GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,752
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,571
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
7,407 advisories
Filter by severity
@zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery
Critical
CVE-2026-61559
was published
for
@zereight/mcp-gitlab
(npm)
Sep 15, 2026
@zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport
Critical
CVE-2026-61568
was published
for
@zereight/mcp-gitlab
(npm)
Sep 15, 2026
@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS
High
GHSA-5648-rgj9-v224
was published
for
@zereight/mcp-gitlab
(npm)
Sep 15, 2026
Flowise OverrideConfig security vulnerability
High
CVE-2024-58351
was published
for
flowise
(npm)
Nov 21, 2024
Duplicate Advisory: Flowise OverrideConfig security vulnerability
Critical
GHSA-5w6g-rc45-wvv9
was published
for
flowise
(npm)
Jun 20, 2026
•
withdrawn
ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS
High
CVE-2026-71553
was published
for
apostrophe
(npm)
Sep 2, 2026
yayson: Prototype pollution in Store/LegacyStore deserialization
Critical
CVE-2026-61534
was published
for
yayson
(npm)
Sep 11, 2026
@Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft
High
CVE-2026-59148
was published
for
@mockoon/cli
(npm)
Sep 11, 2026
@Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)
Moderate
CVE-2026-59149
was published
for
@mockoon/cli
(npm)
Sep 11, 2026
FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix
High
CVE-2026-59973
was published
for
@frontmcp/adapters
(npm)
Sep 11, 2026
fast-uri vulnerable to host confusion via failed IDN canonicalization
High
CVE-2026-13676
was published
for
fast-uri
(npm)
Jul 21, 2026
@jhb.software/payload-alt-text-plugin: Alt Text Endpoint Authorization Bypass via Payload Local API `overrideAccess` Omission
High
CVE-2026-59965
was published
for
@jhb.software/payload-alt-text-plugin
(npm)
Sep 10, 2026
@argos-ci/core: CI Branch Name OS Command Injection
High
CVE-2026-59960
was published
for
@argos-ci/core
(npm)
Sep 10, 2026
OmniRoute ACP Custom-Agent Remote Code Execution (RCE)
Critical
CVE-2026-88062
was published
for
omniroute
(npm)
Sep 10, 2026
n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution
Moderate
CVE-2026-86073
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content
Moderate
CVE-2026-86074
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
Moderate
CVE-2026-86995
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints
Moderate
CVE-2026-86085
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
Moderate
CVE-2026-86993
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions
Moderate
CVE-2026-86084
was published
for
n8n
(npm)
Sep 10, 2026
n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
Moderate
CVE-2026-86080
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers
Moderate
CVE-2026-86079
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service
Moderate
CVE-2026-86078
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter
Moderate
CVE-2026-86994
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution
High
CVE-2026-86083
was published
for
n8n
(npm)
Sep 10, 2026
ProTip!
Advisories are also available from the
GraphQL API