Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3 advisories

Loading
nfpm has incorrect default permissions High
CVE-2023-32698 was published for github.com/goreleaser/nfpm (Go) May 24, 2023
oCHRISo Credited to oCHRISo, caarlos0, and djgilcrease caarlos0 caarlos0
djgilcrease djgilcrease
soft-serve vulnerable to arbitrary code execution by crafting git-lfs requests High
CVE-2024-41956 was published for github.com/charmbracelet/soft-serve (Go) Aug 2, 2024
caarlos0 Credited to caarlos0, aymanbagabas, hdm, and deadpixi aymanbagabas aymanbagabas
hdm hdm deadpixi deadpixi
Soft Serve vulnerable to arbitrary file writing through SSH API High
CVE-2025-58355 was published for github.com/charmbracelet/soft-serve (Go) Sep 2, 2025
msanft Credited to msanft and caarlos0 caarlos0 caarlos0
ProTip! Advisories are also available from the GraphQL API