GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,651
Maven
5,000+
npm
4,279
NuGet
760
pip
4,066
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
166 advisories
Filter by severity
Magento is affected by an os command injection via the Data collection endpoint
High
CVE-2021-36024
was published
for
magento/community-edition
(Composer)
May 24, 2022
sqls-server/sqls is vulnerable to command injection in the config command
High
CVE-2025-61141
was published
for
github.com/sqls-server/sqls
(Go)
Oct 30, 2025
Remote code execution (RCE) in Apache Airflow
High
CVE-2020-11978
was published
for
apache-airflow
(pip)
Jul 27, 2020
`git-comiters` Command Injection vulnerability
High
CVE-2025-59831
was published
for
git-commiters
(npm)
Sep 22, 2025
LiteLLM Vulnerable to Remote Code Execution (RCE)
High
CVE-2024-6825
was published
for
litellm
(pip)
Mar 20, 2025
Flowise: Authenticated Command Execution and Sandbox Bypass via Puppeteer and Playwright Packages
High
CVE-2025-34267
was published
for
flowise
(npm)
Oct 14, 2025
Deno is Vulnerable to Command Injection on Windows During Batch File Execution
High
CVE-2025-61787
was published
for
deno
(Rust)
Oct 8, 2025
figma-developer-mcp vulnerable to command injection in get_figma_data tool
High
CVE-2025-53967
was published
for
figma-developer-mcp
(npm)
Sep 30, 2025
TYPO3 Install Tool vulnerable to Code Execution
High
CVE-2024-22188
was published
for
typo3/cms-core
(Composer)
Feb 13, 2024
mcp-markdownify-server vulnerable to command injection in pptx-to-markdown tool
High
CVE-2025-58358
was published
for
mcp-markdownify-server
(npm)
Sep 2, 2025
Command Injection via sonarqube-scan-action GitHub Action
High
CVE-2025-58178
was published
for
SonarSource/sonarqube-scan-action
(GitHub Actions)
Sep 2, 2025
1Panel agent certificate verification bypass leading to arbitrary command execution
High
CVE-2025-54424
was published
for
github.com/1Panel-dev/1Panel/core
(Go)
Aug 1, 2025
mcp-package-docs vulnerable to command injection in several tools
High
CVE-2025-54073
was published
for
mcp-package-docs
(npm)
Aug 5, 2025
File Browser vulnerable to command execution allowlist bypass
High
CVE-2025-52995
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 30, 2025
File Browser: Command Execution not Limited to Scope
High
CVE-2025-52904
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 30, 2025
filebrowser Allows Shell Commands to Spawn Other Commands
High
CVE-2025-52903
was published
for
github.com/filebrowser/filebrowser
(Go)
Jun 27, 2025
@translated/lara-mcp vulnerable to command injection in import_tmx tool
High
CVE-2025-53832
was published
for
@translated/lara-mcp
(npm)
Jul 21, 2025
MCP Server Kubernetes vulnerable to command injection in several tools
High
CVE-2025-53355
was published
for
mcp-server-kubernetes
(npm)
Jul 8, 2025
Node.js Sandbox MCP Server vulnerability can lead to Sandbox Escape via Command Injection
High
CVE-2025-53372
was published
for
node-code-sandbox-mcp
(npm)
Jul 8, 2025
Databricks JDBC Driver Command Injection vulnerability
High
CVE-2024-49194
was published
for
com.databricks:databricks-jdbc
(Maven)
Dec 17, 2024
@cyanheads/git-mcp-server vulnerable to command injection in several tools
High
CVE-2025-53107
was published
for
@cyanheads/git-mcp-server
(npm)
Jun 30, 2025
@hoppscotch/cli affected by Sandbox Escape in @hoppscotch/js-sandbox leads to RCE
High
CVE-2024-34347
was published
for
@hoppscotch/cli
(npm)
Apr 22, 2024
Composer has a command injection via malicious git branch name
High
CVE-2024-35241
was published
for
composer/composer
(Composer)
Jun 10, 2024
Apache Kylin vulnerable to Command injection by Useless configuration
High
CVE-2022-43396
was published
for
org.apache.kylin:kylin
(Maven)
Dec 30, 2022
ProTip!
Advisories are also available from the
GraphQL API