Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,549 advisories

Loading
Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints Moderate
CVE-2026-55156 was published for @ooples/token-optimizer-mcp (npm) Aug 14, 2026
232-323 Credited to 232-323
Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL Moderate
CVE-2026-53722 was published for nuxt (npm) Jun 16, 2026
manop55555 Credited to manop55555, sota70, and sealonohana sota70 sota70
sealonohana sealonohana
alcls01111 Credited to alcls01111, cookesan, and sealonohana cookesan cookesan
sealonohana sealonohana
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them Moderate
CVE-2026-73419 was published for @auth/core (npm) Jul 23, 2026
Nadav0077 Credited to Nadav0077
TypeORM: migration:generate template-literal code injection Moderate
CVE-2026-73651 was published for typeorm (npm) Jul 21, 2026
smith-xyz Credited to smith-xyz
Quasar: Prototype pollution in the extend() utility Moderate
CVE-2026-73647 was published for quasar (npm) Jul 24, 2026
Dremig Credited to Dremig
ERC7984ERC20Wrapper: once a wrapper is filled, subsequent wrap requests do not revert and result in loss of funds. Moderate
CVE-2026-73645 was published for @openzeppelin/confidential-contracts (npm) Jan 5, 2026
Node.js Adapter for Hono: Unauthenticated memory-leak DoS via aborted WebSocket handshake Moderate
CVE-2026-73565 was published for @hono/node-server (npm) Jul 21, 2026
TarPeg007 Credited to TarPeg007
@backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass Moderate
CVE-2026-73563 was published for @backstage/plugin-auth-backend (npm) Jul 24, 2026
katzj Credited to katzj
decompress allows arbitrary hardlink creation during archive extraction Moderate
CVE-2026-39243 was published for decompress (npm) Jul 10, 2026
Saku0512 Credited to Saku0512
Duplicate Advisory: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint Moderate
GHSA-4jjw-pwvw-q6w3 was published for nuxt (npm) Aug 11, 2026 withdrawn
antonisloukis Credited to antonisloukis
hashi-vault-js: Vault token and secret values exposed in thrown errors Moderate
CVE-2026-55102 was published for hashi-vault-js (npm) Aug 13, 2026
Sebasteuo Credited to Sebasteuo
ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header Moderate
CVE-2026-55087 was published for ep_etherpad-lite (npm) Aug 13, 2026
Trix: Stored XSS via HTMLParser attribute injection on paste Moderate
CVE-2026-73428 was published for action_text-trix (RubyGems) Jul 24, 2026
newbiefromcoma Credited to newbiefromcoma
Trix has a Stored XSS vulnerability through serialized attributes Moderate
CVE-2026-73426 was published for action_text-trix (RubyGems) Mar 12, 2026
thientd Credited to thientd
@astrojs/rss: XML Injection via Unescaped RSS Feed Fields Moderate
CVE-2026-59728 was published for @astrojs/rss (npm) Jul 20, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
jlgore Credited to jlgore
Astro: Reflected XSS via unescaped View Transition animation properties Moderate
CVE-2026-73422 was published for astro (npm) Jul 20, 2026
Ryoga-exe Credited to Ryoga-exe
@hey-api/openapi-ts's `buildClientParams` template: prototype chain substitution via unknown `$<slot>___proto__` key Moderate
CVE-2026-48819 was published for @hey-api/openapi-ts (npm) Jul 1, 2026
programsurf Credited to programsurf, daeungdaeung, yoonsh, and lubroai daeungdaeung daeungdaeung
yoonsh yoonsh lubroai lubroai
Shescape: Path disclosure on Unix with Zsh Moderate
CVE-2026-73412 was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
ProTip! Advisories are also available from the GraphQL API