Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

8 advisories

Loading
Handlebars: JavaScript Injection via AST Type Confusion in compile (bypass of CVE-2026-33937) Critical
CVE-2026-106446 was published for handlebars (npm) Oct 8, 2026
ndelphit Credited to ndelphit, bhaswanthc, dinhvaren, jmoritzc53, n0tra4e, hibrian827, sondt99, nikolakojic-rasit, Ahmed-Elmahgob, vk-can, PellaML, shenhuanageshei, kagebunsher, kustundag, ffasterss, and sanmatte bhaswanthc bhaswanthc
dinhvaren dinhvaren jmoritzc53 jmoritzc53 n0tra4e n0tra4e hibrian827 hibrian827 sondt99 sondt99 nikolakojic-rasit nikolakojic-rasit Ahmed-Elmahgob Ahmed-Elmahgob vk-can vk-can PellaML PellaML shenhuanageshei shenhuanageshei kagebunsher kagebunsher kustundag kustundag ffasterss ffasterss sanmatte sanmatte
simple-git allows command execution through unblocked Git configuration includes High
CVE-2026-102826 was published for simple-git (npm) Oct 5, 2026
bhaswanthc Credited to bhaswanthc and NotAFlightRisk NotAFlightRisk NotAFlightRisk
xmldom: Processing Instruction Target Injection Bypasses requireWellFormed High
CVE-2026-83616 was published for @xmldom/xmldom (npm) Sep 8, 2026
bhaswanthc Credited to bhaswanthc and arpitjain099 arpitjain099 arpitjain099
xmldom: Element name injection via createElement() bypasses requireWellFormed High
CVE-2026-83607 was published for @xmldom/xmldom (npm) Sep 8, 2026
bhaswanthc Credited to bhaswanthc
xmldom: Attribute name injection via setAttribute() bypasses requireWellFormed High
CVE-2026-83605 was published for @xmldom/xmldom (npm) Sep 8, 2026
bhaswanthc Credited to bhaswanthc
manus-use Credited to manus-use and bhaswanthc bhaswanthc bhaswanthc
Multer vulnerable to Denial of Service via incomplete cleanup of aborted uploads Moderate
CVE-2026-5038 was published for multer (npm) Jun 17, 2026
yuki-matsuhashi Credited to yuki-matsuhashi, HamdaanAliQuatil, fasrm, UlisesGascon, bjohansebas, 0xStraw-Hat, bhaswanthc, ByamB4, sbouabid-sec, DavidCarliez, and JebeenLee HamdaanAliQuatil HamdaanAliQuatil
fasrm fasrm UlisesGascon UlisesGascon bjohansebas bjohansebas 0xStraw-Hat 0xStraw-Hat bhaswanthc bhaswanthc ByamB4 ByamB4 sbouabid-sec sbouabid-sec DavidCarliez DavidCarliez JebeenLee JebeenLee
fast-jwt: JWT auth bypass due to empty HMAC secret accepted by async key resolver Critical
CVE-2026-44351 was published for fast-jwt (npm) May 6, 2026
bhaswanthc Credited to bhaswanthc and SociableSteve SociableSteve SociableSteve
ProTip! Advisories are also available from the GraphQL API