GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
45
Go
3,196
Maven
5,000+
npm
5,000+
NuGet
864
pip
4,483
Pub
12
RubyGems
992
Rust
1,186
Swift
51
Unreviewed advisories
All unreviewed
5,000+
20 advisories
Filter by severity
rendertron can remotely shut down Chrome instance
High
CVE-2017-18353
was published
for
rendertron
(npm)
Jan 4, 2019
Sails before 0.12.7 vulnerable to Broken CORS
High
CVE-2016-10549
was published
for
sails
(npm)
Feb 18, 2019
ghost vulnerable to unauthorized newsletter modification via improper access controls
High
CVE-2022-41654
was published
for
ghost
(npm)
Nov 28, 2022
pnpm incorrectly parses tar archives relative to specification
High
CVE-2023-37478
was published
for
@pnpm/cafs
(npm)
Aug 1, 2023
Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem
High
CVE-2024-23331
was published
for
vite
(npm)
Jan 19, 2024
rejetto HFS vulnerable to OS Command Execution by remote authenticated users
High
CVE-2024-39943
was published
for
hfs
(npm)
Jul 5, 2024
Directus incorrectly handles `_in` filter
High
CVE-2024-39701
was published
for
directus
(npm)
Jul 8, 2024
Withdrawn Advisory: Lunary improper access control vulnerability
High
CVE-2024-6087
was published
for
lunary
(npm)
Sep 13, 2024
•
withdrawn
Erxes Incorrect Access Control vulnerability
High
CVE-2024-57190
was published
for
erxes
(npm)
Jun 10, 2025
@executeautomation/database-server does not properly restrict access, bypassing a "read-only" mode
High
CVE-2025-59333
was published
for
@executeautomation/database-server
(npm)
Sep 16, 2025
Strapi core vulnerable to sensitive data exposure via CORS misconfiguration
High
CVE-2025-53092
was published
for
@strapi/core
(npm)
Oct 16, 2025
Kottster app reinitialization can be re-triggered allowing command injection in development mode
High
CVE-2025-62713
was published
for
@kottster/server
(npm)
Oct 23, 2025
@apollo/composition has Improper Enforcement of Access Control on Interface Types and Fields
High
CVE-2025-64530
was published
for
@apollo/composition
(npm)
Nov 14, 2025
Better Auth Passkey Plugin allows passkey deletion through IDOR
High
GHSA-4vcf-q4xf-f48m
was published
for
@better-auth/passkey
(npm)
Nov 25, 2025
OpenClaw has an arbitrary transcript path file write via gateway sessionFile
High
CVE-2026-28459
was published
for
openclaw
(npm)
Feb 17, 2026
OpenClaw Node host system.run rawCommand/command mismatch can bypass allowlist/approvals
High
CVE-2026-26325
was published
for
openclaw
(npm)
Feb 17, 2026
OpenClaw Google Chat shared-path webhook target ambiguity allowed cross-account policy-context misrouting
High
CVE-2026-28469
was published
for
clawdbot
(npm)
Feb 18, 2026
OpenClaw: Native prompt image auto-load did not honor tools.fs.workspaceOnly in sandboxed runs
High
GHSA-9f72-qcpw-2hxc
was published
for
openclaw
(npm)
Mar 3, 2026
Parse Server has a protected fields bypass via logical query operators
High
CVE-2026-30962
was published
for
parse-server
(npm)
Mar 11, 2026
Parse Server has a protected fields bypass via dot-notation in query and sort
High
CVE-2026-31872
was published
for
parse-server
(npm)
Mar 11, 2026
ProTip!
Advisories are also available from the
GraphQL API