Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7,405 advisories

Loading
Masofgon Credited to Masofgon
Masofgon Credited to Masofgon
Masofgon Credited to Masofgon
@eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name High
GHSA-x7m8-jrm8-hpvx was published for @eigenpal/docx-editor-core (npm) Sep 10, 2026
samcorcos Credited to samcorcos
@openhop/server: Path Traversal in Flow ID File Operations High
CVE-2026-59179 was published for @openhop/server (npm) Sep 9, 2026
EQSTLab Credited to EQSTLab and useworld useworld useworld
functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import High
CVE-2026-59176 was published for functype-mcp-server (npm) Sep 9, 2026
EQSTLab Credited to EQSTLab
@yeger/turbo-graph: Unauthenticated Network-Exposed Task Execution via /api/run High
CVE-2026-59160 was published for @yeger/turbo-graph (npm) Sep 9, 2026
EQSTLab Credited to EQSTLab and min8282 min8282 min8282
Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients High
CVE-2026-59158 was published for nuxt-ollama (npm) Sep 9, 2026
EQSTLab Credited to EQSTLab
smol-toml: Denial of Service via malformed TOML documents High
CVE-2026-85730 was published for smol-toml (npm) Sep 9, 2026
Ravi-lk Credited to Ravi-lk
n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy Moderate
CVE-2026-86996 was published for n8n (npm) Sep 8, 2026
vonypeto Credited to vonypeto
Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain Moderate
GHSA-wmmp-3585-3rmp was published for nodemailer (npm) Sep 8, 2026
e1abrador Credited to e1abrador
e1abrador Credited to e1abrador
e1abrador Credited to e1abrador
OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree High
GHSA-2q42-4q24-7rgv was published for @typespec/compiler (npm) Sep 8, 2026
NLx64 Credited to NLx64
multer vulnerable to Denial of Service via crafted multipart field names High
CVE-2026-77078 was published for multer (npm) Sep 8, 2026
O4FDev Credited to O4FDev and UlisesGascon UlisesGascon UlisesGascon
multer vulnerable to Denial of Service via file descriptor leak on aborted uploads High
CVE-2026-77037 was published for multer (npm) Sep 8, 2026
dkoazw Credited to dkoazw, EmirCobanOfficial, bjohansebas, and UlisesGascon EmirCobanOfficial EmirCobanOfficial
bjohansebas bjohansebas UlisesGascon UlisesGascon
multer vulnerable to file size limit bypass via async fileFilter race condition Low
CVE-2026-77063 was published for multer (npm) Sep 8, 2026
ThinkerHao Credited to ThinkerHao, bjohansebas, and UlisesGascon bjohansebas bjohansebas
UlisesGascon UlisesGascon
multer vulnerable to Denial of Service via oversized array index in field names High
CVE-2026-82333 was published for multer (npm) Sep 8, 2026
O4FDev Credited to O4FDev, UlisesGascon, and arpitjain099 UlisesGascon UlisesGascon
arpitjain099 arpitjain099
morgan vulnerable to Log Forging via unescaped Unicode line separators Moderate
CVE-2026-15603 was published for morgan (npm) Sep 8, 2026
mfazrinizar Credited to mfazrinizar, UlisesGascon, jonchurch, bjohansebas, and iaohkut-from-NightWolf-Team UlisesGascon UlisesGascon
jonchurch jonchurch bjohansebas bjohansebas iaohkut-from-NightWolf-Team iaohkut-from-NightWolf-Team
Astro: Remote code execution through AVIF image optimization Critical
GHSA-26w7-cxv4-gfx2 was published for astro (npm) Sep 8, 2026
cn-panda Credited to cn-panda
Ryoga-exe Credited to Ryoga-exe
sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545 High
GHSA-rgj7-g3m4-5g8c was published for sharp (npm) Sep 8, 2026
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources High
CVE-2026-84375 was published for js-yaml (npm) Sep 8, 2026
Tiptap: Quadratic ReDoS in block and inline Markdown attribute parsing High
GHSA-j95f-988m-3j2f was published for @tiptap/core (npm) Sep 8, 2026
joostgrunwald Credited to joostgrunwald
pacocartones Credited to pacocartones and LeonMAG LeonMAG LeonMAG
ProTip! Advisories are also available from the GraphQL API