GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,967
Maven
5,000+
npm
5,000+
NuGet
973
pip
5,000+
Pub
13
RubyGems
1,064
Rust
1,387
Swift
56
Unreviewed advisories
All unreviewed
5,000+
54 advisories
Filter by severity
@agenticmail/mcp Missing Authentication for Critical Function
High
GHSA-63gr-g7jc-v8rg
was published
for
@agenticmail/mcp
(npm)
Jun 1, 2026
CamoFox MCP: Unauthenticated HTTP MCP browser-control surface
High
GHSA-7hgr-7h44-33w2
was published
for
camofox-mcp
(npm)
May 19, 2026
9router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
Critical
CVE-2026-46339
was published
for
9router
(npm)
May 19, 2026
Neotoma: Unauthenticated Inspector/API access via reverse-proxy loopback auth bypass
Moderate
CVE-2026-45577
was published
for
neotoma
(npm)
May 18, 2026
SillyTavern has Authentication Bypass via SSO Header Injection
Critical
CVE-2026-44649
was published
for
sillytavern
(npm)
May 12, 2026
OpenClaude Sandbox Bypass via Model-Controlled `dangerouslyDisableSandbox` Input
Critical
CVE-2026-42074
was published
for
openclaude
(npm)
May 12, 2026
@yoda.digital/gitlab-mcp-server's SSE transport has no authentication and wildcard CORS, exposing all 86 GitLab tools
High
CVE-2026-44895
was published
for
@yoda.digital/gitlab-mcp-server
(npm)
May 9, 2026
Cline Kanban Server has a Cross-Origin WebSocket Hijacking Vulnerability
Critical
CVE-2026-44211
was published
for
cline
(npm)
May 8, 2026
Network-AI missing authentication on MCP HTTP endpoint, which allows unauthenticated privileged tool calls
High
CVE-2026-42856
was published
for
network-ai
(npm)
May 5, 2026
engram: HTTP server CORS wildcard + auth-off-by-default enables CSRF graph exfiltration and persistent indirect prompt injection
High
GHSA-2r2p-4cgf-hv7h
was published
for
engramx
(npm)
Apr 22, 2026
OpenClaw: Sandbox noVNC helper route exposed interactive browser session credentials
Moderate
GHSA-92jp-89mq-4374
was published
for
openclaw
(npm)
Apr 17, 2026
Paperclip: Unauthenticated Access to Multiple API Endpoints in Authenticated Mode
High
GHSA-xfqj-r5qw-8g4j
was published
for
@paperclipai/server
(npm)
Apr 16, 2026
Flowise: Unauthenticated OAuth 2.0 Access Token Disclosure via Public Chatflow in Flowise
High
CVE-2026-41273
was published
for
flowise
(npm)
Apr 16, 2026
Flowise: Unauthenticated Information Disclosure of OAuth Secrets (Cleartext) via GET Request
Moderate
GHSA-6pcv-j4jx-m4vx
was published
for
flowise
(npm)
Apr 16, 2026
n8n-mcp has unauthenticated session termination and information disclosure in HTTP transport
High
GHSA-75hx-xj24-mqrw
was published
for
n8n-mcp
(npm)
Apr 10, 2026
Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket
High
CVE-2026-39363
was published
for
vite
(npm)
Apr 6, 2026
Signal K Server: Unauthenticated Source Priorities Manipulation
Moderate
CVE-2026-33951
was published
for
signalk-server
(npm)
Apr 3, 2026
@grackle-ai/powerline Runs Without Authentication by Default
Moderate
GHSA-xq7h-vwjp-5vrh
was published
for
@grackle-ai/powerline
(npm)
Mar 25, 2026
Duplicate Advisory: OpenClaw: BlueBubbles beta plugin webhook auth hardening (remove passwordless fallback)
Moderate
GHSA-vh4c-j2xv-9pv9
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
Duplicate Advisory: OpenClaw's andbox browser noVNC observer lacked VNC authentication
High
GHSA-cxcw-jm67-3wwp
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
MCP Connect has unauthenticated remote OS command execution via /bridge endpoint
Critical
GHSA-wvr4-3wq4-gpc5
was published
for
mcp-bridge
(npm)
Mar 19, 2026
Parse Server's GraphQL WebSocket endpoint bypasses security middleware
Moderate
CVE-2026-32594
was published
for
parse-server
(npm)
Mar 13, 2026
Dagu: SSE Authentication Bypass in Basic Auth Mode
High
CVE-2026-31882
was published
for
dagu
(npm)
Mar 13, 2026
Flowise Missing Authentication on NVIDIA NIM Endpoints
High
CVE-2026-30824
was published
for
flowise
(npm)
Mar 6, 2026
OpenClaw Loopback CDP probe can leak Gateway token to local listener
Moderate
CVE-2026-22174
was published
for
openclaw
(npm)
Mar 3, 2026
ProTip!
Advisories are also available from the
GraphQL API