Sitelet https://github.com/advisories
Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

34,713 advisories

Loading
mcp-shell has a Secure Mode Allowlist Bypass via Git Shell Alias High
CVE-2026-55582 was published for github.com/sonirico/mcp-shell (Go) Aug 25, 2026
EQSTLab Credited to EQSTLab and sonirico sonirico sonirico
qwed-mcp has Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression Input Critical
CVE-2026-55546 was published for qwed-mcp (pip) Aug 25, 2026
hoanggxyuuki Credited to hoanggxyuuki and NguyenHuyTrung NguyenHuyTrung NguyenHuyTrung
PraisonAI: `--api-key` flag on `praisonai serve` is not properly enforced High
CVE-2026-55541 was published for PraisonAI (pip) Aug 25, 2026
saisathvik1 Credited to saisathvik1
PraisonAI vulnerable to Server-Side Request Forgery via DNS rebinding bypass in webhook_url validation Moderate
CVE-2026-55535 was published for PraisonAI (pip) Aug 25, 2026
vndasunkid Credited to vndasunkid
evertrustai Credited to evertrustai
PraisonAI: [Path Traversal] agent tools escape the configured workspace via symlinks High
CVE-2026-55540 was published for PraisonAI (pip) Aug 25, 2026
riodrwn Credited to riodrwn
SnailSploit Credited to SnailSploit
sour-exploit Credited to sour-exploit
PraisonAI serve agents --api-key is ignored, allowing unauthenticated remote agent execution High
CVE-2026-55534 was published for PraisonAI (pip) Aug 25, 2026
huslayer826 Credited to huslayer826
evertrustai Credited to evertrustai
geo-chen Credited to geo-chen
praisonaiagents: AgentServer declares auth_token but never enforces it on any route High
CVE-2026-55528 was published for praisonaiagents (pip) Aug 25, 2026
SnailSploit Credited to SnailSploit
hoanggxyuuki Credited to hoanggxyuuki and NguyenHuyTrung NguyenHuyTrung NguyenHuyTrung
praisonaiagents has a `web_crawl` SSRF protection bypass via unchecked redirect targets High
CVE-2026-55523 was published for praisonaiagents (pip) Aug 25, 2026
rexpository Credited to rexpository
PraisonAI workflow include bypasses tools.py autoload opt-in and executes included recipe code High
CVE-2026-55522 was published for PraisonAI (pip) Aug 25, 2026
rexpository Credited to rexpository
praisonaiagents web_crawl vulnerable to SSRF via redirect-following High
CVE-2026-55525 was published for praisonaiagents (pip) Aug 25, 2026
Ampliox Credited to Ampliox
Cloudreve's remote download file paths can escape the selected destination directory Moderate
GHSA-w8j7-39hp-8x59 was published for github.com/cloudreve/Cloudreve/v4 (Go) Aug 24, 2026
jinhao-huang Credited to jinhao-huang
Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint Moderate
GHSA-vx2m-jpxr-xv7w was published for github.com/cloudreve/Cloudreve/v4 (Go) Aug 24, 2026
riodrwn Credited to riodrwn
ProTip! Advisories are also available from the GraphQL API