GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,948
Maven
5,000+
npm
5,000+
NuGet
969
pip
5,000+
Pub
13
RubyGems
1,062
Rust
1,383
Swift
56
Unreviewed advisories
All unreviewed
5,000+
299 advisories
Filter by severity
n8n Has a Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints
High
CVE-2026-45732
was published
for
n8n
(npm)
May 14, 2026
FlowiseAI has Mass Assignment in Assistant Update Endpoint that Allows Cross-Workspace Resource Reassignment
High
CVE-2026-46441
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI has Mass Assignment in Chatflow Update Endpoint that Allows Cross-Workspace AgentFlow Reassignment
High
CVE-2026-42863
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI has Mass Assignment in Tool Update Endpoint that Allows Cross-Workspace Resource Reassignment
High
CVE-2026-42862
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI has Mass Assignment in Variable Update Endpoint that Allows Cross-Workspace Resource Reassignment
High
CVE-2026-42861
was published
for
flowise
(npm)
May 14, 2026
MantisBT Has Authorization Bypass in Global Profile Creation
Moderate
CVE-2026-33052
was published
for
mantisbt/mantisbt
(Composer)
May 11, 2026
Open WebUI has inconsistent authorization controls within memories API
High
CVE-2026-44570
was published
for
open-webui
(pip)
May 11, 2026
Spring Cloud Config has an Authorization Bypass Through User-Controlled Key
High
CVE-2026-40981
was published
for
org.springframework.cloud:spring-cloud-config
(Maven)
May 7, 2026
gittuf's policy can be rolled back to prior valid versions
Moderate
CVE-2026-44544
was published
for
github.com/gittuf/gittuf
(Go)
May 7, 2026
ShellHub has cross-tenant IDOR in `GET /api/namespaces/:tenant` via API Key bypasses membership check
Moderate
CVE-2026-44426
was published
for
github.com/shellhub-io/shellhub
(Go)
May 7, 2026
Aegra has cross-user run injection in /threads/{thread_id}/runs (IDOR)
High
CVE-2026-44504
was published
for
aegra-api
(pip)
May 7, 2026
ShellHub has cross-tenant IDOR in `GET /api/sessions/:uid` that discloses SSH session data
Moderate
CVE-2026-44423
was published
for
github.com/shellhub-io/shellhub
(Go)
May 6, 2026
ShellHub has cross-tenant IDOR in `GET /api/devices/:uid` that discloses device data of any namespace
Moderate
CVE-2026-44424
was published
for
github.com/shellhub-io/shellhub
(Go)
May 6, 2026
Hatchet affected by cross-tenant information disclosure in `listTasksByDAGIds`
Moderate
CVE-2026-42572
was published
for
github.com/hatchet-dev/hatchet
(Go)
May 6, 2026
Velocidex Velociraptor has an authorization bypass vulnerability
Moderate
CVE-2026-7573
was published
for
www.velocidex.com/golang/velociraptor
(Go)
May 6, 2026
AVideo: IDOR in PayPalYPT Plugin Allows Any Authenticated User to Cancel Arbitrary PayPal Subscription Agreements
Moderate
CVE-2026-43883
was published
for
wwbn/avideo
(Composer)
May 5, 2026
Grav Vulnerable to Administrative Account Disruption and Privilege De-escalation via User Overwrite Logic
High
CVE-2026-42609
was published
for
getgrav/grav
(Composer)
May 5, 2026
n8n has Public API Variables IDOR that Allows Cross-Project Secret Disclosure
Moderate
CVE-2026-42227
was published
for
n8n
(npm)
Apr 29, 2026
Duplicate Advisory: OpenClaw: Trailing-dot localhost CDP hosts could bypass remote loopback protections
Moderate
GHSA-f5fm-9jmp-c88r
was published
for
openclaw
(npm)
Apr 28, 2026
•
withdrawn
OpenClaw: Hook mapping templates could bypass hook session-key opt-in
Moderate
CVE-2026-45002
was published
for
openclaw
(npm)
Apr 25, 2026
Avo: Broken Access Control Through Unauthorized Execution of Arbitrary Action Classes Across Resources
High
CVE-2026-42205
was published
for
avo
(RubyGems)
Apr 24, 2026
Neko has a Self-service Privilege Escalation for Authenticated Users
High
CVE-2026-39386
was published
for
github.com/m1k1o/neko/server
(Go)
Apr 21, 2026
Flowise: Unauthenticated TTS endpoint accepts arbitrary credential IDs — enables API credit abuse via stored credentials
High
CVE-2026-41279
was published
for
flowise
(npm)
Apr 17, 2026
Flowise: Mass Assignment in DocumentStore Create Endpoint Leads to Cross-Workspace Object Takeover (IDOR)
High
CVE-2026-41277
was published
for
flowise
(npm)
Apr 17, 2026
Paperclip: Cross-tenant agent API key IDOR in `/agents/:id/keys` routes allows full victim-company compromise
Critical
GHSA-3xx2-mqjm-hg9x
was published
for
@paperclipai/server
(npm)
Apr 16, 2026
ProTip!
Advisories are also available from the
GraphQL API