Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,354 advisories

Loading
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions Critical
CVE-2026-77415 was published for jsonata (npm) Aug 21, 2026
c0rydoras Credited to c0rydoras
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions Critical
CVE-2026-77414 was published for jsonata (npm) Aug 21, 2026
c0rydoras Credited to c0rydoras
JSONata: Arbitrary Code Execution via crafted JSONata expressions Critical
CVE-2026-77413 was published for jsonata (npm) Aug 21, 2026
peaktwilight Credited to peaktwilight and c0rydoras c0rydoras c0rydoras
Withdrawn Advisory: OS Command Injection in effect Critical
CVE-2020-7624 was published for effect (npm) Feb 10, 2022 withdrawn
Qinglong has an incomplete fix for CVE-2026-3965: Improper Authentication Critical
CVE-2026-55445 was published for @whyour/qinglong (npm) Aug 20, 2026
decsecre583 Credited to decsecre583
vm2: Sandbox Breakout Using Dangerous Host Proto Mutators Critical
CVE-2026-47698 was published for vm2 (npm) Aug 17, 2026
XmiliaH Credited to XmiliaH, the-vibe-dev, oran-s, dinhvaren, zolbooo, nil340, rexpository, and lukefr09 the-vibe-dev the-vibe-dev
oran-s oran-s dinhvaren dinhvaren zolbooo zolbooo nil340 nil340 rexpository rexpository lukefr09 lukefr09
VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCE Critical
CVE-2026-47686 was published for vm2 (npm) Aug 17, 2026
VladimirEliTokarev Credited to VladimirEliTokarev
Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE Critical
CVE-2026-53633 was published for @vitest/browser (npm) Jun 15, 2026
When Vitest UI server is listening, arbitrary file can be read and executed Critical
CVE-2026-47429 was published for vitest (npm) Jun 1, 2026
sapphi-red Credited to sapphi-red, qispark, joevin-slq-docto, koteswar-k, SaronGrave, and jason-anthropic qispark qispark
joevin-slq-docto joevin-slq-docto koteswar-k koteswar-k SaronGrave SaronGrave jason-anthropic jason-anthropic
@vitest/browser: Browser Mode provider commands bypass the file-access permission gate Critical
CVE-2026-73653 was published for @vitest/browser (npm) Jul 21, 2026
manus-use Credited to manus-use
cruzryan Credited to cruzryan and cuauht cuauht cuauht
sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock Critical
CVE-2026-73567 was published for sm-crypto (npm) Jul 24, 2026
afldl Credited to afldl
marc-zollingkoffer-syzygy Credited to marc-zollingkoffer-syzygy
kakashi-kx Credited to kakashi-kx
Shescape: Shell injection via unescaped parentheses on Windows with CMD Critical
CVE-2026-73414 was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
Budibase has nonymous NoSQL operator injection via published-app query templates Critical
CVE-2026-54350 was published for @budibase/server (npm) Jun 23, 2026
kah-ja Credited to kah-ja
Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload Critical
CVE-2026-54352 was published for @budibase/server (npm) Jun 22, 2026
kah-ja Credited to kah-ja
Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified Critical
CVE-2026-73302 was published for @budibase/server (npm) Jul 24, 2026
freeman-bb Credited to freeman-bb
Budibase: SQL Injection via `multipleStatements: true` Critical
CVE-2026-73300 was published for @budibase/server (npm) Jul 24, 2026
kaimandalic Credited to kaimandalic
juli Credited to juli
Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host Critical
CVE-2026-71319 was published for @nuxt/devtools (npm) Aug 5, 2026
TazmiDev Credited to TazmiDev and anzuukino anzuukino anzuukino
@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution Critical
CVE-2026-54658 was published for @hypequery/clickhouse (npm) Jul 28, 2026
cobyge Credited to cobyge and BarakSrour BarakSrour BarakSrour
DeathsPirate Credited to DeathsPirate
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability Critical
CVE-2026-70477 was published for flowise (npm) Aug 4, 2026
zdi-disclosures Credited to zdi-disclosures
ProTip! Advisories are also available from the GraphQL API