Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

11,261 advisories

Loading
n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints High
CVE-2026-54305 was published for n8n (npm) Jun 16, 2026
Solidscripting Credited to Solidscripting
n8n: Credential Exfiltration via Permission Bypass High
CVE-2026-54307 was published for n8n (npm) Jun 16, 2026
n8n: Stored XSS in Chat Trigger Node High
CVE-2026-54302 was published for n8n (npm) Jun 16, 2026
sm1ee Credited to sm1ee
n8n: Microsoft SQL Node Prototype Pollution High
CVE-2026-54312 was published for n8n (npm) Jun 16, 2026
s2ongmo Credited to s2ongmo
yt-dlp: Arbitrary command injection possible if --exec option used with yt-dlp High
GHSA-69qj-pvh9-c5wg was published for yt-dlp (pip) Jun 16, 2026
independent-arg Credited to independent-arg, bashonly, and Grub4K bashonly bashonly
Grub4K Grub4K
Daytona: Cross-org IDOR in organization role update/delete — any org owner can rewrite or destroy another org's roles High
CVE-2026-54322 was published for github.com/daytonaio/daytona (Go) Jun 16, 2026
vnth4nhnt Credited to vnth4nhnt and mrknight-n1du mrknight-n1du mrknight-n1du
Caddy: FastCGI header normalization bypass in `forward_auth copy_headers` High
CVE-2026-52845 was published for github.com/caddyserver/caddy (Go) Jun 16, 2026
Vincent550102 Credited to Vincent550102
Caddy: Windows `file_server` path authorization bypass via encoded backslash High
CVE-2026-52844 was published for github.com/caddyserver/caddy (Go) Jun 16, 2026
Vincent550102 Credited to Vincent550102
yt-dlp: Arbitrary code execution via manifest downloads with aria2c High
CVE-2026-50574 was published for yt-dlp (pip) Jun 16, 2026
seproDev Credited to seproDev, Grub4K, and bashonly Grub4K Grub4K
bashonly bashonly
Daytona: Public sandbox previews remain accessible for up to one hour after being made private High
CVE-2026-54321 was published for github.com/daytonaio/daytona (Go) Jun 16, 2026
mrknight-n1du Credited to mrknight-n1du
Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts High
CVE-2026-53622 was published for Traefik (Go) Jun 16, 2026
kamil-sawicki Credited to kamil-sawicki
Crawl4AI: SSRF via proxy settings in the Docker server bypasses the crawl-URL SSRF check High
CVE-2026-53755 was published for crawl4ai (pip) Jun 16, 2026
geo-chen Credited to geo-chen
Crawl4AI: Arbitrary file write (symlink/TOCTOU) plus log and webhook-header injection in Docker server High
GHSA-7cx2-g3h9-382p was published for crawl4ai (pip) Jun 16, 2026
Crawl4AI: LLM credential exfiltration in Docker server via request base_url and env: token resolution High
GHSA-f989-c77f-r2cq was published for crawl4ai (pip) Jun 16, 2026
geo-chen Credited to geo-chen
pavanchow Credited to pavanchow, Grub4K, and bashonly Grub4K Grub4K
bashonly bashonly
Deno: Miller-Rabin Primality Test Allows Zero Rounds High
CVE-2026-49440 was published for deno (Rust) Jun 16, 2026
HaoPham23 Credited to HaoPham23
Deno: Command Injection via spawnSync & spawn on Windows High
CVE-2026-49402 was published for deno (Rust) Jun 16, 2026
kejcao Credited to kejcao
Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass High
CVE-2026-48491 was published for Traefik (Go) Jun 16, 2026
kamil-sawicki Credited to kamil-sawicki
n8n: Same-Origin XSS in Respond to Webhook Node High
CVE-2026-54301 was published for n8n (npm) Jun 16, 2026
supperhellokitty20 Credited to supperhellokitty20
n8n: Python sandbox escape High
CVE-2026-49444 was published for n8n (npm) Jun 16, 2026
vipinxsec Credited to vipinxsec
pierreolivierbonin Credited to pierreolivierbonin and jperezdealgaba jperezdealgaba jperezdealgaba
Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints High
CVE-2026-33760 was published for langflow (pip) Jun 16, 2026
akshatgit Credited to akshatgit, AntonioABLima, andifilhohub, ethansilvas, and Jkavia AntonioABLima AntonioABLima
andifilhohub andifilhohub ethansilvas ethansilvas Jkavia Jkavia
Astro: Host header SSRF in prerendered error page fetch High
CVE-2026-54299 was published for astro (npm) Jun 16, 2026
5ud0er Credited to 5ud0er
LinZiyuu Credited to LinZiyuu and ekaf ekaf ekaf
ProTip! Advisories are also available from the GraphQL API