GitHub
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 215 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from April 4, 2012 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Classroom 50 vulnerable to arbitrary file overwrite on the teacher's machine via symlink in a student repo (gh teacher download)
Authorization bypass vulnerability in GitHub Enterprise Server allowed reading of private pull request diffs and patches via repository name collision
Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed HTML attribute injection via the Markdown rendering pipeline
GitHub Enterprise Server notebook viewer vulnerable to Server-side request forgery
Artifact metadata injection in actions/attest
Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed remote code execution via network access from pre-receive hooks to internal services
Race condition vulnerability was identified in GitHub Enterprise Server that allowed remote code execution
Server-side request forgery vulnerability in GitHub Enterprise Server Manage API leaked a replayable gateway-agent bearer token
GitHub CLI: `gh codespace ports forward` exposes forwarded services on all network interfaces by default
GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability
Monitor GitHub in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.