GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,553
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
59 advisories
Filter by severity
Ember has unneutralized terminal escape/control sequences from Caddy logs injected into the operator's TUI
Moderate
CVE-2026-54162
was published
for
github.com/alexandre-daubois/ember
(Go)
Aug 20, 2026
broot renders each file and directory name in its interactive tree view exactly as read from the...
Low
Unreviewed
CVE-2026-72847
was published
Aug 20, 2026
powerlevel10k fails to neutralize control characters in the package.json version field when...
Moderate
Unreviewed
CVE-2026-75483
was published
Aug 17, 2026
Bash-it 3.2.0 contains a terminal escape sequence injection vulnerability in the barbuk theme's...
Moderate
Unreviewed
CVE-2026-73036
was published
Aug 11, 2026
npm-check-updates through 23.0.2, fixed in commit b554b84, contains a terminal escape sequence...
Moderate
Unreviewed
CVE-2026-73035
was published
Aug 10, 2026
Oh My Posh: Terminal escape sequence injection via unsanitized prompt segment data
Moderate
CVE-2026-73506
was published
for
github.com/jandedobbeleer/oh-my-posh
(Go)
Jul 24, 2026
Shescape: Shell injection via unescaped parentheses on Windows with CMD
Critical
CVE-2026-73414
was published
for
shescape
(npm)
Jul 24, 2026
App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from...
High
Unreviewed
CVE-2026-49147
was published
Jul 8, 2026
GitHub CLI: GitHub Actions log output in `gh run view` allows terminal escape sequence injection
Low
CVE-2026-45803
was published
for
github.com/cli/cli
(Go)
May 19, 2026
Claude HUD through 0.0.12, patched in commit 234d9aa, constructs OSC 8 terminal hyperlink escape...
Low
Unreviewed
CVE-2026-47090
was published
May 18, 2026
In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that...
Moderate
Unreviewed
CVE-2026-41526
was published
Apr 28, 2026
http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for...
Low
Unreviewed
CVE-2026-6019
was published
Apr 22, 2026
Inspektor Gadget uses unsanitized ANSI Escape Sequences In `columns` Output Mode
Moderate
CVE-2026-25996
was published
for
github.com/inspektor-gadget/inspektor-gadget
(Go)
Apr 22, 2026
MuPDF mutool does not sanitize PDF metadata fields before writing them to terminal output,...
Moderate
Unreviewed
CVE-2026-40505
was published
Apr 16, 2026
Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an...
Critical
Unreviewed
CVE-2026-26149
was published
Apr 14, 2026
OpenClaw has ACP CLI approval prompt ANSI escape sequence injection
Moderate
CVE-2026-35651
was published
for
openclaw
(npm)
Mar 29, 2026
AWS SDK for PHP has CloudFront Policy Document Injection via Special Characters
High
GHSA-27qh-8cxx-2cr5
was published
for
aws/aws-sdk-php
(Composer)
Mar 27, 2026
Mattermost allows attackers to manipulate administrator terminals via crafted messages containing ANSI and OSC escape sequences
High
CVE-2026-3108
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Mar 26, 2026
An improper neutralization of escape, meta, or control sequences vulnerability has been reported...
Moderate
Unreviewed
CVE-2025-62845
was published
Mar 20, 2026
Tanium addressed an unauthorized code execution vulnerability in Tanium Appliance.
High
Unreviewed
CVE-2025-15311
was published
Feb 5, 2026
Improper neutralization of escape, meta, or control sequences in Copilot allows an unauthorized...
High
Unreviewed
CVE-2026-21521
was published
Jan 23, 2026
Mailpit has an SMTP Header Injection via Regex Bypass
Moderate
CVE-2026-23829
was published
for
github.com/axllent/mailpit
(Go)
Jan 20, 2026
badkeys vulnerable to ASCII control character injection on console via malformed input
Low
CVE-2026-21439
was published
for
badkeys
(pip)
Jan 5, 2026
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server...
Moderate
Unreviewed
CVE-2025-65082
was published
Dec 5, 2025
Soft Serve does not sanitize ANSI escape sequences in user input
Moderate
CVE-2025-64494
was published
for
github.com/charmbracelet/soft-serve
(Go)
Nov 6, 2025
ProTip!
Advisories are also available from the
GraphQL API