GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
55
Go
4,531
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,350 advisories
Filter by severity
vm2: NodeVM `builtin: ['*']` exposes `os` and `dns` — process-wide observability reads AND writes that hijack the host (sibling class of GHSA-9g8x-92q2-p28f)
Critical
GHSA-m5w8-4gq2-6f8x
was published
for
vm2
(npm)
Aug 17, 2026
vm2: Sandbox Breakout Using Dangerous Host Proto Mutators
Critical
CVE-2026-47698
was published
for
vm2
(npm)
Aug 17, 2026
VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCE
Critical
CVE-2026-47686
was published
for
vm2
(npm)
Aug 17, 2026
crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain
Critical
CVE-2026-71851
was published
for
crypto-js
(npm)
Aug 7, 2026
Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host
Critical
CVE-2026-71319
was published
for
@nuxt/devtools
(npm)
Aug 5, 2026
Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables token theft for any connected service
Critical
CVE-2026-70478
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
Critical
CVE-2026-70477
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
Critical
CVE-2026-69264
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
Critical
CVE-2026-70470
was published
for
flowise
(npm)
Aug 4, 2026
Flowise RCE via SQLite Record Manager Node
Critical
CVE-2026-69259
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: Remote Code Execution Vulnerability in CSVAgent
Critical
CVE-2026-69256
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
Critical
CVE-2026-69255
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
Critical
CVE-2026-69254
was published
for
flowise
(npm)
Aug 4, 2026
Flowise RCE via TypeORM DataSource
Critical
CVE-2026-69251
was published
for
flowise
(npm)
Aug 4, 2026
Sequelize: SQL Injection (Oracle DB)
Critical
CVE-2026-69240
was published
for
sequelize
(npm)
Aug 3, 2026
Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass
Critical
CVE-2026-53609
was published
for
apostrophe
(npm)
Jul 31, 2026
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE
Critical
CVE-2026-52887
was published
for
@nocobase/plugin-notification-in-app-message
(npm)
Jul 31, 2026
AWS Amplify Studio UI Component Properties Has an Input Validation Issue
Critical
CVE-2025-4318
was published
for
@aws-amplify/codegen-ui-react
(npm)
Jul 30, 2026
@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution
Critical
CVE-2026-54658
was published
for
@hypequery/clickhouse
(npm)
Jul 28, 2026
Shescape: Shell injection via unescaped parentheses on Windows with CMD
Critical
CVE-2026-73414
was published
for
shescape
(npm)
Jul 24, 2026
sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock
Critical
CVE-2026-73567
was published
for
sm-crypto
(npm)
Jul 24, 2026
Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak
Critical
GHSA-mqhr-6j6h-74p5
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified
Critical
CVE-2026-73302
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: SQL Injection via `multipleStatements: true`
Critical
CVE-2026-73300
was published
for
@budibase/server
(npm)
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API