Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

155 advisories

Loading
Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket High
CVE-2026-53657 was published for github.com/lima-vm/lima/v2 (Go) Aug 14, 2026
misop00p Credited to misop00p and ansjdnakjdnajkd ansjdnakjdnajkd ansjdnakjdnajkd
Duplicate Advisory: SurrealDB has Silent Failure to Overwrite Table Definition of Relation Type Low
GHSA-vmg6-53r4-jhpw was published for surrealdb (Rust) Jul 18, 2026 withdrawn
Duplicate Advisory: Full Table Permissions by Default High
GHSA-m8pp-qc66-6pgp was published for surrealdb (Rust) Jul 18, 2026 withdrawn
YesWiki vulnerable to unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action Critical
CVE-2026-52766 was published for yeswiki/yeswiki (Composer) Jul 9, 2026
CosmicCrusader23 Credited to CosmicCrusader23
turso-cli persists Turso platform JWT with world-readable (0o644) file permissions Moderate
CVE-2026-48790 was published for github.com/tursodatabase/turso-cli (Go) Jun 26, 2026
nextflow auth login command has incorrect default permissions Moderate
CVE-2026-48722 was published for io.nextflow:nextflow (Maven) Jun 25, 2026
OpenClaw: Config recovery could restore openclaw.json with broad file permissions Moderate
CVE-2026-53856 was published for openclaw (npm) Jun 18, 2026
Kaze310 Credited to Kaze310
Nuxt dev server vite-node IPC socket is world-connectable on Linux Moderate
GHSA-534h-c3cw-v3h9 was published for nuxt (npm) Jun 16, 2026
alcls01111 Credited to alcls01111
Apache ActiveMQ has an Incorrect Default Permissions vulnerability High
CVE-2026-49157 was published for org.apache.activemq:apache-activemq (Maven) Jun 1, 2026
Spring AI: ChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakage High
CVE-2026-41712 was published for org.springframework.ai:spring-ai-advisors-vector-store (Maven) May 12, 2026
openclaw-claude-bridge: sandbox is not effective - `--allowed-tools ""` does not restrict available tools Moderate
CVE-2026-39398 was published for openclaw-claude-bridge (npm) Apr 8, 2026
Claude SDK for Python has Insecure Default File Permissions in Local Filesystem Memory Tool Moderate
CVE-2026-34450 was published for anthropic (pip) Apr 1, 2026
gn00295120 Credited to gn00295120
Judel777 Credited to Judel777
OpenClaw session transcript files were created without forced user-only permissions Moderate
CVE-2026-33572 was published for openclaw (npm) Mar 16, 2026
hsongkai11 Credited to hsongkai11
.NET Elevation of Privilege Vulnerability High
CVE-2026-26131 was published for Microsoft.NetCore.App.Runtime.linux-arm (NuGet) Mar 11, 2026
igorkovalchuk Credited to igorkovalchuk
Duplicate Advisory: Microsoft Security Advisory CVE-2026-26131 – .NET Elevation of Privilege Vulnerability High
GHSA-387c-qmrw-59qv was published for Microsoft.NetCore.App.Runtime.linux-arm (NuGet) Mar 10, 2026 withdrawn
AWS CLI: cli_history database does not restrict file permissions on Unix systems Moderate
GHSA-747p-wmpv-9c78 was published for awscli (pip) Feb 27, 2026
AutoGPT is Vulnerable to RCE via Disabled Block Execution High
CVE-2026-24780 was published for agpt (pip) Jan 29, 2026
rahulgovind Credited to rahulgovind
Pepr Has Overly Permissive RBAC ClusterRole in Admin Mode Low
CVE-2026-23634 was published for pepr (npm) Jan 15, 2026
tghastings Credited to tghastings
Mattermost allows other users to determine when users had read channels via channel member objects Low
CVE-2025-55074 was published for github.com/mattermost/mattermost-server (Go) Nov 18, 2025
XWiki AdminTools application doesn't set permissions on the AdminTools space Moderate
CVE-2025-54990 was published for com.xwiki.admintools:application-admintools (Maven) Nov 18, 2025
KubeVirt Excessive Role Permissions Could Enable Unauthorized VMI Migrations Between Nodes Moderate
CVE-2025-64436 was published for kubevirt.io/kubevirt (Go) Nov 6, 2025
mihailkirov Credited to mihailkirov, Faeris95, and xpivarc Faeris95 Faeris95
xpivarc xpivarc
Dragonfly's directories created via os.MkdirAll are not checked for permissions Low
CVE-2025-59349 was published for d7y.io/dragonfly/v2 (Go) Sep 17, 2025
gaius-qi Credited to gaius-qi
Apache DolphinScheduler Incorrect Default Permissions Vulnerability Low
CVE-2024-43166 was published for org.apache.dolphinscheduler:dolphinscheduler (Maven) Sep 3, 2025
ProTip! Advisories are also available from the GraphQL API