GitHub Security Advisories
GitHub Security Advisories (GHSA) is the curated vulnerability database behind Dependabot, covering open-source package ecosystems such as npm, PyPI, Maven, RubyGems, Go and crates.io. It is usually the fastest authoritative signal for supply-chain vulnerabilities in open-source dependencies.
CSIRTS.com ingests GitHub Security Advisories every 3 hours, normalizes each advisory into a common schema and cross-references every CVE against the CISA KEV catalog and public exploit datasets. Publishes reviewed advisories for open-source package ecosystems. Also available via RSS, JSON API and the MCP server.
Latest from GitHub Security Advisories
GHSA-rh53-xvx2-j327: OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret disclosure and arbitrary Kubernetes mutation
GHSA-pr7f-p5mw-fc87: vLLM: Incomplete CVE-2025-62164 remediation can be bypassed by concurrent prompt parts
GHSA-48jh-3gj7-fg8v: vLLM: ReDoS via structured_outputs.regex in the lm-format-enforcer backend (no compile timeout) — missed sibling of GHSA-rwxx-mrjm-wc2m
GHSA-hwrm-c4cx-rf4j: vLLM: Unauthenticated Internal Path and Username Disclosure via Validation Error Messages
GHSA-8737-qx52-hjff: vLLM: Derender endpoints decode caller-supplied GenerateResponse token IDs without output bounds
GHSA-mp7r-57w4-5qm3: SiYuan: Tag labels from password-protected documents are returned to readers who have not entered the password
GHSA-h4v5-crx2-3cv4: SiYuan: Non-administrator responses from /api/system/getConf omit three secrets that the configuration-export path explicitly strips, disclosing the session-cookie signing key and the OS username to anonymous readers
GHSA-h6w7-xxcf-w2mq: SiYuan: Embedded (transclusion) block content is returned without publish-access filtering, leaking private and password-protected document content to anonymous readers
GHSA-34fj-mwm6-fjfg: SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf
GHSA-fgmr-7w36-9qfq: SiYuan: Static-file routes bypass the publish-access controls enforced on the REST API, exposing templates, snippets and export artifacts to anonymous readers
GHSA-f2rw-w22v-54vh: SiYuan: getEncryptedNotebookStatus discloses names and current lock/unlock state of all encrypted notebooks to anonymous readers
GHSA-mfrj-v65r-979c: SiYuan: Publish-access filter on renderAttributeView leaves related-database content unfiltered and fails open on non-block first columns
GHSA-5w7r-f4cg-rqq7: SiYuan: Missing publish-access filter on the HPath/path-resolution endpoints discloses the private document tree to anonymous readers
GHSA-66r2-5gwj-gxm2: SurrealDB: Writes in a PERMISSIONS clause bypass table permissions
GHSA-848m-r628-vrxw: SurrealDB: Custom API route lets authenticated callers override namespace/database scope via URL path
GHSA-gx45-xrj5-g6c4: CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
GHSA-wrj3-vj8c-784f: CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
GHSA-c6mw-8xh8-gpq6: CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
GHSA-6v2g-fpxh-pmmh: CodeWhale: SSRF bypass - TOCTOU on DNS failure for DNS pinning
GHSA-h539-c7r8-3xq4: CodeWhale: js_execution leaks parent environment to model context via missing env scrub
GHSA-7j5w-7r7x-9v27: CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval
GHSA-g29h-pfmp-qp9r: CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)
GHSA-62f5-cp2p-vq95: CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
GHSA-w7wx-5q49-r59w: CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes
Browse all 2,988 advisories from GitHub Security Advisories →
Never miss a GitHub Security Advisories advisory. The daily briefing covers every new advisory from this source — alongside the other feeds we watch for you. Subscribe free — one email every morning after 06:00 UTC, one-click unsubscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.