Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,473 advisories

Loading
FrontMCP: Server-Side Request Forgery (SSRF) in the OpenAPI adapter spec-change poller Moderate
GHSA-8q49-2h5h-434x was published for @frontmcp/adapters (npm) Jul 24, 2026
EchoSkorJjj Credited to EchoSkorJjj and frontegg-david frontegg-david frontegg-david
Quasar: Prototype pollution in the extend() utility Moderate
GHSA-3r53-75j5-3g7j was published for quasar (npm) Jul 24, 2026
Dremig Credited to Dremig
Shescape: Home-directory disclosure in assignment context on Unix with Dash Moderate
GHSA-q53c-4prm-w95q was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
Shescape: Path disclosure on Unix with Zsh Moderate
GHSA-6v4m-fw66-8r4x was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
Budibase: SSRF via bare fetch() in uploadUrl during AI table generation Moderate
GHSA-hfhx-w8p8-4hc7 was published for @budibase/server (npm) Jul 24, 2026
oduoke567 Credited to oduoke567
Budibase: Account Enumeration via Login Lockout Response Differential Moderate
GHSA-cr7p-cr3q-h5cm was published for @budibase/server (npm) Jul 24, 2026
Budibase: OAuth2 Token Disclosure via Automation Test Results Broadcast to Other Builders Moderate
GHSA-gh4h-34gr-87r7 was published for @budibase/server (npm) Jul 24, 2026
Budibase: SSO OAuth2 Token Leakage via User Metadata Endpoints to Power-Role Users Moderate
GHSA-fcrw-f7gg-6g9f was published for @budibase/server (npm) Jul 24, 2026
Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings Moderate
GHSA-4qcj-m5wp-jmf4 was published for @budibase/server (npm) Jul 24, 2026
@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths Moderate
CVE-2026-7120 was published for @fastify/static (npm) Jul 24, 2026
yuki-matsuhashi Credited to yuki-matsuhashi, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
katzj Credited to katzj
@backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass Moderate
GHSA-38hq-7x33-php4 was published for @backstage/plugin-auth-backend (npm) Jul 24, 2026
Trix: Stored XSS via HTMLParser attribute injection on paste Moderate
GHSA-53g2-mvcc-q9x3 was published for action_text-trix (RubyGems) Jul 24, 2026
newbiefromcoma Credited to newbiefromcoma
Valibot: record() issue paths can make flatten() throw for inherited Object property names Moderate
CVE-2026-59952 was published for valibot (npm) Jul 24, 2026
Faze-up Credited to Faze-up
SvelteKit: Prototype pollution in file input deletion path in remote-function forms Moderate
GHSA-866w-xmhq-wj7x was published for @sveltejs/kit (npm) Jul 24, 2026
alanturing881 Credited to alanturing881 and dummdidumm dummdidumm dummdidumm
SvelteKit: Big remote form function payloads can cause Node process to crash Moderate
GHSA-wqjv-9729-c5q2 was published for @sveltejs/kit (npm) Jul 24, 2026
React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass) Moderate
CVE-2026-53669 was published for react-router (npm) Jul 23, 2026
outring Credited to outring
React Router: Open redirect leading to XSS Moderate
CVE-2026-53668 was published for react-router (npm) Jul 23, 2026
SouadSEBAA Credited to SouadSEBAA
React Router: RSCErrorHandler Missing Protocol Validation (XSS) Moderate
CVE-2026-53667 was published for react-router (npm) Jul 23, 2026
unknownhad Credited to unknownhad
React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration Moderate
CVE-2026-53666 was published for react-router (npm) Jul 23, 2026
yoyomiski Credited to yoyomiski
Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them Moderate
GHSA-x445-f3h2-j279 was published for @auth/core (npm) Jul 23, 2026
Nadav0077 Credited to Nadav0077
sm1ee Credited to sm1ee
n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner Moderate
GHSA-9cmh-xcqm-5hqr was published for n8n (npm) Jul 22, 2026
thesecguy45 Credited to thesecguy45
ProTip! Advisories are also available from the GraphQL API