Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7,013 advisories

Loading
mathlive's Lack of Escaping of HTML allows for XSS Moderate
CVE-2026-54705 was published for mathlive (npm) Jul 29, 2026
CosmicCrusader23 Credited to CosmicCrusader23
AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping High
CVE-2026-11393 was published for @aws/agentcore (npm) Jul 29, 2026
@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate Low
GHSA-pc2w-4mq8-32qw was published for @dynatrace-oss/dynatrace-mcp-server (npm) Jul 29, 2026
yotampe-pluto Credited to yotampe-pluto
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies High
CVE-2026-54666 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
swagger-typescript-api vulnerable to code injection via unescaped enum string values High
CVE-2026-54664 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template High
CVE-2026-54661 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref` Moderate
CVE-2026-54663 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template High
CVE-2026-54662 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref` High
CVE-2026-54660 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
Style Dictionary - Prototype Pollution in convertTokenData utility function High
CVE-2026-54639 was published for style-dictionary (npm) Jul 28, 2026
Dremig Credited to Dremig and jorenbroekema jorenbroekema jorenbroekema
@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution Critical
CVE-2026-54658 was published for @hypequery/clickhouse (npm) Jul 28, 2026
cobyge Credited to cobyge
NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass Moderate
CVE-2026-52888 was published for @nocobase/plugin-collection-sql (npm) Jul 28, 2026
lucquach Credited to lucquach
QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding High
CVE-2026-54609 was published for com.quietterminal:qti-neon (Maven) Jul 28, 2026
b-hermes Credited to b-hermes
@wakaru/cli arbitrary file write during bundle unpack High
CVE-2026-54545 was published for @wakaru/cli (npm) Jul 28, 2026
j4k0xb Credited to j4k0xb
FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller Moderate
GHSA-8q49-2h5h-434x was published for @frontmcp/adapters (npm) Jul 24, 2026
EchoSkorJjj Credited to EchoSkorJjj and frontegg-david frontegg-david frontegg-david
Quasar: Prototype pollution in the extend() utility Moderate
GHSA-3r53-75j5-3g7j was published for quasar (npm) Jul 24, 2026
Dremig Credited to Dremig
Shescape: Quadratic-time denial of service in the flag-protection High
GHSA-gm3r-q2wp-hw87 was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
Shescape: Home-directory disclosure in assignment context on Unix with Dash Moderate
GHSA-q53c-4prm-w95q was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
Shescape: Shell injection via unescaped parentheses on Windows with CMD Critical
GHSA-w4hw-qcx7-56pr was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
Shescape: Path disclosure on Unix with Zsh Moderate
GHSA-6v4m-fw66-8r4x was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash High
CVE-2026-14257 was published for brace-expansion (npm) Jul 24, 2026
bnbdr Credited to bnbdr
sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock Critical
GHSA-vh45-f885-3848 was published for sm-crypto (npm) Jul 24, 2026
afldl Credited to afldl
@anephenix/hub: Unauthenticated WebSocket RPC Waiter Resource Exhaustion High
GHSA-g5vv-q72c-7j78 was published for @anephenix/hub (npm) Jul 24, 2026
Budibase: SSRF via bare fetch() in uploadUrl during AI table generation Moderate
GHSA-hfhx-w8p8-4hc7 was published for @budibase/server (npm) Jul 24, 2026
oduoke567 Credited to oduoke567
ProTip! Advisories are also available from the GraphQL API