Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7,407 advisories

Loading
@zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery Critical
CVE-2026-61559 was published for @zereight/mcp-gitlab (npm) Sep 15, 2026
avishaigonen-pluto Credited to avishaigonen-pluto and yotampe-pluto yotampe-pluto yotampe-pluto
@zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport Critical
CVE-2026-61568 was published for @zereight/mcp-gitlab (npm) Sep 15, 2026
avishaigonen-pluto Credited to avishaigonen-pluto and yotampe-pluto yotampe-pluto yotampe-pluto
Flowise OverrideConfig security vulnerability High
CVE-2024-58351 was published for flowise (npm) Nov 21, 2024
ryanhalliday Credited to ryanhalliday
Duplicate Advisory: Flowise OverrideConfig security vulnerability Critical
GHSA-5w6g-rc45-wvv9 was published for flowise (npm) Jun 20, 2026 withdrawn
ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS High
CVE-2026-71553 was published for apostrophe (npm) Sep 2, 2026
breakingsystems Credited to breakingsystems
yayson: Prototype pollution in Store/LegacyStore deserialization Critical
CVE-2026-61534 was published for yayson (npm) Sep 11, 2026
hackchang Credited to hackchang and jede jede jede
sajdakabir Credited to sajdakabir and zerotrail-ai zerotrail-ai zerotrail-ai
miauzxw Credited to miauzxw and geo-chen geo-chen geo-chen
FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix High
CVE-2026-59973 was published for @frontmcp/adapters (npm) Sep 11, 2026
DavidCarliez Credited to DavidCarliez
fast-uri vulnerable to host confusion via failed IDN canonicalization High
CVE-2026-13676 was published for fast-uri (npm) Jul 21, 2026
celinke97 Credited to celinke97 and UlisesGascon UlisesGascon UlisesGascon
@jhb.software/payload-alt-text-plugin: Alt Text Endpoint Authorization Bypass via Payload Local API `overrideAccess` Omission High
CVE-2026-59965 was published for @jhb.software/payload-alt-text-plugin (npm) Sep 10, 2026
EQSTLab Credited to EQSTLab and 232-323 232-323 232-323
@argos-ci/core: CI Branch Name OS Command Injection High
CVE-2026-59960 was published for @argos-ci/core (npm) Sep 10, 2026
EQSTLab Credited to EQSTLab
OmniRoute ACP Custom-Agent Remote Code Execution (RCE) Critical
CVE-2026-88062 was published for omniroute (npm) Sep 10, 2026
c111mb3r Credited to c111mb3r
n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution Moderate
CVE-2026-86073 was published for n8n (npm) Sep 10, 2026
bariskececi Credited to bariskececi
n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content Moderate
CVE-2026-86074 was published for n8n (npm) Sep 10, 2026
nlgbao1340 Credited to nlgbao1340
Masofgon Credited to Masofgon
mtholmquist Credited to mtholmquist
n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check Moderate
CVE-2026-86993 was published for n8n (npm) Sep 10, 2026
nlgbao1340 Credited to nlgbao1340
n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions Moderate
CVE-2026-86084 was published for n8n (npm) Sep 10, 2026
vonypeto Credited to vonypeto
n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers Moderate
CVE-2026-86079 was published for n8n (npm) Sep 10, 2026
vonypeto Credited to vonypeto
n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service Moderate
CVE-2026-86078 was published for n8n (npm) Sep 10, 2026
Masofgon Credited to Masofgon
n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter Moderate
CVE-2026-86994 was published for n8n (npm) Sep 10, 2026
tr4ce-ju Credited to tr4ce-ju
hiddingtrojans Credited to hiddingtrojans
ProTip! Advisories are also available from the GraphQL API