GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
42
GitHub Actions
43
Go
3,164
Maven
5,000+
npm
5,000+
NuGet
863
pip
4,458
Pub
12
RubyGems
991
Rust
1,184
Swift
50
Unreviewed advisories
All unreviewed
5,000+
7,907 advisories
Filter by severity
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in...
Moderate
Unreviewed
CVE-2025-66249
was published
Mar 13, 2026
@google/clasp vulnerable to unsafe path traversal cloning or pulling a malicious script
High
CVE-2026-4092
was published
for
@google/clasp
(npm)
Mar 13, 2026
SFTPGo Vulnerable to Path Traversal and Permission Bypass via Path Normalization Discrepancy
Moderate
CVE-2026-30914
was published
for
github.com/drakkan/sftpgo
(Go)
Mar 13, 2026
Magic Wormhole: "wormhole receive" allows arbitrary local file overwrite
High
CVE-2026-32116
was published
for
magic-wormhole
(pip)
Mar 13, 2026
Dagu: Path Traversal via `dagRunId` in Inline DAG Execution
Critical
CVE-2026-31886
was published
for
github.com/dagu-org/dagu
(Go)
Mar 13, 2026
TinaCMS Vulnerable to Path Traversal Leading to Arbitrary File Read, Write and Delete
High
CVE-2026-28793
was published
for
@tinacms/cli
(npm)
Mar 12, 2026
TinaCMS CLI Dev Server Vulnerable to Cross-Origin File Exfiltration via CORS Misconfiguration + Path Traversal in TinaCMS
Critical
CVE-2026-28792
was published
for
@tinacms/cli
(npm)
Mar 12, 2026
Black: Arbitrary file writes from unsanitized user input in cache file name
High
CVE-2026-32274
was published
for
black
(pip)
Mar 12, 2026
Tina: Path Traversal in Media Upload Handle
High
CVE-2026-28791
was published
for
tinacms
(npm)
Mar 12, 2026
A vulnerability was detected in projectsend up to r1945. This affects the function realpath of...
Moderate
Unreviewed
CVE-2026-4044
was published
Mar 12, 2026
@tinacms/graphql has a Path Traversal issue
Moderate
CVE-2026-24125
was published
for
@tinacms/graphql
(npm)
Mar 12, 2026
ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink
High
CVE-2026-32232
was published
for
zeptoclaw
(Rust)
Mar 12, 2026
OpenClaw: workspace path guard bypass on non-existent out-of-root symlink leaf
High
GHSA-mgrq-9f93-wpp5
was published
for
openclaw
(npm)
Mar 12, 2026
A weakness has been identified in OpenBMB XAgent 1.0.0. Affected by this vulnerability is the...
Moderate
Unreviewed
CVE-2026-3954
was published
Mar 11, 2026
ARMBot contains an unrestricted file upload vulnerability in upload.php that allows...
High
Unreviewed
CVE-2019-25480
was published
Mar 11, 2026
FileThingie 2.5.7 contains an arbitrary file upload vulnerability that allows attackers to upload...
Critical
Unreviewed
CVE-2019-25471
was published
Mar 11, 2026
Coppermine Photo Gallery in versions 1.6.09 through 1.6.27 is vulnerable to path traversal....
High
Unreviewed
CVE-2026-3013
was published
Mar 11, 2026
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and...
Moderate
Unreviewed
CVE-2026-21360
was published
Mar 11, 2026
@appium/support has a Zip Slip arbitrary file write in its ZIP extraction
Moderate
CVE-2026-30973
was published
for
@appium/support
(npm)
Mar 11, 2026
OliveTin's unsafe parsing of UniqueTrackingId can be used to write files
High
CVE-2026-31817
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 11, 2026
node-tar Symlink Path Traversal via Drive-Relative Linkpath
High
CVE-2026-31802
was published
for
tar
(npm)
Mar 10, 2026
MCP Atlassian has an arbitrary file write leading to arbitrary code execution via unconstrained download_path in confluence_download_attachment
Critical
CVE-2026-27825
was published
for
mcp-atlassian
(pip)
Mar 10, 2026
Vaadin: Specially crafted ZIP archives can escape the intended extraction directory
Low
CVE-2026-2741
was published
for
com.vaadin:flow-project
(Maven)
Mar 10, 2026
Apache PDFBox has Path Traversal through PDComplexFileSpecification.getFilename() function
Moderate
CVE-2026-23907
was published
for
org.apache.pdfbox:pdfbox-examples
(Maven)
Mar 10, 2026
ProTip!
Advisories are also available from the
GraphQL API