Our Mission
Enhance security by fostering global collaboration.
Contributions from maintainers, developers, and security researchers
around the world push us forward, making the open source software a
better place.
Security Research
We do the hard work, you can use it.
Dive into security research on open-source projects to explore new and
emerging threats, and learn how to mitigate them so that you can make
your own software more secure.
Read the Research
Latest vulnerabilities disclosed
-
Code injection in vets-apiGHSL-2025-105 • published 25 days ago • Peter Stöckli
-
Code injection in acl-anthologyGHSL-2025-102_GHSL-2025-103 • published 25 days ago • Peter Stöckli
-
Code Injection in esphome/esphome-docs Github Actions WorkflowGHSL-2025-106 • published 1 months ago • Man Yue Mo
-
Cross-site scripting (XSS) in OpenLibrary barcode scannerGHSL-2025-110 • published 1 months ago • Peter Stöckli
-
Cross-site scripting (XSS) in bit platform Boilerplate WebInteropApp - CVE-2025-64710
25,000+
security advisories
curated by Security Lab researchers
9,500+ CVEs
assigned for OS maintainers
GitHub Advisory Database
While CVEs identify vulnerabilities, they don’t tell the whole
story. Entries in the GitHub Advisory database expand beyond
identification to include additional context and details to
support automated security tooling – sourced from a global
community of security experts and curated by the Security Lab – to
help you understand vulnerabilities, assess risk, and fix with
confidence and efficiency.
Resources
Open doors, open solutions:
Embracing Enterprise & Open Source
Open Source Community
Learn about secure coding practices, get hands-on with AppSec
training, and connect with experts during our office hours – free
for open source developers, maintainers, and security researchers.
GitHub Security Lab for the Enterprise
At the GitHub Security Lab, our security experts, through community
collaboration, strengthen open source security which is crucial for
enterprises. We channel the community’s contributions into proven
CodeQL queries and timely security advisories, and offer enterprises
actionable insights that help secure your supply chain and accelerate
the software development lifecycle.
Team
About the GitHub Security Lab.
At the GitHub Security Lab, we cultivate a collaborative community
of developers and security experts who work together to bolster the
security of open source software.
Meet the team
Learn more on GitHub Security Lab
Through research, education, and maintenance of the GitHub Advisory
Database, we empower the community.
We’re active on social media!
Through research, education, and maintenance of the GitHub Advisory
Database, we empower the community.
To keep this community open and welcoming, please read our
Code of Conduct.
