Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,350 advisories

Loading
vm2: Sandbox Breakout Using Dangerous Host Proto Mutators Critical
CVE-2026-47698 was published for vm2 (npm) Aug 17, 2026
XmiliaH Credited to XmiliaH, the-vibe-dev, oran-s, dinhvaren, zolbooo, nil340, rexpository, and lukefr09 the-vibe-dev the-vibe-dev
oran-s oran-s dinhvaren dinhvaren zolbooo zolbooo nil340 nil340 rexpository rexpository lukefr09 lukefr09
VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCE Critical
CVE-2026-47686 was published for vm2 (npm) Aug 17, 2026
VladimirEliTokarev Credited to VladimirEliTokarev
juli Credited to juli
Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host Critical
CVE-2026-71319 was published for @nuxt/devtools (npm) Aug 5, 2026
TazmiDev Credited to TazmiDev and anzuukino anzuukino anzuukino
DeathsPirate Credited to DeathsPirate
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability Critical
CVE-2026-70477 was published for flowise (npm) Aug 4, 2026
zdi-disclosures Credited to zdi-disclosures
amwhoi Credited to amwhoi
Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE Critical
CVE-2026-70470 was published for flowise (npm) Aug 4, 2026
fg0x0 Credited to fg0x0
Flowise RCE via SQLite Record Manager Node Critical
CVE-2026-69259 was published for flowise (npm) Aug 4, 2026
alex-elttam Credited to alex-elttam
Flowise: Remote Code Execution Vulnerability in CSVAgent Critical
CVE-2026-69256 was published for flowise (npm) Aug 4, 2026
jia-elttam Credited to jia-elttam
Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified Critical
CVE-2026-69255 was published for flowise (npm) Aug 4, 2026
lexi-core-ai Credited to lexi-core-ai
Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override Critical
CVE-2026-69254 was published for flowise (npm) Aug 4, 2026
akshat-sj Credited to akshat-sj
Flowise Sandbox Escape to RCE Critical
CVE-2026-69253 was published for flowise (npm) Aug 4, 2026
alex-elttam Credited to alex-elttam
Flowise RCE via TypeORM DataSource Critical
CVE-2026-69251 was published for flowise (npm) Aug 4, 2026
alex-elttam Credited to alex-elttam
Sequelize: SQL Injection (Oracle DB) Critical
CVE-2026-69240 was published for sequelize (npm) Aug 3, 2026
t-tera Credited to t-tera
H3xV0rT3x Credited to H3xV0rT3x
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE Critical
CVE-2026-52887 was published for @nocobase/plugin-notification-in-app-message (npm) Jul 31, 2026
kah-ja Credited to kah-ja
AWS Amplify Studio UI Component Properties Has an Input Validation Issue Critical
CVE-2025-4318 was published for @aws-amplify/codegen-ui-react (npm) Jul 30, 2026
@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution Critical
CVE-2026-54658 was published for @hypequery/clickhouse (npm) Jul 28, 2026
cobyge Credited to cobyge and BarakSrour BarakSrour BarakSrour
Shescape: Shell injection via unescaped parentheses on Windows with CMD Critical
CVE-2026-73414 was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock Critical
CVE-2026-73567 was published for sm-crypto (npm) Jul 24, 2026
afldl Credited to afldl
Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak Critical
GHSA-mqhr-6j6h-74p5 was published for @budibase/server (npm) Jul 24, 2026
Hasinohacker Credited to Hasinohacker
Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified Critical
CVE-2026-73302 was published for @budibase/server (npm) Jul 24, 2026
freeman-bb Credited to freeman-bb
Budibase: SQL Injection via `multipleStatements: true` Critical
CVE-2026-73300 was published for @budibase/server (npm) Jul 24, 2026
kaimandalic Credited to kaimandalic
ProTip! Advisories are also available from the GraphQL API