GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,751
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,570
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
7,404 advisories
Filter by severity
yayson: Prototype pollution in Store/LegacyStore deserialization
Critical
CVE-2026-61534
was published
for
yayson
(npm)
Sep 11, 2026
@Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft
High
CVE-2026-59148
was published
for
@mockoon/cli
(npm)
Sep 11, 2026
@Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)
Moderate
CVE-2026-59149
was published
for
@mockoon/cli
(npm)
Sep 11, 2026
FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix
High
CVE-2026-59973
was published
for
@frontmcp/adapters
(npm)
Sep 11, 2026
@jhb.software/payload-alt-text-plugin: Alt Text Endpoint Authorization Bypass via Payload Local API `overrideAccess` Omission
High
CVE-2026-59965
was published
for
@jhb.software/payload-alt-text-plugin
(npm)
Sep 10, 2026
@argos-ci/core: CI Branch Name OS Command Injection
High
CVE-2026-59960
was published
for
@argos-ci/core
(npm)
Sep 10, 2026
OmniRoute ACP Custom-Agent Remote Code Execution (RCE)
Critical
CVE-2026-88062
was published
for
omniroute
(npm)
Sep 10, 2026
n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution
Moderate
CVE-2026-86073
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content
Moderate
CVE-2026-86074
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
Moderate
CVE-2026-86995
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints
Moderate
CVE-2026-86085
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
Moderate
CVE-2026-86993
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions
Moderate
CVE-2026-86084
was published
for
n8n
(npm)
Sep 10, 2026
n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
Moderate
CVE-2026-86080
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers
Moderate
CVE-2026-86079
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service
Moderate
CVE-2026-86078
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter
Moderate
CVE-2026-86994
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution
High
CVE-2026-86083
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket
Moderate
CVE-2026-86077
was published
for
n8n
(npm)
Sep 10, 2026
Angular: SSR XSS via Unescaped <template> Content Across DocumentFragment Boundaries in Fallback Raw-Content Elements
High
CVE-2026-88060
was published
for
@angular/platform-server
(npm)
Sep 10, 2026
Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSR
High
CVE-2026-88056
was published
for
@angular/platform-server
(npm)
Sep 10, 2026
Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent`
Moderate
CVE-2026-88059
was published
for
@angular/common
(npm)
Sep 10, 2026
Angular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compiler
Moderate
CVE-2026-88057
was published
for
@angular/compiler
(npm)
Sep 10, 2026
n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node
High
CVE-2026-86082
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path
High
CVE-2026-86081
was published
for
n8n
(npm)
Sep 10, 2026
ProTip!
Advisories are also available from the
GraphQL API