GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,869
Erlang
36
GitHub Actions
36
Go
2,493
Maven
5,000+
npm
4,119
NuGet
735
pip
3,941
Pub
12
RubyGems
945
Rust
1,018
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,596 advisories
Filter by severity
x402 SDK vulnerable in outdated versions in resource servers for builders
High
GHSA-3j63-5h8p-gf7c
was published
for
x402
(npm)
Aug 20, 2025
Stored XSS in n8n Form Trigger allows Account Takeover via injected iframe and video/source
High
CVE-2025-52478
was published
for
n8n
(npm)
Aug 19, 2025
Claude Code's Permissive Default Allowlist Enables Unauthorized File Read and Network Exfiltration in Claude Code
High
CVE-2025-55284
was published
for
@anthropic-ai/claude-code
(npm)
Aug 18, 2025
Prototype Pollution in jquery-deparam
High
CVE-2021-20087
was published
for
jquery-deparam
(npm)
May 24, 2021
tar-fs can extract outside the specified dir with a specific tarball
High
CVE-2025-48387
was published
for
tar-fs
(npm)
Jun 3, 2025
GitProxy New Branch Approval Exploit
High
CVE-2025-54585
was published
for
@finos/git-proxy
(npm)
Jul 30, 2025
content-security-policy-parser Prototype Pollution Vulnerability May Lead to RCE
High
CVE-2025-55164
was published
for
content-security-policy-parser
(npm)
Aug 12, 2025
Withdrawn Advisory: bun vulnerable to OS Command Injection
High
CVE-2025-8022
was published
for
bun
(npm)
Jul 23, 2025
•
withdrawn
The AuthKit Remix Library renders sensitive auth data in HTML
High
CVE-2025-55009
was published
for
@workos-inc/authkit-remix
(npm)
Aug 8, 2025
The AuthKit React Router Library rendered sensitive auth data in HTML
High
CVE-2025-55008
was published
for
@workos-inc/authkit-react-router
(npm)
Aug 8, 2025
@fedify/fedify has Improper Authentication and Incorrect Authorization
High
CVE-2025-54888
was published
for
@fedify/fedify
(npm)
Aug 8, 2025
js-toml Prototype Pollution Vulnerability
High
CVE-2025-54803
was published
for
js-toml
(npm)
Aug 4, 2025
Claude Code echo command allowed bypass of user approval prompt for command execution
High
CVE-2025-54795
was published
for
@anthropic-ai/claude-code
(npm)
Aug 4, 2025
Claude Code Research Preview has a Path Restriction Bypass which could allow unauthorized file access
High
CVE-2025-54794
was published
for
@anthropic-ai/claude-code
(npm)
Aug 4, 2025
@stryker-mutator/util vulnerable to Prototype Pollution
High
CVE-2024-57085
was published
for
@stryker-mutator/util
(npm)
Feb 6, 2025
mcp-package-docs vulnerable to command injection in several tools
High
CVE-2025-54073
was published
for
mcp-package-docs
(npm)
Aug 5, 2025
GitProxy Backfile Parsing Exploit
High
CVE-2025-54584
was published
for
@finos/git-proxy
(npm)
Jul 30, 2025
GitProxy Approval Bypass When Pushing Multiple Branches
High
CVE-2025-54583
was published
for
@finos/git-proxy
(npm)
Jul 30, 2025
@nyariv/sandboxjs has Prototype Pollution vulnerability that may lead to RCE
High
CVE-2025-34146
was published
for
@nyariv/sandboxjs
(npm)
Jul 31, 2025
GitProxy Hidden Commits Injection
High
CVE-2025-54586
was published
for
@finos/git-proxy
(npm)
Jul 30, 2025
Linkify Allows Prototype Pollution & HTML Attribute Injection (XSS)
High
CVE-2025-8101
was published
for
linkifyjs
(npm)
Jul 26, 2025
ssrfcheck has Incomplete IP Address Deny List that leads to Server-Side Request Forgery Vulnerability
High
CVE-2025-8267
was published
for
ssrfcheck
(npm)
Jul 28, 2025
ProTip!
Advisories are also available from the
GraphQL API