Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

298 advisories

Loading
@payloadcms/plugin-multi-tenant has a cross-tenant create issue Moderate
CVE-2026-105864 was published for @payloadcms/plugin-multi-tenant (npm) Oct 7, 2026
valmet083 Credited to valmet083
Ghost: Editors Could Promote Staff Users to Their Own Role Moderate
CVE-2026-105678 was published for ghost (npm) Oct 7, 2026
Santoshkumarpuppala Credited to Santoshkumarpuppala and nhattanhh nhattanhh nhattanhh
Backstage: Inconsistent credential enforcement for overlapping proxy routes Moderate
CVE-2026-106456 was published for @backstage/plugin-proxy-backend (npm) Oct 7, 2026
Backstage: Inconsistent repository filtering in Bitbucket Server catalog event updates Moderate
CVE-2026-106458 was published for @backstage/plugin-catalog-backend-module-bitbucket-server (npm) Oct 7, 2026
mppx-condition-gate: Free-access path grants on a self-declared wallet without proving control High
CVE-2026-104891 was published for @insumermodel/mppx-condition-gate (npm) Oct 7, 2026
chenshj73 Credited to chenshj73
Backstage has incorrect authorization in search engine permission filtering Moderate
CVE-2026-106562 was published for @backstage/plugin-search-backend (npm) Oct 7, 2026
Backstage has a sensitive information disclosure in Kubernetes resource queries Moderate
CVE-2026-106561 was published for @backstage/plugin-kubernetes-backend (npm) Oct 7, 2026
Backstage's scaffolder credential handling may allow unintended GitHub authentication fallback Moderate
CVE-2026-106462 was published for @backstage/plugin-scaffolder-backend (npm) Oct 7, 2026
Backstage has improper authorization in GitLab organizational user ingestion Moderate
CVE-2026-106463 was published for @backstage/plugin-catalog-backend-module-gitlab (npm) Oct 7, 2026
Backstage: Improper preservation of access restrictions during service credential delegation High
CVE-2026-106492 was published for @backstage/backend-defaults (npm) Oct 7, 2026
Backstage: Inconsistent enforcement of allowed location types during catalog processing Low
CVE-2026-106496 was published for @backstage/plugin-catalog-backend (npm) Oct 7, 2026
Backstage: Improper URL validation in catalog entity placeholder resolution High
CVE-2026-106498 was published for @backstage/plugin-catalog-backend (npm) Oct 7, 2026
Backstage: Incorrect authorization in scaffolder task listing Moderate
CVE-2026-106461 was published for @backstage/plugin-scaffolder-backend (npm) Oct 7, 2026
xIllunight Credited to xIllunight and MatissJanis MatissJanis MatissJanis
Payload: Field access control bypass on auth collections Critical
CVE-2026-105851 was published for payload (npm) Oct 6, 2026
Zerotistic Credited to Zerotistic
Payload: Sort queries could expose protected field information Moderate
CVE-2026-105805 was published for payload (npm) Oct 6, 2026
braintxx Credited to braintxx
OpenClaw: Channel read actions could skip target allowlists Moderate
GHSA-g7fw-3gjp-g5hf was published for @openclaw/feishu (npm) Oct 5, 2026
qc9c Credited to qc9c
vm2: NodeVM custom resolution bypasses external path boundaries Critical
CVE-2026-100721 was published for vm2 (npm) Oct 5, 2026
rexpository Credited to rexpository
XlabAITeam Credited to XlabAITeam, keenanwgn, pkuGenuine, and liangjs keenanwgn keenanwgn
pkuGenuine pkuGenuine liangjs liangjs
arpitjain099 Credited to arpitjain099
@grpc/grpc-js: The exact path match matcher incorrectly only applies a prefix match for case-insensitive matches Moderate
CVE-2026-101914 was published for @grpc/grpc-js-xds (npm) Sep 28, 2026
manqingzhou Credited to manqingzhou
Duplicate Advisory: vm2: NodeVM custom resolution bypasses external path boundaries Critical
GHSA-c9wr-qm7p-p6vc was published for vm2 (npm) Sep 27, 2026 • withdrawn
uziii2208 Credited to uziii2208 and hoanggxyuuki hoanggxyuuki hoanggxyuuki
@bytebase/dbhub's read-only mode does not prevent database writes High
CVE-2026-61788 was published for @bytebase/dbhub (npm) Sep 24, 2026
ixNyf Credited to ixNyf
ProTip! Advisories are also available from the GraphQL API