GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
113 advisories
Filter by severity
vm2 contains a sandbox escape vulnerability
Critical
CVE-2026-93605
was published
for
vm2
(npm)
Oct 7, 2026
vm2: Default VM can mutate host TypedArray and ArrayBuffer intrinsics after the host-prototype pollution fix
Critical
CVE-2026-92953
was published
for
vm2
(npm)
Oct 5, 2026
vm2: NodeVM `require.external` without an explicit `require.root` grants unrestricted host filesystem access and full RCE
Critical
CVE-2026-92946
was published
for
vm2
(npm)
Oct 5, 2026
vm2 sandbox escape via WebAssembly.compileStreaming Promise species bypass
Critical
CVE-2026-92956
was published
for
vm2
(npm)
Oct 5, 2026
A vulnerability was determined in Jeebase 0.0.1. This vulnerability affects the function...
Low
Unreviewed
CVE-2026-105180
was published
Oct 5, 2026
vm2: NodeVM nesting guard accepts array-shaped require and permits host RCE
Critical
CVE-2026-92935
was published
for
vm2
(npm)
Oct 1, 2026
vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector
Critical
CVE-2026-92944
was published
for
vm2
(npm)
Oct 1, 2026
Duplicate Advisory: Default VM can mutate host TypedArray and ArrayBuffer intrinsics after the host-prototype pollution fix
Critical
GHSA-5v7w-95g5-pj6q
was published
for
vm2
(npm)
Sep 17, 2026
•
withdrawn
Duplicate Advisory: Sandbox Escape (NodeVM)
Critical
GHSA-gg6f-mhqm-f7gp
was published
for
vm2
(npm)
Sep 17, 2026
•
withdrawn
Duplicate Advisory: NodeVM `require.external` without an explicit `require.root` grants unrestricted host filesystem access and full RCE
Critical
GHSA-29x6-9qh5-83gg
was published
for
vm2
(npm)
Sep 17, 2026
•
withdrawn
Duplicate Advisory: NodeVM nesting guard accepts array-shaped require and permits host RCE
Critical
GHSA-9fxx-mv6c-j5xp
was published
for
vm2
(npm)
Sep 17, 2026
•
withdrawn
A vulnerability was determined in a2ui-project a2ui up to 0.10.6. This affects the function...
Moderate
Unreviewed
CVE-2026-92217
was published
Sep 16, 2026
IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS,...
High
Unreviewed
CVE-2026-12354
was published
Sep 15, 2026
Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a client with...
High
Unreviewed
CVE-2026-65181
was published
Sep 9, 2026
A vulnerability was determined in Eleveo Quality Management 9.7.0. Impacted is an unknown...
Low
Unreviewed
CVE-2026-85408
was published
Sep 4, 2026
A security vulnerability has been detected in gouguoa up to 5.10.0/6.0.1. This vulnerability...
Low
Unreviewed
CVE-2026-84430
was published
Sep 2, 2026
Applications that evaluate Spring Expression Language (SpEL) expressions using...
Critical
Unreviewed
CVE-2026-59283
was published
Aug 27, 2026
Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173...
High
Unreviewed
CVE-2026-76023
was published
Aug 20, 2026
asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter
Moderate
GHSA-9w56-46f6-3qhx
was published
for
asteval
(pip)
Aug 20, 2026
A flaw was found in the search-v2-operator. This vulnerability allows a privileged user,...
Critical
Unreviewed
CVE-2026-71470
was published
Aug 19, 2026
vm2: Sandbox Breakout Using Dangerous Host Proto Mutators
Critical
CVE-2026-47698
was published
for
vm2
(npm)
Aug 17, 2026
LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading
Moderate
CVE-2026-48775
was published
for
langgraph-checkpoint
(pip)
Jun 25, 2026
Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API
Critical
CVE-2026-53753
was published
for
crawl4ai
(pip)
Jun 16, 2026
vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass
Critical
CVE-2026-47210
was published
for
vm2
(npm)
May 29, 2026
ProTip!
Advisories are also available from the
GraphQL API