GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
46
GitHub Actions
47
Go
3,340
Maven
5,000+
npm
5,000+
NuGet
881
pip
4,549
Pub
12
RubyGems
1,012
Rust
1,202
Swift
51
Unreviewed advisories
All unreviewed
5,000+
62 advisories
Filter by severity
Parse Server exposes auth data via /users/me endpoint
High
CVE-2026-33627
was published
for
parse-server
(npm)
Mar 24, 2026
Parse Server leaks protected fields via LiveQuery afterEvent trigger
High
CVE-2026-33163
was published
for
parse-server
(npm)
Mar 18, 2026
OpenClaw's dashboard leaked gateway auth material via browser URL/query and localStorage
High
GHSA-rchv-x836-w7xp
was published
for
openclaw
(npm)
Mar 9, 2026
OpenClaw: Native prompt image auto-load did not honor tools.fs.workspaceOnly in sandboxed runs
High
GHSA-9f72-qcpw-2hxc
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: Message action attachment hydration bypasses local media root checks when sandboxRoot is unset
High
CVE-2026-27522
was published
for
openclaw
(npm)
Mar 2, 2026
Feathers exposes internal headers via unencrypted session cookie
High
CVE-2026-27193
was published
for
@feathersjs/authentication-oauth
(npm)
Feb 19, 2026
n8n's Unsafe Buffer Allocation Allows In-Process Memory Disclosure in Task Runner
High
CVE-2025-61917
was published
for
n8n
(npm)
Feb 4, 2026
Shakapacker has environment variable leak via EnvironmentPlugin that exposes secrets to client-side bundles
High
GHSA-96qw-h329-v5rg
was published
for
shakapacker
(RubyGems)
Jan 8, 2026
Storybook manager bundle may expose environment variables during build
High
CVE-2025-68429
was published
for
storybook
(npm)
Dec 18, 2025
Strapi core vulnerable to sensitive data exposure via CORS misconfiguration
High
CVE-2025-53092
was published
for
@strapi/core
(npm)
Oct 16, 2025
@musistudio/claude-code-router has improper CORS configuration
High
CVE-2025-57755
was published
for
@musistudio/claude-code-router
(npm)
Aug 21, 2025
The AuthKit Remix Library renders sensitive auth data in HTML
High
CVE-2025-55009
was published
for
@workos-inc/authkit-remix
(npm)
Aug 8, 2025
The AuthKit React Router Library rendered sensitive auth data in HTML
High
CVE-2025-55008
was published
for
@workos-inc/authkit-react-router
(npm)
Aug 8, 2025
GitProxy Hidden Commits Injection
High
CVE-2025-54586
was published
for
@finos/git-proxy
(npm)
Jul 30, 2025
Directus's webhook trigger flows can leak sensitive data
High
CVE-2025-30353
was published
for
directus
(npm)
Mar 26, 2025
Prototype Pollution Vulnerability in parse-git-config
High
CVE-2025-25975
was published
for
parse-git-config
(npm)
Mar 12, 2025
Eugeny Tabby Sends Password Despite Host Key Verification Failure
High
CVE-2024-48460
was published
for
tabby-ssh
(npm)
Jan 17, 2025
Directus allows unauthenticated access to WebSocket events and operations
High
CVE-2024-54151
was published
for
@directus/api
(npm)
Dec 9, 2024
Modified package published to npm, containing malware that exfiltrates private key material
High
CVE-2024-54134
was published
for
@solana/web3.js
(npm)
Dec 4, 2024
secp256k1-node allows private key extraction over ECDH
High
CVE-2024-48930
was published
for
secp256k1
(npm)
Oct 21, 2024
Malicious homeservers can steal message keys when the matrix-react-sdk user invites another user to a room
High
CVE-2024-47824
was published
for
matrix-react-sdk
(npm)
Oct 15, 2024
Matrix JavaScript SDK's key history sharing could share keys to malicious devices
High
CVE-2024-47080
was published
for
matrix-js-sdk
(npm)
Oct 15, 2024
Tina search token leak via lock file in TinaCMS
High
CVE-2024-45391
was published
for
@tinacms/cli
(npm)
Sep 3, 2024
Directus Allows Single Sign-On User Enumeration
High
CVE-2024-39896
was published
for
directus
(npm)
Jul 8, 2024
Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem
High
CVE-2024-23331
was published
for
vite
(npm)
Jan 19, 2024
ProTip!
Advisories are also available from the
GraphQL API