Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,800 advisories

Loading
Token Optimizer MCP: OS command injection in smart_user via username in get-user-info High
CVE-2026-55157 was published for @ooples/token-optimizer-mcp (npm) Aug 14, 2026
mcfly-zzh Credited to mcfly-zzh
Immutable: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set High
CVE-2026-59880 was published for immutable (npm) Jul 21, 2026
nvth Credited to nvth and 36degrees 36degrees 36degrees
Budibase: SSRF in Automation Steps - Webhook, Zapier, N8N, Slack, Discord Bypass IP Blacklist High
CVE-2026-35219 was published for @budibase/server (npm) Aug 14, 2026
fast-uri vulnerable to host confusion via failed IDN canonicalization High
CVE-2026-13676 was published for fast-uri (npm) Jul 21, 2026
celinke97 Credited to celinke97 and UlisesGascon UlisesGascon UlisesGascon
Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS High
CVE-2026-73654 was published for @trigger.dev/core (npm) Aug 13, 2026
MatiasTilleriasLey Credited to MatiasTilleriasLey
Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers High
CVE-2026-73418 was published for @auth/core (npm) Jul 23, 2026
deprrous Credited to deprrous
Genql: inject arbitrary JavaScript or TypeScript via a GraphQL schema High
CVE-2026-63397 was published for @genql/cli (npm) Jul 16, 2026
0x00-sys Credited to 0x00-sys
SVGO removeScripts plugin leaves some executable scripts intact High
CVE-2026-73650 was published for svgo (npm) Jul 21, 2026
Admu-Dev Credited to Admu-Dev
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
js-yaml: Exponential parsing time in flow collections leads to denial of service High
CVE-2026-73643 was published for js-yaml (npm) Jul 24, 2026
lissy93 Credited to lissy93
fast-xml-parser: Repeated DOCTYPE declarations reset entity expansion limits High
CVE-2026-73569 was published for fast-xml-parser (npm) Jul 21, 2026
the-vibe-dev Credited to the-vibe-dev and amitguptagwl amitguptagwl amitguptagwl
@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion High
CVE-2026-73561 was published for @anephenix/hub (npm) Jul 24, 2026
EQSTLab Credited to EQSTLab and min8282 min8282 min8282
pnpm: Repository-controlled configDependencies can select a pacquet native install engine High
CVE-2026-55697 was published for pnpm (npm) Jun 26, 2026
massif-01 Credited to massif-01, G-Rath, and gabe-gfm G-Rath G-Rath
gabe-gfm gabe-gfm
nanoid: custom generators can loop indefinitely when size is zero High
CVE-2026-67213 was published for nanoid (npm) Jul 29, 2026
ai Credited to ai and dimaman2001 dimaman2001 dimaman2001
fast-uri vulnerable to host confusion via percent-encoded authority delimiters High
CVE-2026-6322 was published for fast-uri (npm) May 8, 2026
Jvr2022 Credited to Jvr2022, mcollina, UlisesGascon, climba03003, zakaryan2004, and jlang-ih mcollina mcollina
UlisesGascon UlisesGascon climba03003 climba03003 zakaryan2004 zakaryan2004 jlang-ih jlang-ih
Astro: Host header SSRF in prerendered error page fetch High
CVE-2026-54299 was published for astro (npm) Jun 16, 2026
5ud0er Credited to 5ud0er and cookesan cookesan cookesan
Astro: Reflected XSS via unescaped slot name High
CVE-2026-50146 was published for astro (npm) Jun 16, 2026
floudeciel Credited to floudeciel and cookesan cookesan cookesan
Shescape: Quadratic-time denial of service in the flag-protection High
CVE-2026-73413 was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
Budibase: SSRF via DNS rebinding in the REST datasource integration High
CVE-2026-73410 was published for @budibase/server (npm) Jul 24, 2026
dhairya7760 Credited to dhairya7760
extract-zip unvalidated symlink path traversal High
CVE-2026-56876 was published for extract-zip (npm) Jun 26, 2026
drengir1 Credited to drengir1
Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile High
CVE-2026-73409 was published for @budibase/server (npm) Jul 24, 2026
Hasinohacker Credited to Hasinohacker
Budibase: Unauthenticated user information disclosure via public tenant user lookup endpoint High
CVE-2026-73406 was published for @budibase/server (npm) Jul 24, 2026
sondt99 Credited to sondt99
@budibase/backend-core has potential SSRF DNS rebinding bypass in outbound fetch validation High
CVE-2026-54353 was published for @budibase/backend-core (npm) Jun 22, 2026
Artex09 Credited to Artex09
Budibase: Privilege escalation via public role assignment API missing app-level authorization High
CVE-2026-73305 was published for @budibase/server (npm) Jul 24, 2026
dinhvaren Credited to dinhvaren
themudhaxk Credited to themudhaxk and Ardeey-code Ardeey-code Ardeey-code
ProTip! Advisories are also available from the GraphQL API