Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,549 advisories

Loading
Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints Moderate
CVE-2026-55156 was published for @ooples/token-optimizer-mcp (npm) Aug 14, 2026
232-323 Credited to 232-323
hashi-vault-js: Vault token and secret values exposed in thrown errors Moderate
CVE-2026-55102 was published for hashi-vault-js (npm) Aug 13, 2026
Sebasteuo Credited to Sebasteuo
ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header Moderate
CVE-2026-55087 was published for ep_etherpad-lite (npm) Aug 13, 2026
Duplicate Advisory: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint Moderate
GHSA-4jjw-pwvw-q6w3 was published for nuxt (npm) Aug 11, 2026 withdrawn
antonisloukis Credited to antonisloukis
Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure Moderate
CVE-2026-71850 was published for hono (npm) Aug 7, 2026
raster0x2a Credited to raster0x2a
Hono: Algorithmic Complexity DoS in Language Middleware Moderate
CVE-2026-71848 was published for hono (npm) Aug 7, 2026
SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header Moderate
CVE-2026-66062 was published for @sveltejs/kit (npm) Aug 7, 2026
Saku0512 Credited to Saku0512
DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS Moderate
GHSA-55q2-fjhq-7xh7 was published for dompurify (npm) Aug 7, 2026
koyokr Credited to koyokr
Mermaid radar diagrams are vulnerable to DoS Moderate
CVE-2026-71439 was published for mermaid (npm) Aug 6, 2026
aloisklink Credited to aloisklink
Mermaid allows CSS injection applying to sibling elements of the diagram Moderate
CVE-2026-50159 was published for mermaid (npm) Aug 6, 2026
h3ri0s Credited to h3ri0s and aloisklink aloisklink aloisklink
Mermaid Architecture diagrams are vulnerable to prototype pollution Moderate
CVE-2026-71437 was published for mermaid (npm) Aug 6, 2026
ThomasRinsma Credited to ThomasRinsma, jkim-notion, and aloisklink jkim-notion jkim-notion
aloisklink aloisklink
Mermaid XY Charts are vulnerable to an infinite loop DoS Moderate
CVE-2026-71436 was published for mermaid (npm) Aug 6, 2026
aloisklink Credited to aloisklink
Nuxt: Unauthorized Component Instantiation via Server Island Props Moderate
CVE-2026-71318 was published for nuxt (npm) Aug 5, 2026
Electron: Sandboxed iframes can launch external protocol handlers Moderate
CVE-2026-70612 was published for electron (npm) Aug 5, 2026
Electron: DevTools embedder handler executes arbitrary files via shell open Moderate
CVE-2026-70611 was published for electron (npm) Aug 5, 2026
Electron: contextBridge object copy honors prototype setters Moderate
CVE-2026-70610 was published for electron (npm) Aug 5, 2026
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter Moderate
CVE-2026-70609 was published for electron (npm) Aug 5, 2026
hackerman70000 Credited to hackerman70000
Electron: window.open features string controls some window options considered privileged Moderate
CVE-2026-70607 was published for electron (npm) Aug 5, 2026
Electron: ProtocolResponse.url reuses the default session cache instead of the registering session Moderate
CVE-2026-70606 was published for electron (npm) Aug 5, 2026
rushitgit Credited to rushitgit
Electron: HTTP redirect followed into local file loader Moderate
CVE-2026-70605 was published for electron (npm) Aug 5, 2026
ProTip! Advisories are also available from the GraphQL API