Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

124 advisories

Loading
Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign Critical
CVE-2026-48150 was published for @budibase/server (npm) Jun 12, 2026
adrgs Credited to adrgs and aisafe-bot aisafe-bot aisafe-bot
ibondarenko1 Credited to ibondarenko1
berkdedekarginoglu Credited to berkdedekarginoglu
Drupal core allows Object Injection Moderate
CVE-2026-6366 was published for drupal/core (Composer) May 20, 2026
yantongggg Credited to yantongggg
Curly-Haired-Baboon Credited to Curly-Haired-Baboon
FlowiseAI: Evaluator create+update mass-assignment allows cross-workspace evaluator takeover High
CVE-2026-46480 was published for flowise (npm) May 14, 2026
offset Credited to offset
FlowiseAI: Evaluation create+update mass-assignment allows cross-workspace evaluation takeover High
CVE-2026-46479 was published for flowise (npm) May 14, 2026
offset Credited to offset
FlowiseAI: DatasetRow create+update mass-assignment allows cross-workspace row takeover High
CVE-2026-46478 was published for flowise (npm) May 14, 2026
offset Credited to offset
FlowiseAI: Dataset create+update mass-assignment allows cross-workspace dataset takeover High
CVE-2026-46477 was published for flowise (npm) May 14, 2026
offset Credited to offset
offset Credited to offset
FlowiseAI: Assistant create+update mass-assignment allows cross-workspace assistant takeover High
CVE-2026-46475 was published for flowise (npm) May 14, 2026
offset Credited to offset
berkdedekarginoglu Credited to berkdedekarginoglu
berkdedekarginoglu Credited to berkdedekarginoglu
berkdedekarginoglu Credited to berkdedekarginoglu
berkdedekarginoglu Credited to berkdedekarginoglu
StarPlatinu Credited to StarPlatinu and igalklebanov igalklebanov igalklebanov
Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget in `parseReviver` Moderate
CVE-2026-42044 was published for axios (npm) May 5, 2026
August829 Credited to August829
Apache camel-coap allows header injection that can lead to remote code execution Critical
CVE-2026-33453 was published for org.apache.camel:camel-coap (Maven) Apr 27, 2026
k8sGPT has Prompt Injection through its k8sGPT-Operator High
GHSA-rp7v-4384-hfrp was published for github.com/k8sgpt-ai/k8sgpt (Go) Apr 24, 2026
haruki3hhh Credited to haruki3hhh
berkdedekarginoglu Credited to berkdedekarginoglu
Unsafe object property setter in mathjs High
CVE-2026-40897 was published for mathjs (npm) Apr 16, 2026
CykuTW Credited to CykuTW
berkdedekarginoglu Credited to berkdedekarginoglu
Kimai's User Preferences API allows standard users to modify restricted attributes: hourly_rate, internal_rate Moderate
CVE-2026-40486 was published for kimai/kimai (Composer) Apr 15, 2026
udaypali Credited to udaypali
mathjs Allows Improperly Controlled Modification of Dynamically-Determined Object Attributes High
CVE-2026-41139 was published for mathjs (npm) Apr 10, 2026
CykuTW Credited to CykuTW and marado marado marado
ProTip! Advisories are also available from the GraphQL API