GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            518 advisories
        Filter by severity
        
      
      
    
                    
                      Keras framework vulnerable to deserialization of untrusted data
                    
                      
  Critical
                    
                
                      
                        CVE-2025-49655
                      
                      was published
                        for
                        
                          keras
                        
                        (pip)
                      Oct 17, 2025 
                    
                  
                    
                      pyquokka is Vulnerable to Remote Code Execution by Pickle Deserialization via FlightServer 
                    
                      
  Critical
                    
                
                      
                        CVE-2025-62515
                      
                      was published
                        for
                        
                          pyquokka
                        
                        (pip)
                      Oct 17, 2025 
                    
                  
                    
                      BBOT's insufficient sanitization issues in gitdumper.py can lead to RCE
                    
                      
  Critical
                    
                
                      
                        CVE-2025-10283
                      
                      was published
                        for
                        
                          bbot
                        
                        (pip)
                      Oct 9, 2025 
                    
                  
                    
                      BBOT's various issues in unarchive.py can cause arbitrary file write and RCE
                    
                      
  Critical
                    
                
                      
                        CVE-2025-10284
                      
                      was published
                        for
                        
                          bbot
                        
                        (pip)
                      Oct 9, 2025 
                    
                  
                    
                      scio is vunerable to  Remote Command Execution  through PyTorch
                    
                      
  Critical
                    
                
                      
                        GHSA-m9mp-6x32-5rhg
                      
                      was published
                        for
                        
                          scio-pypi
                        
                        (pip)
                      Oct 9, 2025 
                    
                  
                    
                      Apache Pyfory python is vulnerable to deserialization of untrusted data
                    
                      
  Critical
                    
                
                      
                        CVE-2025-61622
                      
                      was published
                        for
                        
                          pyfory
                        
                        (pip)
                      Oct 1, 2025 
                    
                  
                    
                      H2O affected by a deserialization vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2025-6544
                      
                      was published
                        for
                        
                          ai.h2o:h2o-core
                        
                        (Maven)
                      Sep 22, 2025 
                    
                  
                    
                      InvokeAI has External Control of File Name or Path
                    
                      
  Critical
                    
                
                      
                        CVE-2025-6237
                      
                      was published
                        for
                        
                          invokeai
                        
                        (pip)
                      Sep 18, 2025 
                    
                  
                    
                      Duplicate Advisory: Picklescan is Vulnerable to Unsafe Globals Check Bypass through Subclass Imports
                    
                      
  Critical
                    
                
                      
                        GHSA-hf6h-9wq7-hmjg
                      
                      was published
                        for
                        
                          picklescan
                        
                        (pip)
                      Sep 17, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      Duplicate Advisory: Picklescan: ZIP archive scan bypass is possible through non-exhaustive Cyclic Redundancy Check
                    
                      
  Critical
                    
                
                      
                        GHSA-4vr7-g93g-cf6m
                      
                      was published
                        for
                        
                          picklescan
                        
                        (pip)
                      Sep 17, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      Duplicate Advisory: Picklescan Bypass is Possible via File Extension Mismatch
                    
                      
  Critical
                    
                
                      
                        GHSA-j424-mc44-f4hj
                      
                      was published
                        for
                        
                          picklescan
                        
                        (pip)
                      Sep 17, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      mcp-kubernetes-server has an OS Command Injection vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2025-59377
                      
                      was published
                        for
                        
                          mcp-kubernetes-server
                        
                        (pip)
                      Sep 15, 2025 
                    
                  
                    
                      Picklescan Bypass is Possible via File Extension Mismatch
                    
                      
  Critical
                    
                
                      
                        CVE-2025-10155
                      
                      was published
                        for
                        
                          picklescan
                        
                        (pip)
                      Sep 10, 2025 
                    
                  
                    
                      Picklescan: ZIP archive scan bypass is possible through non-exhaustive Cyclic Redundancy Check
                    
                      
  Critical
                    
                
                      
                        CVE-2025-10156
                      
                      was published
                        for
                        
                          picklescan
                        
                        (pip)
                      Sep 10, 2025 
                    
                  
                    
                      Picklescan is Vulnerable to Unsafe Globals Check Bypass through Subclass Imports
                    
                      
  Critical
                    
                
                      
                        CVE-2025-10157
                      
                      was published
                        for
                        
                          picklescan
                        
                        (pip)
                      Sep 10, 2025 
                    
                  
                    
                      internetarchive Vulnerable to Directory Traversal in File.download()
                    
                      
  Critical
                    
                
                      
                        CVE-2025-58438
                      
                      was published
                        for
                        
                          internetarchive
                        
                        (pip)
                      Sep 5, 2025 
                    
                  
                    
                      TkEasyGUI Vulnerable to OS Command Injection
                    
                      
  Critical
                    
                
                      
                        CVE-2025-55037
                      
                      was published
                        for
                        
                          TkEasyGUI
                        
                        (pip)
                      Sep 5, 2025 
                    
                  
                    
                      Pixar OpenUSD Sdf_PathNode Module Use-After-Free Vulnerability Leading to Potential Remote Code Execution
                    
                      
  Critical
                    
                
                      
                        GHSA-58p5-r2f6-g2cj
                      
                      was published
                        for
                        
                          usd-core
                        
                        (pip)
                      Sep 4, 2025 
                    
                  
                    
                      DeepDiff Class Pollution in Delta class leading to DoS, Remote Code Execution, and more
                    
                      
  Critical
                    
                
                      
                        CVE-2025-58367
                      
                      was published
                        for
                        
                          deepdiff
                        
                        (pip)
                      Sep 3, 2025 
                    
                  
                    
                      ExecuTorch vulnerable to Heap-based Buffer Overflow
                    
                      
  Critical
                    
                
                      
                        CVE-2025-54951
                      
                      was published
                        for
                        
                          executorch
                        
                        (Maven)
                      Aug 8, 2025 
                    
                  
                    
                      ExecuTorch integer overflow vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2025-30404
                      
                      was published
                        for
                        
                          executorch
                        
                        (Maven)
                      Aug 8, 2025 
                    
                  
                    
                      ExecuTorch heap buffer overflow vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2025-54949
                      
                      was published
                        for
                        
                          executorch
                        
                        (Maven)
                      Aug 8, 2025 
                    
                  
                    
                      ExecuTorch out-of-bounds access vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2025-54950
                      
                      was published
                        for
                        
                          executorch
                        
                        (Maven)
                      Aug 8, 2025 
                    
                  
                    
                      ExecuTorch integer overflow vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2025-30405
                      
                      was published
                        for
                        
                          executorch
                        
                        (Maven)
                      Aug 8, 2025 
                    
                  
                    
                      pyLoad CNL Blueprint allows Path Traversal through `dlc_path` which leads to Remote Code Execution (RCE)
                    
                      
  Critical
                    
                
                      
                        CVE-2025-54802
                      
                      was published
                        for
                        
                          pyload-ng
                        
                        (pip)
                      Aug 4, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API