GitHub Security Advisories
GitHub Security Advisories (GHSA) is the curated vulnerability database behind Dependabot, covering open-source package ecosystems such as npm, PyPI, Maven, RubyGems, Go and crates.io. It is usually the fastest authoritative signal for supply-chain vulnerabilities in open-source dependencies.
CSIRTS.com ingests GitHub Security Advisories every 3 hours, normalizes each advisory into a common schema and cross-references every CVE against the CISA KEV catalog and public exploit datasets. Publishes reviewed advisories for open-source package ecosystems. Also available via RSS, JSON API and the MCP server.
Latest from GitHub Security Advisories
GHSA-cv84-9p8j-fj68: icalendar has Algorithmic Complexity in Equality
GHSA-hvfh-5mj3-5f3j: Chainlist has SSRF via MCP SSE and streamable-http transports that allows unauthenticated internal network access
GHSA-w3fx-mc44-mf6j: Chainlit has command injection via MCP stdio transport that allows unauthenticated remote code execution
GHSA-72f3-6w86-7rv3: @arikusi/deepseek-mcp-server: Missing Authentication on Self-Hosted HTTP MCP Endpoint
GHSA-fh3r-g96v-f578: @arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key
GHSA-xc9g-j69q-37xw: consciousness-explorer / sublinear-time-solver MCP export_state has an arbitrary file write
GHSA-3vfr-4gwf-qxfp: Whistle vulnerable to path traversal
GHSA-g7gc-gmgp-wgqg: eml_parser vulnerable to DoS via deeply nested parens in Received headers
GHSA-m66c-fw79-6359: eml_parser has parser DoS via deeply nested parentheses in e-mail headers
GHSA-fxgq-9m89-cxj9: eml_parser has a URL extraction bypass via HTML entities in URLs
GHSA-777c-2fxx-qr28: AshAuthentication vulnerable to OAuth2/OIDC account takeover via email-based user matching
GHSA-p7x2-g5cq-fhmq: mediasoup: SCTP state cookie lacks cryptographic authentication, enabling unauthorized association establishment (RFC 9260 violation)
GHSA-6ccx-9c9f-327w: gRPC Erlang package has unbounded gzip decompression (decompression bomb)
GHSA-q8gf-9rvj-gmgj: gRPC Erlang package has unbounded request body accumulation in `read_full_body/3`
GHSA-mwr4-5g34-j5cq: gRPC Erlang package's path bindings are overridable by query string and request body
GHSA-grp7-v8xh-rj7h: gRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads
GHSA-cmwv-wf9p-p8wx: genieacs-mcp: DNS rebinding reaches local GenieACS MCP Streamable HTTP transport
GHSA-vwf3-4xxj-qg6h: mcp-contextforge-gateway has Server-Side Template Injection (SSTI) leading to Remote Code Execution in `PromptService._render_template` via unsandboxed Jinja2 Environment
GHSA-m2pc-3q4q-w6jr: reachy_mini Allows Unrestricted Upload of File with Dangerous Type
GHSA-mcj4-mphf-j9ff: Trivy has a path traversal via a crafted vulnerability database or other downloaded artifacts
GHSA-pg62-f8g4-4wqh: phpMyFAQ privilege escalation: GroupController::updatePermissions lets a GROUP_EDIT admin grant rights they do not hold
GHSA-mf8r-wm2w-f8c5: phpMyFAQ public FAQ APIs expose inactive FAQ content
GHSA-88g4-74f3-63x9: phpMyFAQ has Potential Authenticated Path Traversal in PDF Export
GHSA-qj6x-xx2h-8hvv: Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript
Browse all 2,437 advisories from GitHub Security Advisories →
Never miss a GitHub Security Advisories advisory. The daily briefing covers every new advisory from this source — alongside the other feeds we watch for you. Subscribe free — one email every morning after 06:00 UTC, one-click unsubscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.