GitHub
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 206 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from April 4, 2012 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →GitHub Copilot and Visual Studio Code Elevation of Privilege Vulnerability
GitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacters in SAN Matching
GitHub CLI: Terminal escape sequence injection in multiple `gh` commands
GitHub CLI: Unescaped variable components in request URLs could allow path traversal
GitHub CLI: Partial token disclosure in `gh auth status` output
Denial of service vulnerability in GitHub Enterprise Server allowed unauthenticated service disruption via deeply nested request parameters
Path traversal in GitHub Enterprise Server allowed unauthenticated deletion of instance storage via the X-GitHub-Request-Id header
GitHub MCP Server: Nil Pointer Dereference DoS in completion/complete Handler
Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed reading private repository metadata via delegated bypass rule suites
Path traversal vulnerability in GitHub Enterprise Server allowed writing files to arbitrary repository paths, including GitHub Actions workflow files, via unchecked Dependabot dependency-file paths
Monitor GitHub in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.