GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,635
Maven
5,000+
npm
4,262
NuGet
760
pip
4,057
Pub
12
RubyGems
956
Rust
1,054
Swift
45
Unreviewed advisories
All unreviewed
5,000+
433 advisories
Filter by severity
motionEye vulnerable to RCE via unsanitized motion config parameter
High
CVE-2025-60787
was published
for
motioneye
(pip)
Nov 3, 2025
@react-native-community/cli has arbitrary OS command injection
Critical
CVE-2025-11953
was published
for
@react-native-community/cli
(npm)
Nov 3, 2025
Apache Airflow has a command injection vulnerability in "example_dag_decorator"
Moderate
CVE-2025-54941
was published
for
apache-airflow
(pip)
Oct 30, 2025
FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name
Moderate
CVE-2025-62801
was published
for
fastmcp
(pip)
Oct 29, 2025
Jenkins Azure CLI Plugin does not restrict the commands it executes
High
CVE-2025-64140
was published
for
org.jenkins-ci.plugins:azure-cli
(Maven)
Oct 29, 2025
Kottster app reinitialization can be re-triggered allowing command injection in development mode
High
CVE-2025-62713
was published
for
@kottster/server
(npm)
Oct 23, 2025
NeuVector Enforcer is vulnerable to Command Injection and Buffer overflow
Critical
CVE-2025-54469
was published
for
github.com/neuvector/neuvector
(Go)
Oct 21, 2025
Netty has SMTP Command Injection Vulnerability that Allows Email Forgery
High
CVE-2025-59419
was published
for
io.netty:netty-codec-smtp
(Maven)
Oct 15, 2025
n8n: Execute Command Node Allows Authenticated Users to Run Arbitrary Commands on Host
High
GHSA-365g-vjw2-grx8
was published
for
n8n
(npm)
Oct 9, 2025
check-branches is vulnerable to command Injection
Critical
CVE-2025-11148
was published
for
check-branches
(npm)
Sep 30, 2025
Argument injection vulnerability in SonarQube Scan Action
High
CVE-2025-59844
was published
for
SonarSource/sonarqube-scan-action
(GitHub Actions)
Sep 26, 2025
Command Injection in adb-mcp MCP Server
Critical
CVE-2025-59834
was published
for
adb-mcp
(npm)
Sep 24, 2025
`git-comiters` Command Injection vulnerability
High
CVE-2025-59831
was published
for
git-commiters
(npm)
Sep 22, 2025
Flowise has unsandboxed remote code execution via Custom MCP
High
GHSA-6933-jpx5-q87q
was published
for
flowise
(npm)
Sep 15, 2025
mcp-kubernetes-server has an OS Command Injection vulnerability
Critical
CVE-2025-59377
was published
for
mcp-kubernetes-server
(pip)
Sep 15, 2025
Chaos Controller Manager is vulnerable to OS command injection
Critical
CVE-2025-59361
was published
for
github.com/chaos-mesh/chaos-mesh
(Go)
Sep 15, 2025
Chaos Controller Manager is vulnerable to OS command injection
Critical
CVE-2025-59359
was published
for
github.com/chaos-mesh/chaos-mesh
(Go)
Sep 15, 2025
Chaos Controller Manager is vulnerable to OS command injection
Critical
CVE-2025-59360
was published
for
github.com/chaos-mesh/chaos-mesh
(Go)
Sep 15, 2025
Claude Code vulnerable to arbitrary code execution caused by maliciously configured git email
High
CVE-2025-59041
was published
for
@anthropic-ai/claude-code
(npm)
Sep 10, 2025
Hoverfly is vulnerable to Remote Code Execution through an insecure middleware implementation
Critical
CVE-2025-54123
was published
for
github.com/SpectoLabs/hoverfly
(Go)
Sep 10, 2025
OctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File Upload
High
CVE-2025-58180
was published
for
octoprint
(pip)
Sep 9, 2025
@akoskm/create-mcp-server-stdio is vulnerable to MCP Server Command Injection through `exec` API
Critical
CVE-2025-54994
was published
for
@akoskm/create-mcp-server-stdio
(npm)
Sep 8, 2025
TkEasyGUI Vulnerable to OS Command Injection
Critical
CVE-2025-55037
was published
for
TkEasyGUI
(pip)
Sep 5, 2025
Valtimo scripting engine can be used to gain access to sensitive data or resources
Critical
CVE-2025-58059
was published
for
com.ritense.valtimo:core
(Maven)
Aug 28, 2025
wong2 mcp-cli Command Injection Vulnerability
Low
CVE-2025-9262
was published
for
@wong2/mcp-cli
(npm)
Aug 21, 2025
ProTip!
Advisories are also available from the
GraphQL API