Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,379 advisories

Loading
@zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery Critical
CVE-2026-61559 was published for @zereight/mcp-gitlab (npm) Sep 15, 2026
avishaigonen-pluto Credited to avishaigonen-pluto and yotampe-pluto yotampe-pluto yotampe-pluto
@zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport Critical
CVE-2026-61568 was published for @zereight/mcp-gitlab (npm) Sep 15, 2026
avishaigonen-pluto Credited to avishaigonen-pluto and yotampe-pluto yotampe-pluto yotampe-pluto
Duplicate Advisory: Flowise OverrideConfig security vulnerability Critical
GHSA-5w6g-rc45-wvv9 was published for flowise (npm) Jun 20, 2026 withdrawn
yayson: Prototype pollution in Store/LegacyStore deserialization Critical
CVE-2026-61534 was published for yayson (npm) Sep 11, 2026
hackchang Credited to hackchang and jede jede jede
OmniRoute ACP Custom-Agent Remote Code Execution (RCE) Critical
CVE-2026-88062 was published for omniroute (npm) Sep 10, 2026
c111mb3r Credited to c111mb3r
Astro: Remote code execution through AVIF image optimization Critical
GHSA-26w7-cxv4-gfx2 was published for astro (npm) Sep 8, 2026
cn-panda Credited to cn-panda
Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used Critical
GHSA-2xp9-vwfh-vxw4 was published for next (npm) Sep 8, 2026
Next.js: Unauthenticated Remote Code Execution on windows-hosted servers Critical
CVE-2026-75604 was published for next (npm) Sep 8, 2026
evolutionstorm Credited to evolutionstorm and B0RI B0RI B0RI
MapLibre GL JS: XSS Sanitizer Bypass in DOM.sanitize() via Live NamedNodeMap Removal Skip Critical
CVE-2026-85061 was published for maplibre-gl (npm) Sep 8, 2026
CodeWhale: SSRF‌ bypass - TOCTOU on DNS failure for DNS pinning Critical
CVE-2026-75856 was published for codewhale (npm) Sep 4, 2026
JafarAkhondali Credited to JafarAkhondali
Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout) Critical
CVE-2026-62681 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m and mrostamipoor mrostamipoor mrostamipoor
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via schema default -> zod module-level template literal Critical
CVE-2026-72717 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via array-items default -> zod module-level template literal Critical
CVE-2026-71869 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via header-parameter default -> zod module-level template literal Critical
CVE-2026-71871 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generator Critical
CVE-2026-71867 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via enum-typed default -> zod module-level template literal Critical
CVE-2026-71868 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli Critical
CVE-2026-71865 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Gal3m Credited to Gal3m, mrostamipoor, aqeelat, and mohammad228 mrostamipoor mrostamipoor
aqeelat aqeelat mohammad228 mohammad228
Orval: Import-time RCE via query-parameter default -> zod module-level template literal Critical
CVE-2026-72716 was published for orval (npm) Sep 2, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
SAP Approuter Vulnerable to HTTP Request Smuggling Critical
CVE-2026-27690 was published for @sap/approuter (npm) Jul 14, 2026
henrybrink Credited to henrybrink
Duplicate Advisory: better-auth has an external request basePath modification DoS Critical
GHSA-3q45-2fh7-66cj was published for better-auth (npm) Aug 2, 2026 withdrawn
antonisloukis Credited to antonisloukis
vm2: Sandbox Breakout Using Dangerous Host Proto Mutators Critical
CVE-2026-47698 was published for vm2 (npm) Aug 17, 2026
XmiliaH Credited to XmiliaH, the-vibe-dev, oran-s, dinhvaren, PowerliftLog, zolbooo, nil340, rexpository, and lukefr09 the-vibe-dev the-vibe-dev
oran-s oran-s dinhvaren dinhvaren PowerliftLog PowerliftLog zolbooo zolbooo nil340 nil340 rexpository rexpository lukefr09 lukefr09
ProTip! Advisories are also available from the GraphQL API