Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

22 advisories

Loading
NocoBase: Arbitrary File Write chained with Local file Inclusion leads to Remote code execution High
GHSA-ghvf-qf6h-g8x5 was published for @nocobase/server (npm) Aug 20, 2026
lukehebe Credited to lukehebe
SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses Moderate
GHSA-hjwh-xvfw-qrwj was published for mcp-searxng (npm) Aug 19, 2026
NARKHEDE-VAIBHAV Credited to NARKHEDE-VAIBHAV
Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling Moderate
GHSA-92hr-gmr6-h8cp was published for ep_etherpad-lite (npm) Aug 17, 2026
hashi-vault-js: Vault token and secret values exposed in thrown errors Moderate
CVE-2026-55102 was published for hashi-vault-js (npm) Aug 13, 2026
Sebasteuo Credited to Sebasteuo
Budibase: Server Filesystem Existence/Read Oracle via Builder-Controlled MongoDB tlsCertificateKeyFile High
CVE-2026-73409 was published for @budibase/server (npm) Jul 24, 2026
Hasinohacker Credited to Hasinohacker
mcp-memory-keeper: Arbitrary local file read in context_import via unvalidated filePath Moderate
CVE-2026-54561 was published for mcp-memory-keeper (npm) Jul 17, 2026
mcfly-zzh Credited to mcfly-zzh
@asymmetric-effort/specifyjs: Production console warnings may leak internal framework state Moderate
GHSA-qcr8-x557-7cp3 was published for @asymmetric-effort/specifyjs (npm) Jul 2, 2026
Parse Server's GraphQL "Did you mean ...?" validation suggestions disclose schema to unauthenticated callers Moderate
CVE-2026-47248 was published for parse-server (npm) May 29, 2026
offset Credited to offset and mtrezza mtrezza mtrezza
vm2 is Vulnerable to Host File Path Disclosure via Stack Trace Information Leak Moderate
CVE-2026-44002 was published for vm2 (npm) May 7, 2026
koDove Credited to koDove
parse-server: Malformed `$regex` query leaks database error details in API response Moderate
CVE-2026-30835 was published for parse-server (npm) Mar 6, 2026
fancymalware Credited to fancymalware and mtrezza mtrezza mtrezza
OpenClaw session tool visibility hardening and Telegram webhook secret fallback Moderate
CVE-2026-27004 was published for openclaw (npm) Feb 18, 2026
aether-ai-agent Credited to aether-ai-agent
Directus Vulnerable to Information Leakage in Existing Collections Moderate
CVE-2025-64749 was published for @directus/api (npm) Nov 13, 2025
sbstn-k Credited to sbstn-k and kmzs kmzs kmzs
Actual Sync-server Gocardless service is logging sensitive data including bearer tokens and account numbers Moderate
GHSA-xvp7-8vm8-xfxx was published for @actual-app/sync-server (npm) Oct 20, 2025
StoobertB Credited to StoobertB and MatissJanis MatissJanis MatissJanis
Generation of Error Message Containing Sensitive Information in zsa Moderate
CVE-2024-37162 was published for zsa (npm) Jun 6, 2024
tom-sherman Credited to tom-sherman
@backstage/backend-app-api leaks GitLab access tokens High
CVE-2023-6944 was published for @backstage/backend-app-api (npm) Jan 4, 2024
pfeifferj Credited to pfeifferj
NocoDB information disclosure vulnerability High
CVE-2022-2062 was published for nocodb (npm) Jun 14, 2022
Diavante vue-storefront-api and storefront-api disclose stack trace Moderate
CVE-2020-11883 was published for storefront-api (npm) May 24, 2022
ApiKey secret could be revelated on network issue High
CVE-2021-21421 was published for node-etsy-client (npm) Apr 6, 2021
boly38 Credited to boly38
Information Exposure in type-graphql Low
GHSA-xf64-2f9p-6pqq was published for type-graphql (npm) Sep 4, 2020
Authorization header is not sanitized in an error object in auth0 High
CVE-2020-15125 was published for auth0 (npm) Jul 29, 2020
osdiab Credited to osdiab
Sensitive Data Exposure in seneca Low
CVE-2019-5483 was published for seneca (npm) Sep 11, 2019
Sensitive Data Exposure in parse-server Moderate
CVE-2019-1020013 was published for parse-server (npm) Jul 11, 2019
fastrde Credited to fastrde and acinader acinader acinader
ProTip! Advisories are also available from the GraphQL API