GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,690
Maven
5,000+
npm
4,320
NuGet
760
pip
4,096
Pub
12
RubyGems
958
Rust
1,063
Swift
45
Unreviewed advisories
All unreviewed
5,000+
245 advisories
Filter by severity
Keras Directory Traversal Vulnerability
High
CVE-2025-12060
was published
for
keras
(pip)
Dec 2, 2025
Duplicate Advisory: Keras keras.utils.get_file API is vulnerable to a path traversal attack
High
GHSA-28jp-44vh-q42h
was published
for
keras
(pip)
Oct 30, 2025
•
withdrawn
Duplicate Advisory: Keras keras.utils.get_file API is vulnerable to a path traversal attack
High
CVE-2025-12638
was published
for
Keras
(pip)
Nov 28, 2025
•
withdrawn
AstrBot has an arbitrary file read vulnerability in function _encode_image_bs64
Moderate
CVE-2025-57697
was published
for
AstrBot
(pip)
Nov 7, 2025
AstrBot contains a directory traversal vulnerability
High
CVE-2025-57698
was published
for
AstrBot
(pip)
Nov 7, 2025
Dosage vulnerable to a Directory Traversal through crafted HTTP responses
High
CVE-2025-64184
was published
for
dosage
(pip)
Nov 4, 2025
MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability
High
CVE-2025-11201
was published
for
mlflow
(pip)
Oct 29, 2025
GitPython blind local file inclusion
Moderate
CVE-2023-41040
was published
for
GitPython
(pip)
Aug 30, 2023
aiohttp is vulnerable to directory traversal
High
CVE-2024-23334
was published
for
aiohttp
(pip)
Jan 29, 2024
internetarchive Vulnerable to Directory Traversal in File.download()
Critical
CVE-2025-58438
was published
for
internetarchive
(pip)
Sep 5, 2025
Langchain-Chatchat vulnerable to path traversal
Low
CVE-2025-6854
was published
for
langchain-chatchat
(pip)
Jun 29, 2025
Langchain-Chatchat vulnerable to path traversal
Low
CVE-2025-6855
was published
for
langchain-chatchat
(pip)
Jun 29, 2025
SaltStack Salt is vulnerable Arbitrary Directory Access
High
CVE-2020-11652
was published
for
salt
(pip)
May 24, 2022
Mammoth is vulnerable to Directory Traversal
Moderate
CVE-2025-11849
was published
for
Mammoth
(Maven)
Oct 17, 2025
Open WebUI allows Remote Code Execution via Arbitrary File Upload to /audio/api/v1/transcriptions
High
CVE-2024-8060
was published
for
open-webui
(pip)
Mar 20, 2025
GluonCV Arbitrary File Write via TarSlip
High
CVE-2024-12216
was published
for
gluoncv
(pip)
Mar 20, 2025
InvokeAI Arbitrary File Deletion vulnerability
Critical
CVE-2024-11042
was published
for
InvokeAI
(pip)
Mar 20, 2025
DB-GPT vulnerable to Arbitrary File Upload with Path Traversal
Critical
CVE-2024-10902
was published
for
dbgpt
(pip)
Mar 20, 2025
DB-GPT Absolute Path Traversal in knowledge/{space_name}/document/upload
Critical
CVE-2024-10833
was published
for
dbgpt
(pip)
Mar 20, 2025
LoLLMS vulnerable to Expected Behavior Violation
High
CVE-2024-6281
was published
for
lollms
(pip)
Jul 20, 2024
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
Critical
CVE-2024-5980
was published
for
lightning
(pip)
Jun 27, 2024
AWS SAM CLI Path Traversal allows file copy to local cache
Moderate
CVE-2025-3048
was published
for
aws-sam-cli
(pip)
Mar 31, 2025
AWS SAM CLI Path Traversal allows file copy to build container
Moderate
CVE-2025-3047
was published
for
aws-sam-cli
(pip)
Mar 31, 2025
ProTip!
Advisories are also available from the
GraphQL API