GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
216 advisories
Filter by severity
OS Command Injection and Command Injection in kill-port-process
Critical
CVE-2019-15609
was published
for
kill-port-process
(npm)
Feb 10, 2022
shell-quote quote() does not escape newlines in object .op values
Critical
CVE-2026-9277
was published
for
shell-quote
(npm)
Jun 9, 2026
Authenticated Remote Code Execution via loadReader functionName code injection in DbGate
Critical
CVE-2026-47670
was published
for
dbgate-api
(npm)
Jun 5, 2026
launch-editor vulnerable to command injection via the crafted request on Windows
High
CVE-2024-52011
was published
for
launch-editor
(npm)
Jun 3, 2026
ngrok is Vulnerable to Command Injection
High
CVE-2025-57282
was published
for
ngrok
(npm)
May 18, 2026
electerm has Command Injection via runLinux funtion
Critical
CVE-2026-41501
was published
for
electerm
(npm)
Apr 24, 2026
electerm: electerm_install_script_CommandInjection Vulnerability Report
Critical
CVE-2026-41500
was published
for
electerm
(npm)
Apr 16, 2026
Claude Code: Trust Dialog Bypass via Git Worktree Spoofing Allows Arbitrary Code Execution
High
CVE-2026-40068
was published
for
@anthropic-ai/claude-code
(npm)
Apr 24, 2026
yii2-mcp-server has a Command Injection Issue
Low
CVE-2026-7600
was published
for
yii2-mcp-server
(npm)
May 2, 2026
mcp-server-semgrep has a Command Injection issue
Moderate
CVE-2026-7446
was published
for
mcp-server-semgrep
(npm)
Apr 30, 2026
Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses
Critical
GHSA-wpqr-6v78-jr5g
was published
for
@google/gemini-cli
(GitHub Actions)
Apr 24, 2026
Flowise: Airtable_Agent Code Injection Remote Code Execution Vulnerability
Critical
CVE-2026-41265
was published
for
flowise
(npm)
Apr 18, 2026
Paperclip: Malicious skills able to exfiltrate and destroy all user data
High
GHSA-w8hx-hqjv-vjcq
was published
for
@paperclipai/server
(npm)
Apr 16, 2026
OpenClaw: Arbitrary code execution via unvalidated WebView JavascriptInterface
High
CVE-2026-35643
was published
for
openclaw
(npm)
Mar 26, 2026
Agions taskflow-ai vulnerable to os command injection in src/mcp/server/handlers.ts
Moderate
CVE-2026-5831
was published
for
taskflow-ai
(npm)
Apr 9, 2026
@elgentos/magento2-dev-mcp vulnerable to command injection
Low
CVE-2026-5603
was published
for
@elgentos/magento2-dev-mcp
(npm)
Apr 6, 2026
@nor2/heim-mcp vulnerable to command injection
Low
CVE-2026-5602
was published
for
@nor2/heim-mcp
(npm)
Apr 6, 2026
Duplicate Advisory: OpenClaw's system.run shell-wrapper positional argv carriers could execute hidden commands under misleading approval text
Moderate
GHSA-w6f4-3v35-qjhj
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
OpenClaw Improperly Neutralizes Line Breaks in systemd Unit Generation Enables Local Command Execution (Linux)
High
CVE-2026-32063
was published
for
openclaw
(npm)
Mar 3, 2026
@siteboon/claude-code-ui is Vulnerable to Command Injection via Multiple Parameters
Critical
CVE-2026-31862
was published
for
@siteboon/claudecodeui
(npm)
Mar 11, 2026
@budibase/server: Command Injection in PostgreSQL Dump Command
High
CVE-2026-25041
was published
for
@budibase/server
(npm)
Mar 9, 2026
xcode-mcp-server vulnerable to Command Injection
Low
CVE-2026-2178
was published
for
xcode-mcp-server
(npm)
Feb 8, 2026
MCP NMAP Server has an Injection vulnerability
Moderate
CVE-2026-3484
was published
for
mcp-nmap-server
(npm)
Mar 3, 2026
Orval Mock Generation Code Injection via const
High
CVE-2026-24132
was published
for
@orval/mock
(npm)
Jan 22, 2026
ProTip!
Advisories are also available from the
GraphQL API