Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

647 advisories

Loading
Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution... Moderate Unreviewed
CVE-2026-92781 was published Sep 16, 2026
yayson: Prototype pollution in Store/LegacyStore deserialization Critical
CVE-2026-61534 was published for yayson (npm) Sep 11, 2026
hackchang Credited to hackchang and jede jede jede
n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service Moderate
CVE-2026-86078 was published for n8n (npm) Sep 10, 2026
Masofgon Credited to Masofgon
joi: Prototype pollution via a `__proto__` language key in custom messages Low
CVE-2026-84368 was published for @hapi/joi (npm) Sep 8, 2026
tihanyin Credited to tihanyin and mordamin mordamin mordamin
joi: object().rename() with a template target can set the validated object's prototype Low
CVE-2026-84367 was published for joi (npm) Sep 8, 2026
Zyy0530 Credited to Zyy0530, Str1ckl4nd, and 7thParkk Str1ckl4nd Str1ckl4nd
7thParkk 7thParkk
node-csv: Prototype replacement still reachable via columns path Moderate
CVE-2026-85063 was published for csv-parse (npm) Sep 8, 2026
TOON: Prototype pollution when decoding untrusted TOON input High
CVE-2026-82404 was published for @toon-format/toon (npm) Sep 3, 2026
ckorhonen Credited to ckorhonen
ApostropheCMS: 2nd-order prototype pollution via PATCH leading to single-request persistent DoS High
CVE-2026-71553 was published for apostrophe (npm) Sep 2, 2026
breakingsystems Credited to breakingsystems
Tiptap: mergeAttributes() turns an own __proto__ key into inherited executable DOM attributes Moderate
GHSA-cp6q-959q-f8rh was published for @tiptap/core (npm) Sep 2, 2026
joostgrunwald Credited to joostgrunwald
Livewire DOM-based cross-site scripting during client-side state handling Moderate
CVE-2026-81887 was published for livewire/livewire (Composer) Sep 2, 2026
Vagebondcur Credited to Vagebondcur and MelvinTh17 MelvinTh17 MelvinTh17
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
gettext-converter: Prototype pollution in js2i18next() via crafted translation keys Moderate
CVE-2026-55451 was published for gettext-converter (npm) Aug 20, 2026
Dremig Credited to Dremig
Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS High
CVE-2026-73654 was published for @trigger.dev/core (npm) Aug 13, 2026
MatiasTilleriasLey Credited to MatiasTilleriasLey
ProTip! Advisories are also available from the GraphQL API