Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3 advisories

Loading
Webpack's AutoPublicPathRuntimeModule has a DOM Clobbering Gadget that leads to XSS Moderate
CVE-2024-43788 was published for webpack (npm) Aug 27, 2024
jackfromeast Credited to jackfromeast, ishmeals, and mhassan1 ishmeals ishmeals
mhassan1 mhassan1
js-yaml has prototype pollution in merge (<<) Moderate
CVE-2025-64718 was published for js-yaml (npm) Nov 14, 2025
Zephkek Credited to Zephkek, mhassan1, opal-visibuild, alexstrive, jlp-craigmorten, and turi4200 mhassan1 mhassan1
opal-visibuild opal-visibuild alexstrive alexstrive jlp-craigmorten jlp-craigmorten turi4200 turi4200
Cross-site Scripting (XSS) in serialize-javascript Moderate
CVE-2024-11831 was published for serialize-javascript (npm) Feb 10, 2025
mhassan1 Credited to mhassan1
ProTip! Advisories are also available from the GraphQL API