Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7,907 advisories

Loading
@google/clasp vulnerable to unsafe path traversal cloning or pulling a malicious script High
CVE-2026-4092 was published for @google/clasp (npm) Mar 13, 2026
g0w6y Credited to g0w6y
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy Moderate
CVE-2026-30914 was published for github.com/drakkan/sftpgo (Go) Mar 13, 2026
mcantrell Credited to mcantrell
Magic Wormhole: "wormhole receive" allows arbitrary local file overwrite High
CVE-2026-32116 was published for magic-wormhole (pip) Mar 13, 2026
ikmckenz Credited to ikmckenz
Dagu: Path Traversal via `dagRunId` in Inline DAG Execution Critical
CVE-2026-31886 was published for github.com/dagu-org/dagu (Go) Mar 13, 2026
NucleiAv Credited to NucleiAv
TinaCMS Vulnerable to Path Traversal Leading to Arbitrary File Read, Write and Delete High
CVE-2026-28793 was published for @tinacms/cli (npm) Mar 12, 2026
alaeddine03 Credited to alaeddine03
alaeddine03 Credited to alaeddine03
Black: Arbitrary file writes from unsanitized user input in cache file name High
CVE-2026-32274 was published for black (pip) Mar 12, 2026
fg0x0 Credited to fg0x0
Tina: Path Traversal in Media Upload Handle High
CVE-2026-28791 was published for tinacms (npm) Mar 12, 2026
yueyueL Credited to yueyueL
@tinacms/graphql has a Path Traversal issue Moderate
CVE-2026-24125 was published for @tinacms/graphql (npm) Mar 12, 2026
ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink High
CVE-2026-32232 was published for zeptoclaw (Rust) Mar 12, 2026
zpbrent Credited to zpbrent
OpenClaw: workspace path guard bypass on non-existent out-of-root symlink leaf High
GHSA-mgrq-9f93-wpp5 was published for openclaw (npm) Mar 12, 2026
tdjackey Credited to tdjackey
@appium/support has a Zip Slip arbitrary file write in its ZIP extraction Moderate
CVE-2026-30973 was published for @appium/support (npm) Mar 11, 2026
bugbunny-research Credited to bugbunny-research
Wisp Vulnerable to Path Traversal High
CVE-2026-28807 was published for wisp (Erlang) Mar 11, 2026
jtdowney Credited to jtdowney and lpil lpil lpil
OliveTin's unsafe parsing of UniqueTrackingId can be used to write files High
CVE-2026-31817 was published for github.com/OliveTin/OliveTin (Go) Mar 11, 2026
iconnnjka Credited to iconnnjka
node-tar Symlink Path Traversal via Drive-Relative Linkpath High
CVE-2026-31802 was published for tar (npm) Mar 10, 2026
Jvr2022 Credited to Jvr2022
yotampe-pluto Credited to yotampe-pluto and gil-maman-p gil-maman-p gil-maman-p
Vaadin: Specially crafted ZIP archives can escape the intended extraction directory Low
CVE-2026-2741 was published for com.vaadin:flow-project (Maven) Mar 10, 2026
Apache PDFBox has Path Traversal through PDComplexFileSpecification.getFilename() function Moderate
CVE-2026-23907 was published for org.apache.pdfbox:pdfbox-examples (Maven) Mar 10, 2026
ProTip! Advisories are also available from the GraphQL API