Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

866 advisories

Loading
PDF.js: Arbitrary JavaScript execution upon opening a malicious PDF High
CVE-2026-16633 was published for pdfjs-dist (npm) Aug 6, 2026
wlayzz Credited to wlayzz
Ghost: Cross-Site Scripting in Feature Image Captions Moderate
CVE-2026-70596 was published for ghost (npm) Aug 5, 2026
itamarperetz Credited to itamarperetz
XSS in Ghost's ActivityPub client High
CVE-2026-53950 was published for @tryghost/activitypub (npm) Aug 4, 2026
bgeesaman Credited to bgeesaman
Ghost: Cross-Site Scripting in Universal Import Moderate
CVE-2026-70588 was published for ghost (npm) Aug 4, 2026
Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes High
CVE-2026-69151 was published for @angular/compiler (npm) Aug 3, 2026
Hexix23 Credited to Hexix23, alan-agius4, and JeanMeche alan-agius4 alan-agius4
JeanMeche JeanMeche
Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS) High
CVE-2026-69149 was published for @angular/platform-server (npm) Aug 3, 2026
SkyZeroZx Credited to SkyZeroZx and alan-agius4 alan-agius4 alan-agius4
@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag High
CVE-2026-53608 was published for @apostrophecms/seo (npm) Jul 31, 2026
H3xV0rT3x Credited to H3xV0rT3x
Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier High
CVE-2026-58263 was published for jodit (npm) Jul 31, 2026
koyokr Credited to koyokr
koyokr Credited to koyokr
Trix: Stored XSS via HTMLParser attribute injection on paste Moderate
GHSA-53g2-mvcc-q9x3 was published for action_text-trix (RubyGems) Jul 24, 2026
newbiefromcoma Credited to newbiefromcoma
React Router: RSCErrorHandler Missing Protocol Validation (XSS) Moderate
CVE-2026-53667 was published for react-router (npm) Jul 23, 2026
unknownhad Credited to unknownhad
DOMPurify is vulnerable to mutation-XSS via Re-Contextualization Moderate
CVE-2026-65914 was published for dompurify (npm) Mar 27, 2026
researchatfluidattacks Credited to researchatfluidattacks, caverav, and tachote caverav caverav
tachote tachote
IamLeandrooooo Credited to IamLeandrooooo
trace37labs Credited to trace37labs and EchoTydes EchoTydes EchoTydes
n8n: Stored DOM XSS via Resource Locator `cachedResultUrl` High
CVE-2026-65592 was published for n8n (npm) Jul 22, 2026
odgrso Credited to odgrso
Duplicate Advisory: Stored DOM XSS via Resource Locator `cachedResultUrl` High
GHSA-h5xr-fqvj-253p was published for n8n (npm) Jul 22, 2026 withdrawn
Malayke Credited to Malayke
n8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview High
CVE-2026-65597 was published for n8n (npm) Jul 22, 2026
odgrso Credited to odgrso
Duplicate Advisory: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview High
GHSA-vhcw-f978-xjjg was published for n8n (npm) Jul 22, 2026 withdrawn
Malayke Credited to Malayke
SVGO removeScripts plugin leaves some executable scripts intact High
GHSA-2p49-hgcm-8545 was published for svgo (npm) Jul 21, 2026
Admu-Dev Credited to Admu-Dev
DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements. Low
GHSA-c2j3-45gr-mqc4 was published for dompurify (npm) Jul 21, 2026
Rikuxx0 Credited to Rikuxx0
Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility Moderate
CVE-2026-59895 was published for hono (npm) Jul 21, 2026
a-tt-om Credited to a-tt-om and teebow1e teebow1e teebow1e
thientd Credited to thientd
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands Low
CVE-2026-59727 was published for astro (npm) Jul 20, 2026
jlgore Credited to jlgore
ProTip! Advisories are also available from the GraphQL API