Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,903 advisories

Loading
aws-cdk-lib: OS Command Injection in NodejsFunction Bundling High
CVE-2026-11417 was published for aws-cdk-lib (npm) Jun 15, 2026
Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration Moderate
CVE-2026-47751 was published for anthropics/claude-code-action (GitHub Actions) Jun 10, 2026
Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter Critical
CVE-2026-48030 was published for pheditor/pheditor (Composer) Jun 9, 2026
muslimbek-0x Credited to muslimbek-0x
DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php. Critical Unreviewed
CVE-2026-38615 was published Jun 9, 2026
shell-quote quote() does not escape newlines in object .op values Critical
CVE-2026-9277 was published for shell-quote (npm) Jun 9, 2026
akshatgit Credited to akshatgit and ljharb ljharb ljharb
ProTip! Advisories are also available from the GraphQL API