Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,983 advisories

Loading
u-ktdi Credited to u-ktdi, dewankpant, shrutilohani, Moaaz-0x, yardenporat353, pucagit, nick-hollon-lc, and localhost-detect dewankpant dewankpant
shrutilohani shrutilohani Moaaz-0x Moaaz-0x yardenporat353 yardenporat353 pucagit pucagit nick-hollon-lc nick-hollon-lc localhost-detect localhost-detect
Open WebUI Vulnerable to Arbitrary File Upload and Path Traversal High
CVE-2026-44566 was published for open-webui (pip) May 8, 2026
KoreLogicSecurityDisclosures Credited to KoreLogicSecurityDisclosures
Open WebUI has Improper Authorization Control High
CVE-2026-44567 was published for open-webui (pip) May 8, 2026
KoreLogicSecurityDisclosures Credited to KoreLogicSecurityDisclosures
Open WebUI has stored XSS in Excel file preview High
CVE-2026-44549 was published for open-webui (pip) May 8, 2026
Classic298 Credited to Classic298
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI High
CVE-2026-44209 was published for banks (pip) May 8, 2026
Anandakrishnasv Credited to Anandakrishnasv
Open WebUI has Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwrite High
CVE-2026-44554 was published for open-webui (pip) May 8, 2026
Classic298 Credited to Classic298
Open WebUI's responses passthrough endpoint lacks access control authorization High
CVE-2026-44556 was published for open-webui (pip) May 8, 2026
Classic298 Credited to Classic298
Open WebUI's Base Model Routing Bypasses Access Control via Model Chaining High
CVE-2026-44555 was published for open-webui (pip) May 8, 2026
Classic298 Credited to Classic298
Classic298 Credited to Classic298
Classic298 Credited to Classic298
open-webui Vulnerable to Stored XSS via Model Description High
CVE-2026-44721 was published for open-webui (npm) May 8, 2026
fr0stydev Credited to fr0stydev and Classic298 Classic298 Classic298
gmaps-mcp's unauthenticated HTTP transport allows unlimited Google Maps API calls at operator expense High
GHSA-52cq-7v8r-62c6 was published for gmaps-mcp (pip) May 8, 2026
OpenStack Cyborg uses rule:allow (check_str='@') as the default policy for multiple API endpoints High
CVE-2026-40213 was published for openstack-cyborg (pip) May 8, 2026
netbox-data-flows has stored XSS in ObjectAlias names rendered inside DataFlow tables High
GHSA-v7qw-hx66-4w9x was published for netbox-data-flows (pip) May 7, 2026
xanode Credited to xanode
0xmrma Credited to 0xmrma
Postorius is vulnerable to XSS High
CVE-2026-44742 was published for postorius (pip) May 7, 2026
Diffusers has a `trust_remote_code` bypass via `custom_pipeline` and local custom components High
CVE-2026-44513 was published for diffusers (pip) May 7, 2026
hlky Credited to hlky and Vancir Vancir Vancir
Diffusers has a `trust_remote_code` bypass via `custom_pipeline` and local custom components High
CVE-2026-44827 was published for diffusers (pip) May 7, 2026 withdrawn
Aegra has cross-user run injection in /threads/{thread_id}/runs (IDOR) High
CVE-2026-44504 was published for aegra-api (pip) May 7, 2026
victorjmarin Credited to victorjmarin
Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect High
CVE-2026-44503 was published for Microsoft.Kiota.Abstractions (Go) May 7, 2026
MIchaelMainer Credited to MIchaelMainer
HyperPS Credited to HyperPS
PraisonAI has unauthenticated RCE via `tool_override.py` (CVE-2026-40287 patch bypass) High
CVE-2026-44334 was published for praisonai (pip) May 6, 2026
everping Credited to everping
PraisonAI has an SSRF bypass High
CVE-2026-44335 was published for praisonaiagents (pip) May 6, 2026
Fushuling Credited to Fushuling and RacerZ-fighting RacerZ-fighting RacerZ-fighting
GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath High
CVE-2026-44244 was published for GitPython (pip) May 6, 2026
daridor9 Credited to daridor9
python-multipart has Denial of Service via unbounded multipart part headers High
CVE-2026-42561 was published for python-multipart (pip) May 6, 2026
SinhSinhAn Credited to SinhSinhAn and intadd intadd intadd
ProTip! Advisories are also available from the GraphQL API