Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,484 advisories

Loading
MCP Atlassian: Arbitrary file read/exfiltration via upload_attachment missing validate_safe_path() High
CVE-2026-77258 was published for mcp-atlassian (pip) Sep 22, 2026
junbyjun1238 Credited to junbyjun1238
MCP Atlassian: SSRF Protection Bypass High
CVE-2026-77274 was published for mcp-atlassian (pip) Sep 22, 2026
RacerZ-fighting Credited to RacerZ-fighting
b-hermes Credited to b-hermes
mcp-atlassian has an incomplete SSRF remediation High
CVE-2026-77267 was published for mcp-atlassian (pip) Sep 22, 2026
romain-deperne Credited to romain-deperne
rushitgit Credited to rushitgit
MCP Atlassian: SSRF redirect protection missing for basic-auth and OAuth authentication branches High
CVE-2026-77261 was published for mcp-atlassian (pip) Sep 22, 2026
hewei-gikaku Credited to hewei-gikaku
MCP Atlassian: HTTP upload tools accept arbitrary server-local file paths High
CVE-2026-77257 was published for mcp-atlassian (pip) Sep 22, 2026
MCP Atlassian: ENABLED_TOOLS / Toolset authorization bypass High
CVE-2026-77243 was published for mcp-atlassian (pip) Sep 22, 2026
0xmagic0 Credited to 0xmagic0
MCP Atlassian: Arbitrary File Read & Exfiltration (Confused Deputy) in JIRA update_issue High
CVE-2026-77255 was published for mcp-atlassian (pip) Sep 22, 2026
aurelienp-alt Credited to aurelienp-alt
MCP Atlassian: Jira and Confluence attachment upload tools can read arbitrary server-local files High
CVE-2026-77253 was published for mcp-atlassian (pip) Sep 22, 2026
sondt99 Credited to sondt99
MCP Atlassian: MCP HTTP Client Server-Local File Exfiltration via Unvalidated Attachment Upload Path High
CVE-2026-77246 was published for mcp-atlassian (pip) Sep 22, 2026
EQSTLab Credited to EQSTLab and 232-323 232-323 232-323
MPXJ: XXE Vulnerability in MerlinReader High
CVE-2026-61570 was published for MPXJ.Net (RubyGems) Sep 22, 2026
dyingman1 Credited to dyingman1
psd-tools composite/numpy has uncontrolled memory allocation via crafted PSD geometry High
CVE-2026-59991 was published for psd-tools (pip) Sep 22, 2026
joszamama Credited to joszamama
Faze-up Credited to Faze-up
LMDeploy has an SSRF bypass High
GHSA-39wr-7q6h-cf68 was published for lmdeploy (pip) Sep 18, 2026
Fushuling Credited to Fushuling, RacerZ-fighting, and clzoom RacerZ-fighting RacerZ-fighting
clzoom clzoom
romain-deperne Credited to romain-deperne
djust: A template binding inherits a context safety grant it never earned (XSS) High
GHSA-xjw9-38cr-6372 was published for djust (pip) Sep 17, 2026
djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS) High
GHSA-9395-2g46-rj3f was published for djust (pip) Sep 17, 2026
Jupyter Server: 5xx request logging leaks token-bearing Referer header values High
CVE-2026-86049 was published for jupyter_server (pip) Sep 17, 2026
DavidCarliez Credited to DavidCarliez, Yann-P, and krassowski Yann-P Yann-P
krassowski krassowski
ProTip! Advisories are also available from the GraphQL API