GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,506
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
573 advisories
Filter by severity
Ghost: Cross-Site Scripting in Feature Image Captions
Moderate
CVE-2026-70596
was published
for
ghost
(npm)
Aug 5, 2026
Ghost: Cross-Site Scripting in Universal Import
Moderate
CVE-2026-70588
was published
for
ghost
(npm)
Aug 4, 2026
sanitize-html has incomplete URI scheme validation in that allows javascript: URIs through action, formaction, data, poster, and background attributes
Moderate
CVE-2026-53606
was published
for
sanitize-html
(npm)
Jul 31, 2026
Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement href check that allows link XSS
Moderate
CVE-2026-62324
was published
for
jodit
(npm)
Jul 31, 2026
Trix: Stored XSS via HTMLParser attribute injection on paste
Moderate
GHSA-53g2-mvcc-q9x3
was published
for
action_text-trix
(RubyGems)
Jul 24, 2026
React Router: RSCErrorHandler Missing Protocol Validation (XSS)
Moderate
CVE-2026-53667
was published
for
react-router
(npm)
Jul 23, 2026
Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
Moderate
CVE-2026-59895
was published
for
hono
(npm)
Jul 21, 2026
Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
Moderate
CVE-2026-59729
was published
for
astro
(npm)
Jul 20, 2026
Astro: Reflected XSS via unescaped View Transition animation properties
Moderate
GHSA-4g3v-8h47-v7g6
was published
for
astro
(npm)
Jul 20, 2026
@asymmetric-effort/specifyjs: CSS expression sanitization is bypassable in renderToString
Moderate
CVE-2026-50290
was published
for
@asymmetric-effort/specifyjs
(npm)
Jul 2, 2026
devbridge-autocomplete has XSS in its default formatters: formatGroup and formatResult fail to escape HTML in untrusted inputs
Moderate
GHSA-hvqh-jw65-wcpq
was published
for
devbridge-autocomplete
(npm)
Jun 22, 2026
Outerbase Studio: Stored XSS in Text Widget Leads to Authentication Token Exposure
Moderate
CVE-2026-55650
was published
for
@outerbase/studio
(npm)
Jun 19, 2026
OpenClaw: Exported session HTML could keep unsafe markdown links
Moderate
CVE-2026-53841
was published
for
openclaw
(npm)
Jun 18, 2026
DOMPurify: Permanent `ALLOWED_ATTR` pollution via `setConfig()` bypassing the hook clone-guard (incomplete fix of the 3.4.7 hook-pollution patch)
Moderate
CVE-2026-65898
was published
for
dompurify
(npm)
Jun 18, 2026
TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes
Moderate
CVE-2026-55661
was published
for
@tinacms/mdx
(npm)
Jun 18, 2026
NocoDB: Stored Cross-Site Scripting via Secure Attachment
Moderate
CVE-2026-53929
was published
for
nocodb
(npm)
Jun 17, 2026
n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints
Moderate
CVE-2026-54303
was published
for
n8n
(npm)
Jun 16, 2026
Astro: XSS via Unescaped Attribute Names in Spread Props
Moderate
CVE-2026-54298
was published
for
astro
(npm)
Jun 16, 2026
Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL
Moderate
CVE-2026-53722
was published
for
nuxt
(npm)
Jun 16, 2026
Nuxt: URL-handling weaknesses in `navigateTo` and `reloadNuxtApp`: SSR open redirect, client-side script execution via the `open` option, and protocol-relative bypass in `reloadNuxtApp`
Moderate
CVE-2026-56326
was published
for
nuxt
(npm)
Jun 16, 2026
DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <template>.content
Moderate
CVE-2026-49978
was published
for
dompurify
(npm)
Jun 15, 2026
DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks
Moderate
CVE-2026-49458
was published
for
dompurify
(npm)
Jun 15, 2026
DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM
Moderate
CVE-2026-49459
was published
for
dompurify
(npm)
Jun 15, 2026
@angular/compiler: Two-Way Property Binding Sanitization Bypass (XSS)
Moderate
CVE-2026-54265
was published
for
@angular/compiler
(npm)
Jun 15, 2026
Angular: Template and Attribute Namespace Sanitization Bypass (XSS)
Moderate
CVE-2026-50557
was published
for
@angular/compiler
(npm)
Jun 15, 2026
ProTip!
Advisories are also available from the
GraphQL API