GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,569
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,522
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,354 advisories
Filter by severity
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
Critical
CVE-2026-77415
was published
for
jsonata
(npm)
Aug 21, 2026
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
Critical
CVE-2026-77414
was published
for
jsonata
(npm)
Aug 21, 2026
JSONata: Arbitrary Code Execution via crafted JSONata expressions
Critical
CVE-2026-77413
was published
for
jsonata
(npm)
Aug 21, 2026
Withdrawn Advisory: OS Command Injection in effect
Critical
CVE-2020-7624
was published
for
effect
(npm)
Feb 10, 2022
•
withdrawn
Qinglong has an incomplete fix for CVE-2026-3965: Improper Authentication
Critical
CVE-2026-55445
was published
for
@whyour/qinglong
(npm)
Aug 20, 2026
vm2: Sandbox Breakout Using Dangerous Host Proto Mutators
Critical
CVE-2026-47698
was published
for
vm2
(npm)
Aug 17, 2026
vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)
Critical
GHSA-m5w8-4gq2-6f8x
was published
for
vm2
(npm)
Aug 17, 2026
VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCE
Critical
CVE-2026-47686
was published
for
vm2
(npm)
Aug 17, 2026
Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE
Critical
CVE-2026-53633
was published
for
@vitest/browser
(npm)
Jun 15, 2026
When Vitest UI server is listening, arbitrary file can be read and executed
Critical
CVE-2026-47429
was published
for
vitest
(npm)
Jun 1, 2026
@vitest/browser: Browser Mode provider commands bypass the file-access permission gate
Critical
CVE-2026-73653
was published
for
@vitest/browser
(npm)
Jul 21, 2026
Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)
Critical
CVE-2026-73649
was published
for
velocityjs
(npm)
Jul 24, 2026
sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock
Critical
CVE-2026-73567
was published
for
sm-crypto
(npm)
Jul 24, 2026
Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
Critical
CVE-2026-73421
was published
for
next-auth
(npm)
Jul 23, 2026
Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
Critical
CVE-2026-73420
was published
for
@auth/core
(npm)
Jul 23, 2026
Shescape: Shell injection via unescaped parentheses on Windows with CMD
Critical
CVE-2026-73414
was published
for
shescape
(npm)
Jul 24, 2026
Budibase has nonymous NoSQL operator injection via published-app query templates
Critical
CVE-2026-54350
was published
for
@budibase/server
(npm)
Jun 23, 2026
Budibase has arbitrary file read by workspace-builder via PWA-zip symlink upload
Critical
CVE-2026-54352
was published
for
@budibase/server
(npm)
Jun 22, 2026
Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified
Critical
CVE-2026-73302
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: SQL Injection via `multipleStatements: true`
Critical
CVE-2026-73300
was published
for
@budibase/server
(npm)
Jul 24, 2026
crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
Critical
CVE-2026-71851
was published
for
crypto-js
(npm)
Aug 7, 2026
Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host
Critical
CVE-2026-71319
was published
for
@nuxt/devtools
(npm)
Aug 5, 2026
@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution
Critical
CVE-2026-54658
was published
for
@hypequery/clickhouse
(npm)
Jul 28, 2026
Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service
Critical
CVE-2026-70478
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
Critical
CVE-2026-70477
was published
for
flowise
(npm)
Aug 4, 2026
ProTip!
Advisories are also available from the
GraphQL API