GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
2,549 advisories
Filter by severity
Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints
Moderate
CVE-2026-55156
was published
for
@ooples/token-optimizer-mcp
(npm)
Aug 14, 2026
Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL
Moderate
CVE-2026-53722
was published
for
nuxt
(npm)
Jun 16, 2026
Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`
Moderate
CVE-2026-56326
was published
for
nuxt
(npm)
Jun 16, 2026
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
Moderate
CVE-2026-73419
was published
for
@auth/core
(npm)
Jul 23, 2026
TypeORM: migration:generate template-literal code injection
Moderate
CVE-2026-73651
was published
for
typeorm
(npm)
Jul 21, 2026
Quasar: Prototype pollution in the extend() utility
Moderate
CVE-2026-73647
was published
for
quasar
(npm)
Jul 24, 2026
ERC7984ERC20Wrapper: once a wrapper is filled, subsequent wrap requests do not revert and result in loss of funds.
Moderate
CVE-2026-73645
was published
for
@openzeppelin/confidential-contracts
(npm)
Jan 5, 2026
Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake
Moderate
CVE-2026-73565
was published
for
@hono/node-server
(npm)
Jul 21, 2026
@backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass
Moderate
CVE-2026-73563
was published
for
@backstage/plugin-auth-backend
(npm)
Jul 24, 2026
Mongoose: Prototype pollution in mongoose update casting via __proto__-prefixed dotted path (Schema._getSchema/path getter)
Moderate
CVE-2026-73562
was published
for
mongoose
(npm)
Jul 24, 2026
decompress allows arbitrary hardlink creation during archive extraction
Moderate
CVE-2026-39243
was published
for
decompress
(npm)
Jul 10, 2026
Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
Moderate
CVE-2026-72744
was published
for
nuxt
(npm)
Aug 7, 2026
Duplicate Advisory: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint
Moderate
GHSA-4jjw-pwvw-q6w3
was published
for
nuxt
(npm)
Aug 11, 2026
•
withdrawn
hashi-vault-js: Vault token and secret values exposed in thrown errors
Moderate
CVE-2026-55102
was published
for
hashi-vault-js
(npm)
Aug 13, 2026
ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token
Moderate
CVE-2026-55088
was published
for
ep_etherpad-lite
(npm)
Aug 13, 2026
ep_etherpad-lite: Import/export uses Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwrite
Moderate
CVE-2026-55086
was published
for
ep_etherpad-lite
(npm)
Aug 13, 2026
ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header
Moderate
CVE-2026-55087
was published
for
ep_etherpad-lite
(npm)
Aug 13, 2026
Trix: Stored XSS via HTMLParser attribute injection on paste
Moderate
CVE-2026-73428
was published
for
action_text-trix
(RubyGems)
Jul 24, 2026
Trix has a Stored XSS vulnerability through serialized attributes
Moderate
CVE-2026-73426
was published
for
action_text-trix
(RubyGems)
Mar 12, 2026
Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
Moderate
CVE-2026-59729
was published
for
astro
(npm)
Jul 20, 2026
@astrojs/rss: XML Injection via Unescaped RSS Feed Fields
Moderate
CVE-2026-59728
was published
for
@astrojs/rss
(npm)
Jul 20, 2026
Astro: composable `astro/hono` pipeline bypasses `security.checkOrigin` when `middleware()` is absent or misordered
Moderate
CVE-2026-73423
was published
for
astro
(npm)
Jul 20, 2026
Astro: Reflected XSS via unescaped View Transition animation properties
Moderate
CVE-2026-73422
was published
for
astro
(npm)
Jul 20, 2026
@hey-api/openapi-ts's `buildClientParams` template: prototype chain substitution via unknown `$<slot>___proto__` key
Moderate
CVE-2026-48819
was published
for
@hey-api/openapi-ts
(npm)
Jul 1, 2026
Shescape: Path disclosure on Unix with Zsh
Moderate
CVE-2026-73412
was published
for
shescape
(npm)
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API