Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3 advisories

Loading
Trivy Action has a script injection via sourced env file in composite action Moderate
CVE-2026-26189 was published for aquasecurity/trivy-action (GitHub Actions) Feb 18, 2026
1seal Credited to 1seal, DmitriyLewen, and simar7 DmitriyLewen DmitriyLewen
simar7 simar7
Laravel framework susceptible to reflected cross-site scripting Moderate
CVE-2024-13918 was published for laravel/framework (Composer) Mar 10, 2025
DmitriyLewen Credited to DmitriyLewen, xaldama, and kalidor xaldama xaldama
kalidor kalidor
SnakeYaml Constructor Deserialization Remote Code Execution High
CVE-2022-1471 was published for org.yaml:snakeyaml (Maven) Dec 12, 2022
justintaft Credited to justintaft, securisec, JLLeitschuh, DmitriyLewen, yairmzr, and pjfanning securisec securisec
JLLeitschuh JLLeitschuh DmitriyLewen DmitriyLewen yairmzr yairmzr pjfanning pjfanning
ProTip! Advisories are also available from the GraphQL API