GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
50
GitHub Actions
50
Go
3,673
Maven
5,000+
npm
5,000+
NuGet
932
pip
4,891
Pub
13
RubyGems
1,051
Rust
1,315
Swift
53
Unreviewed advisories
All unreviewed
5,000+
6,000 advisories
Filter by severity
sse-channel: SSE Injection via unsanitized event fields
Moderate
CVE-2026-44217
was published
for
sse-channel
(npm)
May 5, 2026
ip-address has XSS in Address6 HTML-emitting methods
Moderate
CVE-2026-42338
was published
for
ip-address
(npm)
May 5, 2026
Mongoose's Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection
High
CVE-2026-42334
was published
for
mongoose
(npm)
May 5, 2026
@evomap/evolver's validator sandbox allowlist permits `npm`/`npx`, yielding RCE from Hub-delivered validation tasks via lifecycle scripts
High
GHSA-jxh8-jh77-xh6g
was published
for
@evomap/evolver
(npm)
May 5, 2026
@evomap/evolver has an unbounded request body in proxy /asset/submit that causes persistent disk-exhaustion DoS
Moderate
GHSA-7xp7-m392-h92c
was published
for
@evomap/evolver
(npm)
May 5, 2026
@evomap/evolver: Path Traversal in `evolver fetch` default-branch `safeId` allows Hub-controlled overwrite of project files (RCE)
High
GHSA-cfcj-hqpf-hccf
was published
for
@evomap/evolver
(npm)
May 5, 2026
MagicMirror vulnerable to unauthenticated SSRF via /cors endpoint
Critical
CVE-2026-42281
was published
for
magicmirror
(npm)
May 5, 2026
open-websearch has SSRF in `fetchWebContent` MCP tool: bracketed IPv6 literals and non-resolving hostname check bypass `isPrivateOrLocalHostname`
High
CVE-2026-42260
was published
for
open-websearch
(npm)
May 5, 2026
parse-server: MFA SMS one-time password accepted twice under concurrent login
Low
CVE-2026-43930
was published
for
parse-server
(npm)
May 5, 2026
ssrfcheck Vulnerable to Server-Side Request Forgery (SSRF) and Incomplete List of Disallowed Inputs
High
CVE-2026-43929
was published
for
ssrfcheck
(npm)
May 5, 2026
ssrfcheck: SSRF Bypass Caused by Failure to Classify Reserved IP Address Space as Invalid
High
CVE-2025-8267
was published
for
ssrfcheck
(npm)
May 5, 2026
link-preview-js vulnerable to IPv6 and internal loopback attacks
High
CVE-2026-43897
was published
for
link-preview-js
(npm)
May 5, 2026
exiftool-vendored vulnerable to argument injection via newline characters in tag names
High
CVE-2026-43893
was published
for
exiftool-vendored
(npm)
May 5, 2026
OpenClaw's gateway config mutation guard allowed unsafe model-driven config writes
High
GHSA-cwj3-vqpp-pmxr
was published
for
openclaw
(npm)
May 5, 2026
OpenClaw vulnerable to arbitrary code execution via attacker-controlled setup-api.js loaded from cwd during env-key resolution
High
GHSA-r39h-4c2p-3jxp
was published
for
openclaw
(npm)
May 5, 2026
OpenClaw's Webhooks SecretRef route secret remains valid after rotation/reload
Moderate
GHSA-q8ff-7ffm-m3r9
was published
for
openclaw
(npm)
May 5, 2026
@workos/authkit-session has an Open Redirect via state-derived redirect target
Moderate
CVE-2026-42565
was published
for
@workos/authkit-session
(npm)
May 5, 2026
@tdurieux/anonymous_github Vulnerable to XSS via Unsanitized GitHub Repository Content Rendering in Anonymous GitHub Origin
High
GHSA-g485-8j3v-p6x8
was published
for
@tdurieux/anonymous_github
(npm)
May 5, 2026
Inngest TypeScript SDK exposes environment variables via serve() handler on unhandled HTTP methods
High
CVE-2026-42047
was published
for
inngest
(npm)
May 5, 2026
LobeHub has a Cross-Site Scripting issue that escalates to Remote Code Execution
Moderate
CVE-2026-42045
was published
for
@lobehub/lobehub
(npm)
May 5, 2026
Network-AI missing authentication on MCP HTTP endpoint, which allows unauthenticated privileged tool calls
High
CVE-2026-42856
was published
for
network-ai
(npm)
May 5, 2026
VM2 Has a WASM Sandbox Escape (Node 25 only)
Critical
CVE-2026-26956
was published
for
vm2
(npm)
May 5, 2026
VM2 Has a Sandbox Escape Issue via SuppressedError
Critical
CVE-2026-26332
was published
for
vm2
(npm)
May 5, 2026
VM2 Has Sandbox Breakout Through Inspect Function
Critical
CVE-2026-24781
was published
for
vm2
(npm)
May 5, 2026
VM2 Has Sandbox Breakout Through Promise Species
Critical
CVE-2026-24120
was published
for
vm2
(npm)
May 5, 2026
ProTip!
Advisories are also available from the
GraphQL API