GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
25 advisories
Filter by severity
High severity vulnerability that affects generator-jhipster
High
GHSA-mc84-xr9p-938r
was published
for
generator-jhipster
(npm)
Sep 23, 2019
Server-Side Request Forgery and Inclusion of Functionality from Untrusted Control Sphere in jsreport
High
CVE-2020-8128
was published
for
jsreport
(npm)
Apr 13, 2021
Unintended Require in larvitbase-api
High
CVE-2019-5479
was published
for
larvitbase-api
(npm)
Sep 11, 2019
Markdownify subject to Remote Code Execution via malicious markdown file
High
CVE-2022-41709
was published
for
electron-markdownify
(npm)
Oct 19, 2022
n8n Vulnerable to Remote Code Execution via Git Node Pre-Commit Hook
High
CVE-2025-62726
was published
for
n8n
(npm)
Oct 30, 2025
Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events
High
CVE-2025-64496
was published
for
open-webui
(npm)
Nov 7, 2025
Claude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn Versions
High
CVE-2025-59828
was published
for
@anthropic-ai/claude-code
(npm)
Sep 24, 2025
Duplicate Advisory: Embedded malware in ua-parser-js
High
GHSA-236c-vhj4-gfxg
was published
for
ua-parser-js
(npm)
May 25, 2022
•
withdrawn
Improper Control of Generation of Code ('Code Injection') in @tygo-van-den-hurk/slyde
High
CVE-2026-26974
was published
for
@tygo-van-den-hurk/slyde
(npm)
Feb 18, 2026
OpenClaw: safeBins static default trusted dirs allow writable-dir binary hijack (`jq`)
High
CVE-2026-32009
was published
for
openclaw
(npm)
Mar 3, 2026
Duplicate Advisory: OpenClaw: Workspace plugin auto-discovery allowed code execution from cloned repositories
High
GHSA-j5qh-5234-4rqp
was published
for
openclaw
(npm)
Mar 31, 2026
•
withdrawn
OpenClaw: Workspace plugin auto-discovery allowed code execution from cloned repositories
High
CVE-2026-32920
was published
for
openclaw
(npm)
Mar 13, 2026
Duplicate Advisory: OpenClaw: Workspace `.env` can override the bundled hooks root and load attacker hook code
High
GHSA-jx3c-247h-cxwp
was published
for
openclaw
(npm)
Apr 24, 2026
•
withdrawn
OpenClaw: Workspace `.env` can override the bundled plugin trust root
High
CVE-2026-41396
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Workspace `.env` can override the bundled hooks root and load attacker hook code
High
CVE-2026-41336
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: Channel setup catalog lookups could include untrusted workspace plugin shadows
High
CVE-2026-43571
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Workspace provider auth choices could auto-enable untrusted provider plugins
High
CVE-2026-43569
was published
for
openclaw
(npm)
Apr 17, 2026
[Eclipse Theia] Indirect Prompt Injection via Adversarial Workspace File and Directory Names in AI Chat
High
CVE-2026-44688
was published
for
@theia/ai-chat
(npm)
Jun 18, 2026
[Eclipse Theia] Arbitrary Command Execution via Untrusted Workspace Task Definitions
High
CVE-2026-44691
was published
for
@theia/debug
(npm)
Jun 18, 2026
[Eclipse Theia] Indirect Prompt Injection via Auto-Loaded Workspace Prompt Template Files in AI Chat
High
CVE-2026-46580
was published
for
@theia/ai-chat
(npm)
Jun 18, 2026
pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle
High
CVE-2026-55487
was published
for
pnpm
(npm)
Jun 26, 2026
pnpm: Repository-controlled configDependencies can select a pacquet native install engine
High
CVE-2026-55697
was published
for
pnpm
(npm)
Jun 26, 2026
pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes
High
CVE-2026-55698
was published
for
pnpm
(npm)
Jun 26, 2026
OpenClaw's marketplace runtime extension metadata could point at unscanned payloads
High
CVE-2026-53810
was published
for
openclaw
(npm)
Jul 2, 2026
yeoman-environment Vulnerable to Arbitrary Package Installation without User Confirmation
High
CVE-2026-42089
was published
for
yeoman-environment
(npm)
May 26, 2026
ProTip!
Advisories are also available from the
GraphQL API