GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
298 advisories
Filter by severity
@payloadcms/plugin-multi-tenant has a cross-tenant create issue
Moderate
CVE-2026-105864
was published
for
@payloadcms/plugin-multi-tenant
(npm)
Oct 7, 2026
Ghost: Editors Could Promote Staff Users to Their Own Role
Moderate
CVE-2026-105678
was published
for
ghost
(npm)
Oct 7, 2026
Backstage: Inconsistent credential enforcement for overlapping proxy routes
Moderate
CVE-2026-106456
was published
for
@backstage/plugin-proxy-backend
(npm)
Oct 7, 2026
Backstage: Inconsistent repository filtering in Bitbucket Server catalog event updates
Moderate
CVE-2026-106458
was published
for
@backstage/plugin-catalog-backend-module-bitbucket-server
(npm)
Oct 7, 2026
mppx-condition-gate: Free-access path grants on a self-declared wallet without proving control
High
CVE-2026-104891
was published
for
@insumermodel/mppx-condition-gate
(npm)
Oct 7, 2026
Backstage has incorrect authorization in search engine permission filtering
Moderate
CVE-2026-106562
was published
for
@backstage/plugin-search-backend
(npm)
Oct 7, 2026
Backstage has a sensitive information disclosure in Kubernetes resource queries
Moderate
CVE-2026-106561
was published
for
@backstage/plugin-kubernetes-backend
(npm)
Oct 7, 2026
Backstage's scaffolder credential handling may allow unintended GitHub authentication fallback
Moderate
CVE-2026-106462
was published
for
@backstage/plugin-scaffolder-backend
(npm)
Oct 7, 2026
Backstage has improper authorization in GitLab organizational user ingestion
Moderate
CVE-2026-106463
was published
for
@backstage/plugin-catalog-backend-module-gitlab
(npm)
Oct 7, 2026
Backstage: Improper preservation of access restrictions during service credential delegation
High
CVE-2026-106492
was published
for
@backstage/backend-defaults
(npm)
Oct 7, 2026
Backstage: Inconsistent enforcement of allowed location types during catalog processing
Low
CVE-2026-106496
was published
for
@backstage/plugin-catalog-backend
(npm)
Oct 7, 2026
Backstage: Improper URL validation in catalog entity placeholder resolution
High
CVE-2026-106498
was published
for
@backstage/plugin-catalog-backend
(npm)
Oct 7, 2026
Backstage: Incorrect authorization in scaffolder task listing
Moderate
CVE-2026-106461
was published
for
@backstage/plugin-scaffolder-backend
(npm)
Oct 7, 2026
Actual Sync Server: CORS Proxy GitHub API Allowlist Prefix Bypass Leaks Private Repositories Through the Server GitHub Token
High
CVE-2026-57449
was published
for
@actual-app/sync-server
(npm)
Oct 7, 2026
Payload: Field access control bypass on auth collections
Critical
CVE-2026-105851
was published
for
payload
(npm)
Oct 6, 2026
Payload: Sort queries could expose protected field information
Moderate
CVE-2026-105805
was published
for
payload
(npm)
Oct 6, 2026
OpenClaw: Channel read actions could skip target allowlists
Moderate
GHSA-g7fw-3gjp-g5hf
was published
for
@openclaw/feishu
(npm)
Oct 5, 2026
vm2: NodeVM custom resolution bypasses external path boundaries
Critical
CVE-2026-100721
was published
for
vm2
(npm)
Oct 5, 2026
vm2 Custom Module Resolver Can Bypass the External Package Allowlist by Loading a Colliding Host Package
Critical
CVE-2026-92951
was published
for
vm2
(npm)
Oct 1, 2026
vm2: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted
Moderate
CVE-2026-92945
was published
for
vm2
(npm)
Oct 1, 2026
@grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for case-insensitive matches
Moderate
CVE-2026-101914
was published
for
@grpc/grpc-js-xds
(npm)
Sep 28, 2026
Duplicate Advisory: vm2: NodeVM custom resolution bypasses external path boundaries
Critical
GHSA-c9wr-qm7p-p6vc
was published
for
vm2
(npm)
Sep 27, 2026
•
withdrawn
Knowns Unrestricted Path Traversal leading to out-of-bounds arbitrary .md file read, write, and deletion in MCP Docs + Memory Tools
High
CVE-2026-86439
was published
for
knowns
(npm)
Sep 25, 2026
@bytebase/dbhub's read-only mode does not prevent database writes
High
CVE-2026-61788
was published
for
@bytebase/dbhub
(npm)
Sep 24, 2026
Unleash: A project member can reorder activation strategies belonging to any other project / environment (cross-project integrity write), bypassing project RBAC and the audit log
Moderate
CVE-2026-77425
was published
for
unleash-server
(npm)
Sep 22, 2026
ProTip!
Advisories are also available from the
GraphQL API