Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,923 advisories

Loading
sajdakabir Credited to sajdakabir and zerotrail-ai zerotrail-ai zerotrail-ai
FrontMCP and mcp-from-openapi have bypass of OpenAPI external $ref SSRF fix High
CVE-2026-59973 was published for @frontmcp/adapters (npm) Sep 11, 2026
DavidCarliez Credited to DavidCarliez
@jhb.software/payload-alt-text-plugin: Alt Text Endpoint Authorization Bypass via Payload Local API `overrideAccess` Omission High
CVE-2026-59965 was published for @jhb.software/payload-alt-text-plugin (npm) Sep 10, 2026
EQSTLab Credited to EQSTLab and 232-323 232-323 232-323
@argos-ci/core: CI Branch Name OS Command Injection High
CVE-2026-59960 was published for @argos-ci/core (npm) Sep 10, 2026
EQSTLab Credited to EQSTLab
hiddingtrojans Credited to hiddingtrojans
Angular: SSR XSS via Unescaped <template> Content Across DocumentFragment Boundaries in Fallback Raw-Content Elements High
CVE-2026-88060 was published for @angular/platform-server (npm) Sep 10, 2026
mabjr33 Credited to mabjr33 and alan-agius4 alan-agius4 alan-agius4
Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSR High
CVE-2026-88056 was published for @angular/platform-server (npm) Sep 10, 2026
alan-agius4 Credited to alan-agius4 and Adyej999 Adyej999 Adyej999
yadhukrishnam Credited to yadhukrishnam
Masofgon Credited to Masofgon
Masofgon Credited to Masofgon
Masofgon Credited to Masofgon
@eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name High
GHSA-x7m8-jrm8-hpvx was published for @eigenpal/docx-editor-core (npm) Sep 10, 2026
samcorcos Credited to samcorcos
@openhop/server: Path Traversal in Flow ID File Operations High
CVE-2026-59179 was published for @openhop/server (npm) Sep 9, 2026
EQSTLab Credited to EQSTLab and useworld useworld useworld
functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import High
CVE-2026-59176 was published for functype-mcp-server (npm) Sep 9, 2026
EQSTLab Credited to EQSTLab
@yeger/turbo-graph: Unauthenticated Network-Exposed Task Execution via /api/run High
CVE-2026-59160 was published for @yeger/turbo-graph (npm) Sep 9, 2026
EQSTLab Credited to EQSTLab and min8282 min8282 min8282
Nuxt Ollama: Public Runtime Config Exposes Ollama API Key to Browser Clients High
CVE-2026-59158 was published for nuxt-ollama (npm) Sep 9, 2026
EQSTLab Credited to EQSTLab
smol-toml: Denial of Service via malformed TOML documents High
CVE-2026-85730 was published for smol-toml (npm) Sep 9, 2026
Ravi-lk Credited to Ravi-lk
e1abrador Credited to e1abrador
OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree High
GHSA-2q42-4q24-7rgv was published for @typespec/compiler (npm) Sep 8, 2026
NLx64 Credited to NLx64
multer vulnerable to Denial of Service via crafted multipart field names High
CVE-2026-77078 was published for multer (npm) Sep 8, 2026
O4FDev Credited to O4FDev and UlisesGascon UlisesGascon UlisesGascon
multer vulnerable to Denial of Service via file descriptor leak on aborted uploads High
CVE-2026-77037 was published for multer (npm) Sep 8, 2026
dkoazw Credited to dkoazw, EmirCobanOfficial, bjohansebas, and UlisesGascon EmirCobanOfficial EmirCobanOfficial
bjohansebas bjohansebas UlisesGascon UlisesGascon
multer vulnerable to Denial of Service via oversized array index in field names High
CVE-2026-82333 was published for multer (npm) Sep 8, 2026
O4FDev Credited to O4FDev, UlisesGascon, and arpitjain099 UlisesGascon UlisesGascon
arpitjain099 arpitjain099
sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545 High
GHSA-rgj7-g3m4-5g8c was published for sharp (npm) Sep 8, 2026
js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources High
CVE-2026-84375 was published for js-yaml (npm) Sep 8, 2026
ProTip! Advisories are also available from the GraphQL API