GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,752
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,571
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
2,923 advisories
Filter by severity
@zereight/mcp-gitlab has multiple safety-control bypasses: execute_graphql read-only + allow-list bypass, unauthenticated transports, session-exhaustion DoS
High
GHSA-5648-rgj9-v224
was published
for
@zereight/mcp-gitlab
(npm)
Sep 15, 2026
@Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft
High
CVE-2026-59148
was published
for
@mockoon/cli
(npm)
Sep 11, 2026
FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix
High
CVE-2026-59973
was published
for
@frontmcp/adapters
(npm)
Sep 11, 2026
@jhb.software/payload-alt-text-plugin: Alt Text Endpoint Authorization Bypass via Payload Local API `overrideAccess` Omission
High
CVE-2026-59965
was published
for
@jhb.software/payload-alt-text-plugin
(npm)
Sep 10, 2026
@argos-ci/core: CI Branch Name OS Command Injection
High
CVE-2026-59960
was published
for
@argos-ci/core
(npm)
Sep 10, 2026
n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution
High
CVE-2026-86083
was published
for
n8n
(npm)
Sep 10, 2026
Angular: SSR XSS via Unescaped <template> Content Across DocumentFragment Boundaries in Fallback Raw-Content Elements
High
CVE-2026-88060
was published
for
@angular/platform-server
(npm)
Sep 10, 2026
Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSR
High
CVE-2026-88056
was published
for
@angular/platform-server
(npm)
Sep 10, 2026
n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node
High
CVE-2026-86082
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path
High
CVE-2026-86081
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint
High
CVE-2026-86075
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution
High
CVE-2026-86076
was published
for
n8n
(npm)
Sep 10, 2026
@eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name
High
GHSA-x7m8-jrm8-hpvx
was published
for
@eigenpal/docx-editor-core
(npm)
Sep 10, 2026
@openhop/server: Path Traversal in Flow ID File Operations
High
CVE-2026-59179
was published
for
@openhop/server
(npm)
Sep 9, 2026
functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import
High
CVE-2026-59176
was published
for
functype-mcp-server
(npm)
Sep 9, 2026
@yeger/turbo-graph: Unauthenticated Network-Exposed Task Execution via /api/run
High
CVE-2026-59160
was published
for
@yeger/turbo-graph
(npm)
Sep 9, 2026
Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients
High
CVE-2026-59158
was published
for
nuxt-ollama
(npm)
Sep 9, 2026
smol-toml: Denial of Service via malformed TOML documents
High
CVE-2026-85730
was published
for
smol-toml
(npm)
Sep 9, 2026
Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list
High
GHSA-2x7j-588g-ccc2
was published
for
nodemailer
(npm)
Sep 8, 2026
OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree
High
GHSA-2q42-4q24-7rgv
was published
for
@typespec/compiler
(npm)
Sep 8, 2026
multer vulnerable to Denial of Service via crafted multipart field names
High
CVE-2026-77078
was published
for
multer
(npm)
Sep 8, 2026
multer vulnerable to Denial of Service via file descriptor leak on aborted uploads
High
CVE-2026-77037
was published
for
multer
(npm)
Sep 8, 2026
multer vulnerable to Denial of Service via oversized array index in field names
High
CVE-2026-82333
was published
for
multer
(npm)
Sep 8, 2026
sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545
High
GHSA-rgj7-g3m4-5g8c
was published
for
sharp
(npm)
Sep 8, 2026
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources
High
CVE-2026-84375
was published
for
js-yaml
(npm)
Sep 8, 2026
ProTip!
Advisories are also available from the
GraphQL API