Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

140 advisories

Loading
Unleash: Missing await on permission check + cross-project IDOR in admin API High
CVE-2026-77426 was published for unleash-server (npm) Sep 22, 2026
deepstream: PATCH_MULTI action bypasses Valve permission system allowing unauthorized record writes High
CVE-2026-63116 was published for @deepstream/server (npm) Sep 22, 2026
manus-use Credited to manus-use
mtholmquist Credited to mtholmquist
n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check Moderate
CVE-2026-86993 was published for n8n (npm) Sep 10, 2026
nlgbao1340 Credited to nlgbao1340
n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter Moderate
CVE-2026-86994 was published for n8n (npm) Sep 10, 2026
tr4ce-ju Credited to tr4ce-ju
n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket Moderate
CVE-2026-86077 was published for n8n (npm) Sep 10, 2026
tr4ce-ju Credited to tr4ce-ju
n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy Moderate
CVE-2026-86996 was published for n8n (npm) Sep 8, 2026
vonypeto Credited to vonypeto
sai-sh Credited to sai-sh
9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass High
CVE-2026-55638 was published for 9router (npm) Aug 28, 2026
dinhvaren Credited to dinhvaren
Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url` High
CVE-2026-54356 was published for @budibase/server (npm) Aug 26, 2026
KovachVL Credited to KovachVL
StarPlatinu Credited to StarPlatinu
geo-chen Credited to geo-chen
MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth Moderate
CVE-2026-69146 was published for mlflow (npm) Aug 17, 2026
geo-chen Credited to geo-chen
quantumshiro Credited to quantumshiro
offset Credited to offset
Flowise: Missing Authorization on Execution Update Endpoint High
CVE-2026-70475 was published for flowise (npm) Aug 4, 2026
Dimpyj1604 Credited to Dimpyj1604
truongvip1 Credited to truongvip1
@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate Low
GHSA-pc2w-4mq8-32qw was published for @dynatrace-oss/dynatrace-mcp-server (npm) Jul 29, 2026
yotampe-pluto Credited to yotampe-pluto
sfwani Credited to sfwani
Budibase: Privilege escalation via public role assignment API missing app-level authorization High
CVE-2026-73305 was published for @budibase/server (npm) Jul 24, 2026
dinhvaren Credited to dinhvaren
@better-auth/scim: account takeover and stale access via SCIM provider-id collision Critical
GHSA-rjg6-39jm-rgg4 was published for @better-auth/scim (npm) Jul 24, 2026
ProTip! Advisories are also available from the GraphQL API