GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,874
Erlang
37
GitHub Actions
36
Go
2,520
Maven
5,000+
npm
4,160
NuGet
741
pip
3,961
Pub
12
RubyGems
946
Rust
1,028
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,213 advisories
Filter by severity
podman kube play symlink traversal vulnerability
High
CVE-2025-9566
was published
for
github.com/containers/podman/v4
(Go)
Sep 4, 2025
InvokeAI has External Control of File Name or Path
Critical
CVE-2025-6237
was published
for
invokeai
(pip)
Sep 18, 2025
astral-tokio-tar has a path traversal in tar extraction
Moderate
CVE-2025-59825
was published
for
astral-tokio-tar
(Rust)
Sep 23, 2025
Mattermost Path Traversal vulnerability
High
CVE-2025-9079
was published
for
github.com/mattermost/mattermost-server
(Go)
Sep 19, 2025
Nuxt has Client-Side Path Traversal in Nuxt Island Payload Revival
Low
CVE-2025-59414
was published
for
nuxt
(npm)
Sep 17, 2025
DragonFly vulnerable to arbitrary file read and write on a peer machine
Moderate
CVE-2025-59352
was published
for
github.com/dragonflyoss/dragonfly
(Go)
Sep 17, 2025
Langchain-Chatchat has a Path Traversal vulnerability
Low
CVE-2025-6853
was published
for
langchain-chatchat
(pip)
Jun 29, 2025
Flowise has arbitrary file access due to missing chat flow id validation
Critical
GHSA-q67q-549q-p849
was published
for
flowise
(npm)
Sep 15, 2025
Mockoon has a Path Traversal and LFI in the static file serving endpoint
High
CVE-2025-59049
was published
for
@mockoon/cli
(npm)
Mar 11, 2025
internetarchive Vulnerable to Directory Traversal in File.download()
Critical
CVE-2025-58438
was published
for
internetarchive
(pip)
Sep 5, 2025
xml2rfc is vulnerable to arbitrary file reads through prepped files
High
GHSA-9mv7-3c64-mmqw
was published
for
xml2rfc
(pip)
Sep 10, 2025
MONAI does not prevent path traversal, potentially leading to arbitrary file writes
High
CVE-2025-58755
was published
for
monai
(pip)
Sep 9, 2025
Vite middleware may serve files starting with the same name with the public directory
Low
CVE-2025-58751
was published
for
vite
(npm)
Sep 9, 2025
Path Traversal in Liferay Portal
High
CVE-2022-42123
was published
for
com.liferay.portal:release.portal.bom
(Maven)
Nov 15, 2022
Hexo `include_code` has a path traversal
High
CVE-2023-39584
was published
for
hexo
(npm)
Sep 8, 2023
Soft Serve vulnerable to arbitrary file writing through SSH API
High
CVE-2025-58355
was published
for
github.com/charmbracelet/soft-serve
(Go)
Sep 2, 2025
MobSF Path Traversal in GET /download/<filename> using absolute filenames
Low
CVE-2025-58161
was published
for
mobsf
(pip)
Sep 2, 2025
MobSF Vulnerable to Arbitrary File Write (AR-Slip) via Absolute Path in .a Extraction
Moderate
CVE-2025-58162
was published
for
mobsf
(pip)
Sep 2, 2025
Harness Allows Arbitrary File Write in Gitness LFS server
High
CVE-2025-58158
was published
for
github.com/harness/gitness
(Go)
Aug 29, 2025
Mattermost Fails to Sanitize File Names
Moderate
CVE-2025-6465
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost Fails to Sanitize Path Traversal Sequences
Moderate
CVE-2025-8023
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Mattermost Fails to Validate File Paths
Moderate
CVE-2025-36530
was published
for
github.com/mattermost/mattermost-server
(Go)
Aug 21, 2025
Dpanel has an arbitrary file read vulnerability
Moderate
CVE-2025-53363
was published
for
github.com/donknap/dpanel
(Go)
Aug 22, 2025
Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat
Moderate
CVE-2015-5174
was published
for
org.apache.tomcat:tomcat
(Maven)
May 14, 2022
Improper Limitation of a Pathname to a Restricted Directory in Apache Tomcat
Moderate
CVE-2015-5345
was published
for
org.apache.tomcat:tomcat
(Maven)
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API