Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

363 advisories

Loading
Vikunja: Write-level project members can delete admin-tier link shares through an unloaded permission check Moderate
GHSA-fmmf-xq98-g327 was published for code.vikunja.io/api (Go) Oct 9, 2026
Vikunja: Webhooks and link shares survive every revocation path, so a removed collaborator keeps a live feed Moderate
GHSA-hjx8-qv73-f7cm was published for code.vikunja.io/api (Go) Oct 9, 2026
euriconicacio Credited to euriconicacio and Tan-JunWei Tan-JunWei Tan-JunWei
Vikunja: Saved filter creation with an empty filter string recalculates task positions across all tenants Moderate
GHSA-fprf-r6rv-xg99 was published for code.vikunja.io/api (Go) Oct 9, 2026
Tan-JunWei Credited to Tan-JunWei
Vikunja: Link-share token can enumerate users through the v2 API Moderate
CVE-2026-91981 was published for code.vikunja.io/api (Go) Oct 9, 2026
0xcelien Credited to 0xcelien
Vikunja: API token scopes bypassed via task expand parameter (comments, reactions, time entry counts) Moderate
CVE-2026-91983 was published for code.vikunja.io/api (Go) Oct 9, 2026
ybsun0215 Credited to ybsun0215 and JellowBeanz26 JellowBeanz26 JellowBeanz26
manus-use Credited to manus-use
Vikunja: Link-share token reads any tenant's kanban buckets and enumerates usernames/IDs instance-wide (BOLA) Critical
CVE-2026-68582 was published for code.vikunja.io/api (Go) Oct 9, 2026
Vikunja: Link-share principal ID collision allows cross-account API token issuance and management High
CVE-2026-68581 was published for code.vikunja.io/api (Go) Oct 9, 2026
ryuyunseong Credited to ryuyunseong
Shirshakhtml Credited to Shirshakhtml
SiYuan discloses an administrator's open documents and search terms to anonymous readers Moderate
CVE-2026-72788 was published for github.com/siyuan-note/siyuan/kernel (Go) Oct 1, 2026
Shirshakhtml Credited to Shirshakhtml
mabdullah22 Credited to mabdullah22
Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter Moderate
CVE-2026-88978 was published for github.com/hatchet-dev/hatchet (Go) Sep 22, 2026
d3do-23 Credited to d3do-23
Gardener: Authorization Bypass via Group Subject Injection Moderate
CVE-2026-79767 was published for gardener/gardener (Go) Sep 22, 2026
dnny-13 Credited to dnny-13
OpenBao Skips Stricter Deny Policy for LIST operations Moderate
CVE-2026-63131 was published for github.com/openbao/openbao (Go) Sep 22, 2026
babakizo420 Credited to babakizo420
OpenBao's Templated Policies Allow Privilege Escalation via Wildcard Characters High
CVE-2026-71543 was published for github.com/openbao/openbao (Go) Sep 22, 2026
Hatchet: Cross-Tenant Durable Task Event Log Disclosure via Missing Authorization Check Moderate
CVE-2026-63342 was published for github.com/hatchet-dev/hatchet (Go) Sep 22, 2026
sfwani Credited to sfwani
Obot: MCP Registry API readable without authentication Moderate
GHSA-pr6h-vr44-xq8j was published for github.com/obot-platform/obot (Go) Sep 18, 2026
hewei-gikaku Credited to hewei-gikaku
Obot: OAuth Dynamic Client Registration Enables API Token Theft via Audience Confusion High
GHSA-xwmw-prc4-v3cr was published for github.com/obot-platform/obot (Go) Sep 18, 2026
EQSTLab Credited to EQSTLab and min8282 min8282 min8282
Capsule: Tenant owner bypasses Capsule's forbidden namespace/service/node label and annotation enforcement High
CVE-2026-61672 was published for github.com/projectcapsule/capsule (Go) Sep 18, 2026
5ud0er Credited to 5ud0er
Pig-Tail Credited to Pig-Tail
Duplicate Advisory: Vikunja: API token scopes bypassed via task expand parameter (comments, reactions, time entry counts) Moderate
GHSA-phph-c358-5mwm was published for code.vikunja.io/api (Go) Sep 15, 2026 • withdrawn
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization High
CVE-2026-88008 was published for github.com/traefik/traefik/v2 (Go) Sep 10, 2026
ihopenre-eng Credited to ihopenre-eng
ProTip! Advisories are also available from the GraphQL API