg/panel
(Go)
Aug 4, 2025
Claude Code Research Preview has a Path Restriction Bypass which could allow unauthorized file access
High
CVE-2025-54794
was published
for
@anthropic-ai/claude-code
(npm)
Aug 4, 2025
Traefik Client Plugin's Path Traversal Vulnerability Allows Arbitrary File Overwrite and Remote Code Execution
High
CVE-2025-54386
was published
for
github.com/traefik/traefik/v2
(Go)
Aug 1, 2025
Bugsink path traversal via event_id in ingestion
High
CVE-2025-54433
was published
for
bugsink
(pip)
Jul 29, 2025
files-bucket-server vulnerable to Directory Traversal
High
CVE-2025-8021
was published
for
files-bucket-server
(npm)
Jul 23, 2025
`pyLoad` has Path Traversal Vulnerability in `json/upload` Endpoint that allows Arbitrary File Write
High
CVE-2025-54140
was published
for
pyload-ng
(pip)
Jul 21, 2025
ProTip!
Advisories are also available from the
GraphQL API