Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,351 advisories

Loading
Budibase: SQL Injection via `multipleStatements: true` Critical
CVE-2026-73300 was published for @budibase/server (npm) Jul 24, 2026
kaimandalic Credited to kaimandalic
Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer Critical
GHSA-w28w-gp39-m4p6 was published for @prompty/core (npm) Jul 24, 2026
lexdotdev Credited to lexdotdev
cruzryan Credited to cruzryan and cuauht cuauht cuauht
mufeedvh Credited to mufeedvh
@better-auth/scim: account takeover and stale access via SCIM provider-id collision Critical
GHSA-rjg6-39jm-rgg4 was published for @better-auth/scim (npm) Jul 24, 2026
marc-zollingkoffer-syzygy Credited to marc-zollingkoffer-syzygy
kakashi-kx Credited to kakashi-kx
@vitest/browser: Browser Mode provider commands bypass the file-access permission gate Critical
CVE-2026-73653 was published for @vitest/browser (npm) Jul 21, 2026
manus-use Credited to manus-use
Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry Critical
CVE-2026-59891 was published for @sigstore/oci (npm) Jul 21, 2026
gyubin02 Credited to gyubin02
node-tar: Decompression/parse DoS via unlimited input Critical
CVE-2026-59873 was published for tar (npm) Jul 20, 2026
Jvr2022 Credited to Jvr2022
websocket-driver: Message corruption via abuse of protocol length headers Critical
CVE-2026-54466 was published for websocket-driver (npm) Jul 15, 2026
pranjalithakur Credited to pranjalithakur
nuiifornet Credited to nuiifornet
n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments Critical
CVE-2026-54052 was published for n8n-mcp (npm) Jul 14, 2026
axsharma Credited to axsharma and 0xmagic0 0xmagic0 0xmagic0
@better-auth/sso provider registration has server-side request forgery via unvalidated OIDC endpoints Critical
CVE-2026-53513 was published for @better-auth/sso (npm) Jul 7, 2026
vaadata-poyetont Credited to vaadata-poyetont
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins Critical
CVE-2026-53512 was published for better-auth (npm) Jul 7, 2026
subhanUmer Credited to subhanUmer
9router has unauthenticated CRUD on /api/providers and Full API Key Leak via /api/usage/stats Critical
GHSA-vjc7-jrh9-9j86 was published for 9router (npm) Jul 6, 2026
newnol Credited to newnol
Decompress: Archive extraction can create files and links outside of the target directory Critical
CVE-2026-53486 was published for @xhmikosr/decompress (npm) Jul 6, 2026
XhmikosR Credited to XhmikosR
9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass Critical
CVE-2026-49352 was published for 9router (npm) Jul 2, 2026
kaito7926 Credited to kaito7926
9router: Missing Authorization and OS Command Injection Critical
CVE-2026-59800 was published for 9router (npm) Jul 2, 2026
vcth4nh Credited to vcth4nh and Ductinn Ductinn Ductinn
OpenClaw: QQBot admin commands could skip DM-only and allowFrom policy Critical
GHSA-w4v6-g3wm-w36c was published for openclaw (npm) Jul 2, 2026
Kherrisan Credited to Kherrisan
Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header Critical
CVE-2026-53943 was published for ghost (npm) Jul 1, 2026
Crypto-Cat Credited to Crypto-Cat
deepstream is vulnerable to prototype pollution Critical
CVE-2026-49252 was published for @deepstream/server (npm) Jun 26, 2026
Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication Critical
CVE-2026-48797 was published for @mcptoolshop/backpropagate (npm) Jun 26, 2026
i18next-fs-backend vulnerable to prototype pollution via crafted missing-key string Critical
CVE-2026-48713 was published for i18next-fs-backend (npm) Jun 25, 2026
codeswhite Credited to codeswhite
ProTip! Advisories are also available from the GraphQL API