GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,845
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,578
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
140 advisories
Filter by severity
Unleash: Missing await on permission check + cross-project IDOR in admin API
High
CVE-2026-77426
was published
for
unleash-server
(npm)
Sep 22, 2026
deepstream: PATCH_MULTI action bypasses Valve permission system allowing unauthorized record writes
High
CVE-2026-63116
was published
for
@deepstream/server
(npm)
Sep 22, 2026
n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints
Moderate
CVE-2026-86085
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
Moderate
CVE-2026-86993
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter
Moderate
CVE-2026-86994
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket
Moderate
CVE-2026-86077
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy
Moderate
CVE-2026-86996
was published
for
n8n
(npm)
Sep 8, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
CVE-2026-75858
was published
for
codewhale
(npm)
Sep 4, 2026
ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtree
Moderate
CVE-2026-63669
was published
for
apostrophe
(npm)
Sep 3, 2026
9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass
High
CVE-2026-55638
was published
for
9router
(npm)
Aug 28, 2026
Budibase authenticated arbitrary S3 signed upload URL issuance via `/api/attachments/:datasourceId/url`
High
CVE-2026-54356
was published
for
@budibase/server
(npm)
Aug 26, 2026
Tina: Broken Access Control: arbitrary bucket-key write/delete in `next-tinacms-s3` (and sibling production media adapters)
Moderate
CVE-2026-59992
was published
for
next-tinacms-azure
(npm)
Aug 19, 2026
GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data
High
CVE-2026-55178
was published
for
@geolens/sdk
(npm)
Aug 18, 2026
MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id
High
CVE-2026-69148
was published
for
mlflow
(npm)
Aug 17, 2026
MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth
Moderate
CVE-2026-69146
was published
for
mlflow
(npm)
Aug 17, 2026
Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients
High
CVE-2026-71316
was published
for
nuxt
(npm)
Aug 5, 2026
Flowise: Unauthenticated Credential Abuse via Text-to-Speech Endpoint Allows Unauthorized Use of Private Chatflow TTS Credentials
Moderate
GHSA-8gj2-2cvc-6xx7
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: Missing Authorization on Execution Update Endpoint
High
CVE-2026-70475
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history
High
CVE-2026-70473
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization
High
CVE-2026-69252
was published
for
flowise
(npm)
Aug 4, 2026
Duplicate Advisory: SiYuan: Cross-boundary content disclosure via getBacklinkDoc/getBackmentionDoc (publish mode): reader-reachable rendered DOM of publish-forbidden docs; sibling list endpoints are filtered
Critical
GHSA-2mmh-4rf8-7xg6
was published
for
siyuan
(npm)
Aug 3, 2026
•
withdrawn
@dynatrace-oss/dynatrace-mcp-server's create_dynatrace_notebook missing the human-approval gate
Low
GHSA-pc2w-4mq8-32qw
was published
for
@dynatrace-oss/dynatrace-mcp-server
(npm)
Jul 29, 2026
Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings
Moderate
CVE-2026-73301
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: Privilege escalation via public role assignment API missing app-level authorization
High
CVE-2026-73305
was published
for
@budibase/server
(npm)
Jul 24, 2026
@better-auth/scim: account takeover and stale access via SCIM provider-id collision
Critical
GHSA-rjg6-39jm-rgg4
was published
for
@better-auth/scim
(npm)
Jul 24, 2026
ProTip!
Advisories are also available from the
GraphQL API