GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,676
Maven
5,000+
npm
4,297
NuGet
760
pip
4,077
Pub
12
RubyGems
957
Rust
1,058
Swift
45
Unreviewed advisories
All unreviewed
5,000+
54 advisories
Filter by severity
Resty has a Path Traversal vulnerability
Low
CVE-2025-13435
was published
for
cn.dreampie:resty
(Maven)
Nov 20, 2025
Astro Development Server has Arbitrary Local File Read
Low
CVE-2025-64757
was published
for
astro
(npm)
Nov 19, 2025
Langchain-Chatchat vulnerable to path traversal
Low
CVE-2025-6854
was published
for
langchain-chatchat
(pip)
Jun 29, 2025
Langchain-Chatchat vulnerable to path traversal
Low
CVE-2025-6855
was published
for
langchain-chatchat
(pip)
Jun 29, 2025
Shopware vulnerable to path traversal via Plugin upload
Low
GHSA-6wh5-mw9h-5c3w
was published
for
shopware/core
(Composer)
Oct 21, 2025
Withdrawn Advisory: cross-zip is vulnerable to Directory Traversal through selective use of zip/unzip operations
Low
CVE-2025-11569
was published
for
cross-zip
(npm)
Oct 10, 2025
•
withdrawn
auth0-PHP SDK Does Not Properly Handle File Types in Bulk User Import
Low
CVE-2025-58769
was published
for
auth0/auth0-php
(Composer)
Oct 1, 2025
Nuxt has Client-Side Path Traversal in Nuxt Island Payload Revival
Low
CVE-2025-59414
was published
for
nuxt
(npm)
Sep 17, 2025
Langchain-Chatchat has a Path Traversal vulnerability
Low
CVE-2025-6853
was published
for
langchain-chatchat
(pip)
Jun 29, 2025
Vite middleware may serve files starting with the same name with the public directory
Low
CVE-2025-58751
was published
for
vite
(npm)
Sep 9, 2025
MobSF Path Traversal in GET /download/<filename> using absolute filenames
Low
CVE-2025-58161
was published
for
mobsf
(pip)
Sep 2, 2025
Upsonic is vulnerable to Path Traversal attack through its os.path.join function
Low
CVE-2025-6278
was published
for
upsonic
(pip)
Jun 19, 2025
Traefik allows path traversal using url encoding
Low
CVE-2025-47952
was published
for
github.com/traefik/traefik
(Go)
May 28, 2025
auth-js Vulnerable to Insecure Path Routing from Malformed User Input
Low
CVE-2025-48370
was published
for
@supabase/auth-js
(npm)
May 27, 2025
Kirby vulnerable to path traversal in the router for PHP's built-in server
Low
CVE-2025-30207
was published
for
getkirby/cms
(Composer)
May 13, 2025
sudo-rs Session File Relative Path Traversal vulnerability
Low
CVE-2023-42456
was published
for
sudo-rs
(Rust)
Sep 21, 2023
OpenStack Ironic fails to restrict paths used for file:// image URLs
Low
CVE-2025-44021
was published
for
ironic
(pip)
May 8, 2025
SurrealDB has local file read of 2-column TSV files via analyzers
Low
GHSA-2cvj-g5r5-jrrg
was published
for
surrealdb
(Rust)
Apr 10, 2025
Agnai vulnerable to Relative Path Traversal in Image Upload
Low
CVE-2024-47171
was published
for
agnai
(npm)
Sep 26, 2024
Agnai File Disclosure Vulnerability: JSON via Path Traversal
Low
CVE-2024-47170
was published
for
agnai
(npm)
Sep 26, 2024
Directory Traversal vulnerability in GET/PUT allows attackers to Disclose Information or Write Files via a crafted GET/PUT request
Low
CVE-2020-15239
was published
for
xmpp-http-upload
(pip)
Oct 6, 2020
Path traversal vulnerability in stripe-cli
Low
CVE-2024-45401
was published
for
github.com/stripe/stripe-cli
(Go)
Sep 5, 2024
GuardDog vulnerable to arbitrary file write when scanning a specially-crafted remote PyPI package
Low
CVE-2022-23530
was published
for
guarddog
(pip)
Dec 5, 2022
GuardDog vulnerable to arbitrary file write when scanning a specially-crafted PyPI package
Low
CVE-2022-23531
was published
for
guarddog
(pip)
Dec 2, 2022
Kubernetes Secrets Store CSI Driver plugins arbitrary file write
Low
CVE-2020-8567
was published
for
github.com/Azure/secrets-store-csi-driver-provider-azure
(Go)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API