Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,627 advisories

Loading
Vikunja: Write-level project members can delete admin-tier link shares through an unloaded permission check Moderate
GHSA-fmmf-xq98-g327 was published for code.vikunja.io/api (Go) Oct 9, 2026
Vikunja: Webhooks and link shares survive every revocation path, so a removed collaborator keeps a live feed Moderate
GHSA-hjx8-qv73-f7cm was published for code.vikunja.io/api (Go) Oct 9, 2026
euriconicacio Credited to euriconicacio and Tan-JunWei Tan-JunWei Tan-JunWei
Vikunja: Saved filter creation with an empty filter string recalculates task positions across all tenants Moderate
GHSA-fprf-r6rv-xg99 was published for code.vikunja.io/api (Go) Oct 9, 2026
Tan-JunWei Credited to Tan-JunWei
Contao: Improper access control in the table access voter Moderate
CVE-2026-107851 was published for contao/core-bundle (Composer) Oct 9, 2026
sven-jaeger-git Credited to sven-jaeger-git
Vikunja: Link-share token can enumerate users through the v2 API Moderate
CVE-2026-91981 was published for code.vikunja.io/api (Go) Oct 9, 2026
0xcelien Credited to 0xcelien
Vikunja: API token scopes bypassed via task expand parameter (comments, reactions, time entry counts) Moderate
CVE-2026-91983 was published for code.vikunja.io/api (Go) Oct 9, 2026
ybsun0215 Credited to ybsun0215 and JellowBeanz26 JellowBeanz26 JellowBeanz26
manus-use Credited to manus-use
pacioli: A submit consent marker licensed cancellation of caller-named pre-existing documents Moderate
CVE-2026-107841 was published for pacioli-guard (pip) Oct 9, 2026
Vikunja: Link-share token reads any tenant's kanban buckets and enumerates usernames/IDs instance-wide (BOLA) Critical
CVE-2026-68582 was published for code.vikunja.io/api (Go) Oct 9, 2026
Vikunja: Link-share principal ID collision allows cross-account API token issuance and management High
CVE-2026-68581 was published for code.vikunja.io/api (Go) Oct 9, 2026
ryuyunseong Credited to ryuyunseong
Strawberry GraphQL: Synchronous permission checks can treat an awaitable authorization result as truthy High
CVE-2026-107728 was published for strawberry-graphql (pip) Oct 9, 2026
Hama1cco Credited to Hama1cco and patrick91 patrick91 patrick91
rexpository Credited to rexpository
PraisonAI: Platform members can rewrite shared labels and owner issue labels without owner/admin authorization Moderate
CVE-2026-61440 was published for praisonai-platform (pip) Oct 8, 2026
rexpository Credited to rexpository
AsyncHttpClient: Pooled connections can still be shared across NTLM, Negotiate and proxy logins High
CVE-2026-107230 was published for org.asynchttpclient:async-http-client (Maven) Oct 8, 2026
ProTip! Advisories are also available from the GraphQL API