GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,771
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
7,424 advisories
Filter by severity
@argos-ci/core: CI Branch Name OS Command Injection
High
CVE-2026-59960
was published
for
@argos-ci/core
(npm)
Sep 10, 2026
OmniRoute ACP Custom-Agent Remote Code Execution (RCE)
Critical
CVE-2026-88062
was published
for
omniroute
(npm)
Sep 10, 2026
n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution
Moderate
CVE-2026-86073
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content
Moderate
CVE-2026-86074
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
Moderate
CVE-2026-86995
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints
Moderate
CVE-2026-86085
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
Moderate
CVE-2026-86993
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions
Moderate
CVE-2026-86084
was published
for
n8n
(npm)
Sep 10, 2026
n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
Moderate
CVE-2026-86080
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers
Moderate
CVE-2026-86079
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service
Moderate
CVE-2026-86078
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter
Moderate
CVE-2026-86994
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution
High
CVE-2026-86083
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket
Moderate
CVE-2026-86077
was published
for
n8n
(npm)
Sep 10, 2026
Angular: SSR XSS via Unescaped <template> Content Across DocumentFragment Boundaries in Fallback Raw-Content Elements
High
CVE-2026-88060
was published
for
@angular/platform-server
(npm)
Sep 10, 2026
Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSR
High
CVE-2026-88056
was published
for
@angular/platform-server
(npm)
Sep 10, 2026
Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent`
Moderate
CVE-2026-88059
was published
for
@angular/common
(npm)
Sep 10, 2026
Angular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compiler
Moderate
CVE-2026-88057
was published
for
@angular/compiler
(npm)
Sep 10, 2026
n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node
High
CVE-2026-86082
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path
High
CVE-2026-86081
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint
High
CVE-2026-86075
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution
High
CVE-2026-86076
was published
for
n8n
(npm)
Sep 10, 2026
@eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name
High
GHSA-x7m8-jrm8-hpvx
was published
for
@eigenpal/docx-editor-core
(npm)
Sep 10, 2026
@openhop/server: Path Traversal in Flow ID File Operations
High
CVE-2026-59179
was published
for
@openhop/server
(npm)
Sep 9, 2026
functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import
High
CVE-2026-59176
was published
for
functype-mcp-server
(npm)
Sep 9, 2026
ProTip!
Advisories are also available from the
GraphQL API