Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

187 advisories

Loading
Orval: Import-time RCE via query-parameter default -> zod module-level template literal Critical
CVE-2026-72716 was published for orval (npm) Sep 2, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Yamcs vulnerable to Remote Code Execution via instance-template argument YAML injection (createInstance) Critical
CVE-2026-55559 was published for org.yamcs:yamcs-core (Maven) Aug 28, 2026
MarkLee131 Credited to MarkLee131 and manus-use manus-use manus-use
silverstripe-advancedworkflow vulnerable to remote code execution via advanced workflow email template High
CVE-2026-54718 was published for symbiote/silverstripe-advancedworkflow (Composer) Aug 27, 2026
Phalcon Volt compiler `join` filter compile-time PHP code injection (SSTI leads to RCE) Critical
CVE-2026-59989 was published for phalcon/cphalcon (Composer) Aug 21, 2026
nikkoenggaliano Credited to nikkoenggaliano
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes) High
CVE-2026-53964 was published for document-merge-service (pip) Aug 19, 2026
sofianeelhor Credited to sofianeelhor, c0rydoras, and tonghuaroot c0rydoras c0rydoras
tonghuaroot tonghuaroot
Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions. Critical Unreviewed
CVE-2026-66613 was published Aug 19, 2026
@dynatrace-oss/dynatrace-mcp-server has a workflow template injection via create_workflow_for_notification Moderate
GHSA-xrmj-5g4g-8987 was published for @dynatrace-oss/dynatrace-mcp-server (npm) Jul 31, 2026
yotampe-pluto Credited to yotampe-pluto
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies High
CVE-2026-54666 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
ProTip! Advisories are also available from the GraphQL API