Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7,404 advisories

Loading
yayson: Prototype pollution in Store/LegacyStore deserialization Critical
CVE-2026-61534 was published for yayson (npm) Sep 11, 2026
hackchang Credited to hackchang and jede jede jede
sajdakabir Credited to sajdakabir and zerotrail-ai zerotrail-ai zerotrail-ai
miauzxw Credited to miauzxw and geo-chen geo-chen geo-chen
FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix High
CVE-2026-59973 was published for @frontmcp/adapters (npm) Sep 11, 2026
DavidCarliez Credited to DavidCarliez
@jhb.software/payload-alt-text-plugin: Alt Text Endpoint Authorization Bypass via Payload Local API `overrideAccess` Omission High
CVE-2026-59965 was published for @jhb.software/payload-alt-text-plugin (npm) Sep 10, 2026
EQSTLab Credited to EQSTLab and 232-323 232-323 232-323
@argos-ci/core: CI Branch Name OS Command Injection High
CVE-2026-59960 was published for @argos-ci/core (npm) Sep 10, 2026
EQSTLab Credited to EQSTLab
OmniRoute ACP Custom-Agent Remote Code Execution (RCE) Critical
CVE-2026-88062 was published for omniroute (npm) Sep 10, 2026
c111mb3r Credited to c111mb3r
n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution Moderate
CVE-2026-86073 was published for n8n (npm) Sep 10, 2026
bariskececi Credited to bariskececi
n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content Moderate
CVE-2026-86074 was published for n8n (npm) Sep 10, 2026
nlgbao1340 Credited to nlgbao1340
Masofgon Credited to Masofgon
mtholmquist Credited to mtholmquist
n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check Moderate
CVE-2026-86993 was published for n8n (npm) Sep 10, 2026
nlgbao1340 Credited to nlgbao1340
n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions Moderate
CVE-2026-86084 was published for n8n (npm) Sep 10, 2026
vonypeto Credited to vonypeto
n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers Moderate
CVE-2026-86079 was published for n8n (npm) Sep 10, 2026
vonypeto Credited to vonypeto
n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service Moderate
CVE-2026-86078 was published for n8n (npm) Sep 10, 2026
Masofgon Credited to Masofgon
n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter Moderate
CVE-2026-86994 was published for n8n (npm) Sep 10, 2026
tr4ce-ju Credited to tr4ce-ju
hiddingtrojans Credited to hiddingtrojans
n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket Moderate
CVE-2026-86077 was published for n8n (npm) Sep 10, 2026
tr4ce-ju Credited to tr4ce-ju
Angular: SSR XSS via Unescaped <template> Content Across DocumentFragment Boundaries in Fallback Raw-Content Elements High
CVE-2026-88060 was published for @angular/platform-server (npm) Sep 10, 2026
mabjr33 Credited to mabjr33 and alan-agius4 alan-agius4 alan-agius4
Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSR High
CVE-2026-88056 was published for @angular/platform-server (npm) Sep 10, 2026
alan-agius4 Credited to alan-agius4 and Adyej999 Adyej999 Adyej999
Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent` Moderate
CVE-2026-88059 was published for @angular/common (npm) Sep 10, 2026
JeanMeche Credited to JeanMeche, alan-agius4, and SkyZeroZx alan-agius4 alan-agius4
SkyZeroZx SkyZeroZx
SkyZeroZx Credited to SkyZeroZx, josephperrott, alan-agius4, and JeanMeche josephperrott josephperrott
alan-agius4 alan-agius4 JeanMeche JeanMeche
yadhukrishnam Credited to yadhukrishnam
Masofgon Credited to Masofgon
ProTip! Advisories are also available from the GraphQL API