Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

540 advisories

Loading
Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS High
CVE-2026-73654 was published for @trigger.dev/core (npm) Aug 13, 2026
MatiasTilleriasLey Credited to MatiasTilleriasLey
Mermaid configuration APIs allow prototype pollution Low
CVE-2026-71438 was published for mermaid (npm) Aug 6, 2026
Str1ckl4nd Credited to Str1ckl4nd, Zyy0530, 7thParkk, mauriceng98, and aloisklink Zyy0530 Zyy0530
7thParkk 7thParkk mauriceng98 mauriceng98 aloisklink aloisklink
Mermaid Architecture diagrams are vulnerable to prototype pollution Moderate
CVE-2026-71437 was published for mermaid (npm) Aug 6, 2026
ThomasRinsma Credited to ThomasRinsma, jkim-notion, and aloisklink jkim-notion jkim-notion
aloisklink aloisklink
Electron: contextBridge object copy honors prototype setters Moderate
CVE-2026-70610 was published for electron (npm) Aug 5, 2026
Duplicate Advisory: Axios: Prototype pollution auth subfields can inject Basic auth Moderate
GHSA-38gx-cfqf-f652 was published for axios (npm) Aug 1, 2026 withdrawn
H3xV0rT3x Credited to H3xV0rT3x
Jodit has prototype pollution via Jodit.configure() / ConfigMerge Moderate
CVE-2026-54756 was published for jodit (npm) Jul 31, 2026
@phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging High
CVE-2026-54737 was published for @phun-ky/defaults-deep (npm) Jul 31, 2026
supeRdaem Credited to supeRdaem
Style Dictionary - Prototype Pollution in convertTokenData utility function High
CVE-2026-54639 was published for style-dictionary (npm) Jul 28, 2026
Dremig Credited to Dremig and jorenbroekema jorenbroekema jorenbroekema
Quasar: Prototype pollution in the extend() utility Moderate
CVE-2026-73647 was published for quasar (npm) Jul 24, 2026
Dremig Credited to Dremig
katzj Credited to katzj
SvelteKit: Prototype pollution in file input deletion path in remote-function forms Moderate
GHSA-866w-xmhq-wj7x was published for @sveltejs/kit (npm) Jul 24, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team and dummdidumm dummdidumm dummdidumm
find-my-way: DDoS with HTTP2 High
CVE-2026-47219 was published for find-my-way (npm) Jul 23, 2026
Nadav0077 Credited to Nadav0077 and mcollina mcollina mcollina
n8n: Prototype Pollution via VM Expression Engine Sandbox Escape Leads to Denial of Service Moderate
GHSA-hx4h-vr3m-45vh was published for n8n (npm) Jul 22, 2026
n8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service High
GHSA-xwx6-jjhv-84p8 was published for n8n (npm) Jul 22, 2026
breakingsystems Credited to breakingsystems
assakafpix Credited to assakafpix
Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning High
GHSA-gcfj-64vw-6mp9 was published for axios (npm) Jul 20, 2026
thesmartshadow Credited to thesmartshadow
Axios: Nested axios option objects can consume polluted prototype values Moderate
GHSA-7q8q-rj6j-mhjq was published for axios (npm) Jul 20, 2026
asadeddin Credited to asadeddin
Axios: Prototype pollution gadgets can alter axios request construction Moderate
GHSA-mmx7-hfxf-jppx was published for axios (npm) Jul 20, 2026
bilerden Credited to bilerden
protobufjs: Text Format string map parsing can mutate returned map object prototype Moderate
CVE-2026-59876 was published for protobufjs (npm) Jul 20, 2026
Faze-up Credited to Faze-up
Axios: Prototype pollution auth subfields can inject Basic auth Moderate
CVE-2026-67314 was published for axios (npm) Jul 20, 2026
lullu57 Credited to lullu57
Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__ Low
CVE-2026-54335 was published for @feathersjs/commons (npm) Jul 14, 2026
ridingsa Credited to ridingsa
@hey-api/openapi-ts's `buildClientParams` template: prototype chain substitution via unknown `$<slot>___proto__` key Moderate
CVE-2026-48819 was published for @hey-api/openapi-ts (npm) Jul 1, 2026
programsurf Credited to programsurf, daeungdaeung, yoonsh, and lubroai daeungdaeung daeungdaeung
yoonsh yoonsh lubroai lubroai
@adonisjs/bodyparser has an incomplete fix for CVE-2026-25754 High
CVE-2026-48795 was published for @adonisjs/bodyparser (npm) Jun 30, 2026
EchoSkorJjj Credited to EchoSkorJjj
deepstream is vulnerable to prototype pollution Critical
CVE-2026-49252 was published for @deepstream/server (npm) Jun 26, 2026
ProTip! Advisories are also available from the GraphQL API