GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,029
Maven
5,000+
npm
5,000+
NuGet
976
pip
5,000+
Pub
13
RubyGems
1,070
Rust
1,404
Swift
61
Unreviewed advisories
All unreviewed
5,000+
421 advisories
Filter by severity
Pi Agent: Race condition in Pi auth.json writes could expose stored credentials
Low
CVE-2026-54327
was published
for
@earendil-works/pi-coding-agent
(npm)
Jun 17, 2026
Pi Agent: Potential XSS in HTML session exports via Markdown URL sanitization bypass
Low
CVE-2026-54326
was published
for
@earendil-works/pi-coding-agent
(npm)
Jun 16, 2026
Cross-site scripting via <NoScript> slot content in Nuxt's head components
Low
GHSA-m3q2-p4fw-w38m
was published
for
nuxt
(npm)
Jun 16, 2026
Nuxt: Dev server discloses project absolute path and persistent workspace UUID via `/.well-known/appspecific/com.chrome.devtools.json`
Low
GHSA-rq7w-g337-39qq
was published
for
nuxt
(npm)
Jun 15, 2026
DOMPurify: Trusted Types policy survives `clearConfig()` and can poison later `RETURN_TRUSTED_TYPE` output
Low
GHSA-vxr8-fq34-vvx9
was published
for
dompurify
(npm)
Jun 15, 2026
React Router: Potential CSRF via PUT/PATCH/DELETE document requests
Low
CVE-2026-53663
was published
for
@remix-run/server-runtime
(npm)
Jun 15, 2026
DOMPurify: SAFE_FOR_TEMPLATES bypass - template expressions survive sanitization inside <template> content when using DOM output modes
Low
GHSA-gvmj-g25r-r7wr
was published
for
dompurify
(npm)
Jun 15, 2026
DOMPurify: `IN_PLACE` mode trusts attacker-controlled `nodeName` on live non-form nodes, allowing script retention and XSS via attacker-supplied DOM objects
Low
GHSA-x4vx-rjvf-j5p4
was published
for
dompurify
(npm)
Jun 15, 2026
@babel/core: Arbitrary File Read via sourceMappingURL Comment
Low
CVE-2026-49356
was published
for
@babel/core
(npm)
Jun 15, 2026
esbuild allows arbitrary file read when running the development server on Windows
Low
GHSA-g7r4-m6w7-qqqr
was published
for
esbuild
(npm)
Jun 12, 2026
Papra HTTP redirect bypass can lead to SSRF via webhook delivery system
Low
CVE-2026-48051
was published
for
@papra/webhooks
(npm)
Jun 10, 2026
NocoDB: Missing Ownership Check in MCP Attachment Read
Low
CVE-2026-47388
was published
for
nocodb
(npm)
Jun 5, 2026
NocoDB: User Enumeration via Sign-In Timing
Low
CVE-2026-47380
was published
for
nocodb
(npm)
Jun 5, 2026
vm2 setup-sandbox.js violates Defense Invariant #11 in stack-trace formatter
Low
GHSA-q3fm-4wcw-g57x
was published
for
vm2
(npm)
May 29, 2026
Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix
Low
CVE-2026-44489
was published
for
axios
(npm)
May 29, 2026
NocoDB: Stale Auth Cache After API Token Deletion
Low
CVE-2026-46554
was published
for
nocodb
(npm)
May 21, 2026
NocoDB: Attachment Size Limit Bypass via Upload-by-URL
Low
CVE-2026-46553
was published
for
nocodb
(npm)
May 21, 2026
NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation
Low
CVE-2026-46549
was published
for
nocodb
(npm)
May 21, 2026
Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning
Low
CVE-2026-46342
was published
for
@nuxt/nitro-server
(npm)
May 19, 2026
Turbo: Unexpected local code execution during Yarn Berry detection
Low
CVE-2026-45772
was published
for
@turbo/codemod
(npm)
May 19, 2026
Summarize contains a missing authorization vulnerability
Low
CVE-2026-45244
was published
for
@steipete/summarize
(npm)
May 18, 2026
Broken dropper in @mistralai/mistralai, @mistralai/mistralai-azure, @mistralai/mistralai-gcp
Low
GHSA-jgg6-4rpr-wfh7
was published
for
@mistralai/mistralai
(npm)
May 18, 2026
Sveltia CMS: Stored XSS in entry summary rendering via entity-decoded HTML
Low
GHSA-97r8-rf7q-wmjw
was published
for
@sveltia/cms
(npm)
May 18, 2026
@ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue
Low
CVE-2026-8769
was published
for
@ai-sdk/provider-utils
(npm)
May 18, 2026
@kilocode/cli Vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Low
CVE-2026-8766
was published
for
@kilocode/cli
(npm)
May 18, 2026
ProTip!
Advisories are also available from the
GraphQL API