Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,644 advisories

Loading
Electron: contextBridge object copy honors prototype setters Moderate
CVE-2026-70610 was published for electron (npm) Aug 5, 2026
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter Moderate
CVE-2026-70609 was published for electron (npm) Aug 5, 2026
hackerman70000 Credited to hackerman70000
Electron: window.open features string controls some window options considered privileged Moderate
CVE-2026-70607 was published for electron (npm) Aug 5, 2026
Electron: ProtocolResponse.url reuses the default session cache instead of the registering session Moderate
CVE-2026-70606 was published for electron (npm) Aug 5, 2026
rushitgit Credited to rushitgit
Electron: HTTP redirect followed into local file loader Moderate
CVE-2026-70605 was published for electron (npm) Aug 5, 2026
Electron: Extension tab APIs operate across session boundaries Moderate
CVE-2026-70602 was published for electron (npm) Aug 5, 2026
Electron: shell.openPath path validation bypass via embedded null byte Moderate
CVE-2026-70603 was published for electron (npm) Aug 5, 2026
yassine-doyensec Credited to yassine-doyensec, ikkisoft, and maxence-Doyensec ikkisoft ikkisoft
maxence-Doyensec maxence-Doyensec
Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin Moderate
CVE-2026-70599 was published for electron (npm) Aug 5, 2026
offset Credited to offset
Electron: Parent process code-sign check is spoofable Moderate
CVE-2026-70597 was published for electron (npm) Aug 5, 2026
Ghost Content API filter bypass reveals private fields Moderate
CVE-2026-53949 was published for ghost (npm) Aug 5, 2026
Ghost: Cross-Site Scripting in Feature Image Captions Moderate
CVE-2026-70596 was published for ghost (npm) Aug 5, 2026
itamarperetz Credited to itamarperetz
Ghost: Server-Side Request Forgery Mitigation Issue Moderate
CVE-2026-70595 was published for ghost (npm) Aug 5, 2026
Ghost: Paid gift memberships obtainable at minimal cost via the donations feature Moderate
CVE-2026-59817 was published for ghost (npm) Aug 4, 2026
sane100400 Credited to sane100400 and P4P3R-HAK P4P3R-HAK P4P3R-HAK
Ghost: Member existence leak via magic link sign-in response Moderate
CVE-2026-53947 was published for ghost (npm) Aug 4, 2026
Ghost: Session Fixation in Ghost Admin Moderate
CVE-2026-70594 was published for ghost (npm) Aug 4, 2026
meifukun Credited to meifukun
Ghost: Theme Upload Path Traversal Moderate
CVE-2026-70593 was published for ghost (npm) Aug 4, 2026
steph3nsims Credited to steph3nsims and KeenSecurityLab KeenSecurityLab KeenSecurityLab
Ghost: Database Backup Path Traversal Moderate
CVE-2026-70592 was published for ghost (npm) Aug 4, 2026
meifukun Credited to meifukun and alcls01111 alcls01111 alcls01111
Ghost: Server-Side Request Forgery in Image Fetching Moderate
CVE-2026-70591 was published for ghost (npm) Aug 4, 2026
koyokr Credited to koyokr and DavidCarliez DavidCarliez DavidCarliez
Ghost: Blind Password Hash Disclosure in Ghost Admin API Moderate
CVE-2026-70590 was published for ghost (npm) Aug 4, 2026
Ghost: Mobiledoc image-size fetch SSRF Moderate
CVE-2026-53946 was published for ghost (npm) Aug 4, 2026
Ghost: Server-side request forgery via DNS rebinding in external request handling Moderate
CVE-2026-53945 was published for ghost (npm) Aug 4, 2026
l3tchupkt Credited to l3tchupkt
Ghost: Private IP filtering bypass to make server-side requests to internal services Moderate
CVE-2026-53944 was published for ghost (npm) Aug 4, 2026
l3tchupkt Credited to l3tchupkt
Ghost: Archived Offers can be Redeemed Moderate
CVE-2026-70589 was published for ghost (npm) Aug 4, 2026
Ghost: File Upload Content-Type Spoofing Moderate
CVE-2026-53948 was published for ghost (npm) Aug 4, 2026
Ghost: Cross-Site Scripting in Universal Import Moderate
CVE-2026-70588 was published for ghost (npm) Aug 4, 2026
meifukun Credited to meifukun
ProTip! Advisories are also available from the GraphQL API