Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

36,257 advisories

Loading
alham-rizvi Credited to alham-rizvi
Wasmtime: Preemption and traps during bulk operations enable breaking internal VM state Low
CVE-2026-104855 was published for wasmtime (Rust) Oct 2, 2026
Trigger.dev: Trigger CLI debug deployment logs expose resolved environment secret values Moderate
GHSA-fj2x-mqqp-3v2w was published for trigger.dev (npm) Oct 2, 2026
Vibe-Trading FastAPI endpoints permit unauthenticated access, file upload, and an RCE chain Critical
GHSA-v2f8-6655-7grj was published for vibe-trading-ai (pip) Oct 2, 2026
lemi9090 Credited to lemi9090
Vibe-Trading file-read tools expose arbitrary server-readable files High
GHSA-5rmq-chc7-m22f was published for vibe-trading-ai (pip) Oct 2, 2026
lemi9090 Credited to lemi9090
Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRF Critical
GHSA-jqmf-mx4f-hfr6 was published for vibe-trading-ai (pip) Oct 2, 2026
lemi9090 Credited to lemi9090
Trigger.dev: Cross-environment deployment cancel Moderate
GHSA-4672-hwv6-gq62 was published for trigger.dev (npm) Oct 2, 2026
CyberKareem Credited to CyberKareem
sajdakabir Credited to sajdakabir
Trigger.dev: Unauthenticated Realtime Stream Data Injection via Run FriendlyId Moderate
GHSA-59h8-w5q6-mfmp was published for trigger.dev (npm) Oct 2, 2026
sfwani Credited to sfwani, dodge1218, geo-chen, and MatiasTilleriasLey dodge1218 dodge1218
geo-chen geo-chen MatiasTilleriasLey MatiasTilleriasLey
Trigger.dev Self-Hosted Deployment: Default Secrets allow Unauthenticated Infrastructure Compromise High
GHSA-pqxw-g93w-hj9x was published for trigger.dev (npm) Oct 2, 2026
sfwani Credited to sfwani
ismayilamiraslanov555 Credited to ismayilamiraslanov555
Trigger.dev: V1 coordinator default-secret unauth Socket.IO Critical
GHSA-gg6r-gp4c-89hp was published for trigger.dev (npm) Oct 2, 2026
lissy93 Credited to lissy93
geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point Moderate
CVE-2026-77387 was published for geopy (pip) Oct 2, 2026
gnsehfvlr Credited to gnsehfvlr, apoorvdarshan, and KostyaEsmukov apoorvdarshan apoorvdarshan
KostyaEsmukov KostyaEsmukov
Xray-core: Pinning a CA certificate via pinnedPeerCertSha256 can lead to the success of MITM attacks High
GHSA-5wf9-h793-w73c was published for github.com/xtls/xray-core (Go) Oct 2, 2026
Trigger.dev: Blind SSRF via alert-channel webhook Moderate
GHSA-q567-cr4x-96w4 was published for trigger.dev (npm) Oct 2, 2026
CyberKareem Credited to CyberKareem and dizconnectz dizconnectz dizconnectz
Trigger.dev: Missing Authentication in Run Replay Action Allows Cross-Organization Task Execution (IDOR) High
GHSA-pp95-gc86-jq6q was published for trigger.dev (npm) Oct 2, 2026
sajdakabir Credited to sajdakabir and zerotrail-ai zerotrail-ai zerotrail-ai
Trigger.dev: Server-side request forgery via unvalidated webhook alert-channel URL High
GHSA-xxv7-2vv3-h682 was published for trigger.dev (npm) Oct 2, 2026
geo-chen Credited to geo-chen
Trigger.dev: Run replay injects a task run into an attacker-chosen environment (cross-tenant write) High
GHSA-qxpp-qjg8-x4jv was published for trigger.dev (npm) Oct 2, 2026
geo-chen Credited to geo-chen
Composer: GHSA-gjfg-22fp-rrxx fix bypass via symlinked package bin path Moderate
CVE-2026-59944 was published for composer/composer (Composer) Oct 2, 2026
DavidCarliez Credited to DavidCarliez, manus-use, and arpitjain099 manus-use manus-use
arpitjain099 arpitjain099
Dulwich: Arbitrary File Write (RCE) on Windows via Unvalidated Drive Letters in Tree Paths High
GHSA-8mcx-5rqc-vhmf was published for dulwich (pip) Oct 2, 2026
LukeBanto Credited to LukeBanto and jelmer jelmer jelmer
Dulwich: Infinite Loop Denial of Service (DoS) in Packfile Object Resolution Moderate
GHSA-35mr-4567-66vg was published for dulwich (pip) Oct 2, 2026
LukeBanto Credited to LukeBanto
Dulwich: Symlink write-through in checkout(paths=[]) via raw os.open bypasses all symlink protections High
GHSA-8w8g-wq8h-fq33 was published for dulwich (pip) Oct 2, 2026
manus-use Credited to manus-use and jelmer jelmer jelmer
Dulwich: Symlink directory traversal in filter-branch index_filter via cross-commit state persistence High
GHSA-5fqc-mrg8-w798 was published for dulwich (pip) Oct 2, 2026
manus-use Credited to manus-use and jelmer jelmer jelmer
manus-use Credited to manus-use and jelmer jelmer jelmer
ProTip! Advisories are also available from the GraphQL API