Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

3 advisories

Loading
lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` Moderate
CVE-2026-2950 was published for lodash (npm) Apr 1, 2026
Haruna38 Credited to Haruna38, shpik-kr, maru1009, ott3r07, zolbooo, backuardo, falsyvalues, jonchurch, jdalton, and UlisesGascon shpik-kr shpik-kr
maru1009 maru1009 ott3r07 ott3r07 zolbooo zolbooo backuardo backuardo falsyvalues falsyvalues jonchurch jonchurch jdalton jdalton UlisesGascon UlisesGascon
n8n: Prototype Pollution via VM Expression Engine Sandbox Escape Leads to Denial of Service Moderate
GHSA-hx4h-vr3m-45vh was published for n8n (npm) Jul 22, 2026
zolbooo Credited to zolbooo
moment vulnerable to Path Traversal via crafted non-string locale name Moderate
CVE-2026-17495 was published for moment (npm) Sep 29, 2026
zolbooo Credited to zolbooo, UlisesGascon, gilmoreorless, and mattjohnsonpint UlisesGascon UlisesGascon
gilmoreorless gilmoreorless mattjohnsonpint mattjohnsonpint
ProTip! Advisories are also available from the GraphQL API