Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

36 advisories

Loading
berkdedekarginoglu Credited to berkdedekarginoglu
Aviral2642 Credited to Aviral2642
Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration High
CVE-2026-69250 was published for flowise (npm) Aug 4, 2026
b-hermes Credited to b-hermes
themudhaxk Credited to themudhaxk and Ardeey-code Ardeey-code Ardeey-code
@better-auth/stripe: cross-organization billing tampering in organization subscription actions High
GHSA-h3rm-78g3-j7cp was published for @better-auth/stripe (npm) Jul 24, 2026
n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner High
CVE-2026-65016 was published for n8n (npm) Jul 22, 2026
ttzero25 Credited to ttzero25
Duplicate Advisory: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner High
GHSA-mwq7-vcmc-cm4q was published for n8n (npm) Jul 22, 2026 withdrawn
Directus: Authorization-dependent response served from unsegmented cache key High
CVE-2026-61836 was published for directus (npm) Jul 20, 2026
tr4ce-ju Credited to tr4ce-ju
@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers High
GHSA-j8v8-g9cx-5qf4 was published for @better-auth/scim (npm) Jul 7, 2026
Jvr2022 Credited to Jvr2022
AgenticMail: Cross-agent task authorization bypass in AgenticMail API High
CVE-2026-57494 was published for @agenticmail/api (npm) Jun 18, 2026
YHalo-wyh Credited to YHalo-wyh
whrit Credited to whrit
n8n Has a Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints High
CVE-2026-45732 was published for n8n (npm) May 14, 2026
nkoorty Credited to nkoorty and jjjutla jjjutla jjjutla
berkdedekarginoglu Credited to berkdedekarginoglu
berkdedekarginoglu Credited to berkdedekarginoglu
berkdedekarginoglu Credited to berkdedekarginoglu
berkdedekarginoglu Credited to berkdedekarginoglu
DeathsPirate Credited to DeathsPirate
berkdedekarginoglu Credited to berkdedekarginoglu
berkdedekarginoglu Credited to berkdedekarginoglu
Directus: Path Traversal and Broken Access Control in File Management API High
CVE-2026-39942 was published for directus (npm) Apr 4, 2026
r3dpower Credited to r3dpower, pmins99, and odgrso pmins99 pmins99
odgrso odgrso
OpenClaw: `session_status` sessionId resolution bypasses sandboxed session-tree visibility High
GHSA-q2qc-744p-66r2 was published for openclaw (npm) Mar 29, 2026
nexrin Credited to nexrin, KeenSecurityLab, and qclawer KeenSecurityLab KeenSecurityLab
qclawer qclawer
tr4ce-ju Credited to tr4ce-ju
StudioCMS: IDOR — Arbitrary API Token Revocation Leading to Denial of Service High
CVE-2026-30945 was published for studiocms (npm) Mar 11, 2026
FilipeGaudard Credited to FilipeGaudard and Adammatthiesen Adammatthiesen Adammatthiesen
StudioCMS has Privilege Escalation via Insecure API Token Generation High
CVE-2026-30944 was published for studiocms (npm) Mar 10, 2026
FilipeGaudard Credited to FilipeGaudard and Adammatthiesen Adammatthiesen Adammatthiesen
ProTip! Advisories are also available from the GraphQL API