GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,615
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,036
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            4,255 advisories
        Filter by severity
        
      
      
    
                    
                      node-tar has a race condition leading to uninitialized memory exposure
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-64118
                      
                      was published
                        for
                        
                          tar
                        
                        (npm)
                      Oct 30, 2025 
                    
                  
                    
                      n8n Vulnerable to Remote Code Execution via Git Node Pre-Commit Hook
                    
                      
  High
                    
                
                      
                        CVE-2025-62726
                      
                      was published
                        for
                        
                          n8n
                        
                        (npm)
                      Oct 30, 2025 
                    
                  
                    
                      TypeORM vulnerable to SQL injection via crafted request to repository.save or repository.update
                    
                      
  High
                    
                
                      
                        CVE-2025-60542
                      
                      was published
                        for
                        
                          typeorm
                        
                        (npm)
                      Oct 29, 2025 
                    
                  
                    
                      NextAuthjs Email misdelivery Vulnerability
                    
                      
  Moderate
                    
                
                      
                        GHSA-5jpx-9hw9-2fx4
                      
                      was published
                        for
                        
                          next-auth
                        
                        (npm)
                      Oct 29, 2025 
                    
                  
                    
                      Astro's bypass of image proxy domain validation leads to SSRF and potential XSS
                    
                      
  High
                    
                
                      
                        CVE-2025-59837
                      
                      was published
                        for
                        
                          astro
                        
                        (npm)
                      Oct 28, 2025 
                    
                  
                    
                      Hono vulnerable to Vary Header Injection leading to potential CORS Bypass
                    
                      
  Moderate
                    
                
                      
                        GHSA-q7jf-gf43-6x6p
                      
                      was published
                        for
                        
                          hono
                        
                        (npm)
                      Oct 24, 2025 
                    
                  
                    
                      rollbar vulnerable to Prototype Pollution in merge()
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62517
                      
                      was published
                        for
                        
                          rollbar
                        
                        (npm)
                      Oct 23, 2025 
                    
                  
                    
                      Kottster app reinitialization can be re-triggered allowing command injection in development mode
                    
                      
  High
                    
                
                      
                        CVE-2025-62713
                      
                      was published
                        for
                        
                          @kottster/server
                        
                        (npm)
                      Oct 23, 2025 
                    
                  
                    
                      Hono Improper Authorization vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2025-62610
                      
                      was published
                        for
                        
                          hono
                        
                        (npm)
                      Oct 22, 2025 
                    
                  
                    
                      Koa Vulnerable to Open Redirect via Trailing Double-Slash (//) in back Redirect Logic
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62595
                      
                      was published
                        for
                        
                          koa
                        
                        (npm)
                      Oct 21, 2025 
                    
                  
                    
                      Uptime Kuma Server-side Template Injection (SSTI) in Notification Templates Allows Arbitrary File Read
                    
                      
  Moderate
                    
                
                      
                        GHSA-vffh-c9pq-4crh
                      
                      was published
                        for
                        
                          uptime-kuma
                        
                        (npm)
                      Oct 20, 2025 
                    
                  
                    
                      vite allows server.fs.deny bypass via backslash on Windows
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-62522
                      
                      was published
                        for
                        
                          vite
                        
                        (npm)
                      Oct 20, 2025 
                    
                  
                    
                      Actual Sync-server Gocardless service is logging sensitive data including bearer tokens and account numbers
                    
                      
  Moderate
                    
                
                      
                        GHSA-xvp7-8vm8-xfxx
                      
                      was published
                        for
                        
                          @actual-app/sync-server
                        
                        (npm)
                      Oct 20, 2025 
                    
                  
                    
                      rollbar vulnerable to prototype pollution
                    
                      
  Low
                    
                
                      
                        CVE-2025-57325
                      
                      was published
                        for
                        
                          rollbar
                        
                        (npm)
                      Oct 20, 2025 
                    
                  
                    
                      Duplicate Advisory: FlowiseAI Pre-Auth Arbitrary Code Execution
                    
                      
  Critical
                    
                
                      
                        GHSA-3g4j-r53p-22wx
                      
                      was published
                        for
                        
                          flowise
                        
                        (npm)
                      Oct 17, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      Lobe Chat vulnerable to Server-Side Request Forgery with native web fetch module
                    
                      
  Low
                    
                
                      
                        CVE-2025-62505
                      
                      was published
                        for
                        
                          @lobehub/chat
                        
                        (npm)
                      Oct 17, 2025 
                    
                  
                    
                      Mammoth is vulnerable to Directory Traversal
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-11849
                      
                      was published
                        for
                        
                          Mammoth
                        
                        (Maven)
                      Oct 17, 2025 
                    
                  
                    
                      Angular SSR has a Server-Side Request Forgery (SSRF) flaw
                    
                      
  High
                    
                
                      
                        CVE-2025-62427
                      
                      was published
                        for
                        
                          @angular/ssr
                        
                        (npm)
                      Oct 16, 2025 
                    
                  
                    
                      Strapi core vulnerable to sensitive data exposure via CORS misconfiguration
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-53092
                      
                      was published
                        for
                        
                          @strapi/core
                        
                        (npm)
                      Oct 16, 2025 
                    
                  
                    
                      Strapi Password Hashing Missing Maximum Password Length Validation
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-25298
                      
                      was published
                        for
                        
                          @strapi/core
                        
                        (npm)
                      Oct 16, 2025 
                    
                  
                    
                      Strapi Allows Unauthorized Access to Private Fields via parms.lookup
                    
                      
  High
                    
                
                      
                        CVE-2024-56143
                      
                      was published
                        for
                        
                          @strapi/core
                        
                        (npm)
                      Oct 16, 2025 
                    
                  
                    
                      Strapi is vulnerable to Insufficient Session Expiration
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-3930
                      
                      was published
                        for
                        
                          @strapi/strapi
                        
                        (npm)
                      Oct 16, 2025 
                    
                  
                    
                      happy-dom's `--disallow-code-generation-from-strings` is not sufficient for isolating untrusted JavaScript
                    
                      
  Critical
                    
                
                      
                        CVE-2025-62410
                      
                      was published
                        for
                        
                          happy-dom
                        
                        (npm)
                      Oct 15, 2025 
                    
                  
                    
                      `sveltekit-superforms` has Prototype Pollution in `parseFormData` function of `formData.js`
                    
                      
  High
                    
                
                      
                        CVE-2025-62381
                      
                      was published
                        for
                        
                          sveltekit-superforms
                        
                        (npm)
                      Oct 15, 2025 
                    
                  
                    
                      Mailgen has HTML Injection and XSS Filter Bypass in Plaintext Emails
                    
                      
  Low
                    
                
                      
                        CVE-2025-62380
                      
                      was published
                        for
                        
                          mailgen
                        
                        (npm)
                      Oct 15, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API