Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7,257 advisories

Loading
Mermaid configuration APIs allow prototype pollution Low
CVE-2026-71438 was published for mermaid (npm) Aug 6, 2026
Str1ckl4nd Credited to Str1ckl4nd, Zyy0530, 7thParkk, mauriceng98, and aloisklink Zyy0530 Zyy0530
7thParkk 7thParkk mauriceng98 mauriceng98 aloisklink aloisklink
Mermaid allows CSS injection applying to sibling elements of the diagram Moderate
CVE-2026-50159 was published for mermaid (npm) Aug 6, 2026
h3ri0s Credited to h3ri0s and aloisklink aloisklink aloisklink
Mermaid Architecture diagrams are vulnerable to prototype pollution Moderate
CVE-2026-71437 was published for mermaid (npm) Aug 6, 2026
ThomasRinsma Credited to ThomasRinsma, jkim-notion, and aloisklink jkim-notion jkim-notion
aloisklink aloisklink
Mermaid XY Charts are vulnerable to an infinite loop DoS Moderate
CVE-2026-71436 was published for mermaid (npm) Aug 6, 2026
aloisklink Credited to aloisklink
dinhvaren Credited to dinhvaren
Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host Critical
CVE-2026-71319 was published for @nuxt/devtools (npm) Aug 5, 2026
TazmiDev Credited to TazmiDev and anzuukino anzuukino anzuukino
Nuxt: Unauthorized Component Instantiation via Server Island Props Moderate
CVE-2026-71318 was published for nuxt (npm) Aug 5, 2026
quantumshiro Credited to quantumshiro
Pig-Tail Credited to Pig-Tail, sec-reex, and DavidCarliez sec-reex sec-reex
DavidCarliez DavidCarliez
manop55555 Credited to manop55555
Electron: Sandboxed iframes can launch external protocol handlers Moderate
CVE-2026-70612 was published for electron (npm) Aug 5, 2026
Electron: DevTools embedder handler executes arbitrary files via shell open Moderate
CVE-2026-70611 was published for electron (npm) Aug 5, 2026
Electron: contextBridge object copy honors prototype setters Moderate
CVE-2026-70610 was published for electron (npm) Aug 5, 2026
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter Moderate
CVE-2026-70609 was published for electron (npm) Aug 5, 2026
hackerman70000 Credited to hackerman70000
Ciarands Credited to Ciarands
Electron: window.open features string controls some window options considered privileged Moderate
CVE-2026-70607 was published for electron (npm) Aug 5, 2026
Electron: ProtocolResponse.url reuses the default session cache instead of the registering session Moderate
CVE-2026-70606 was published for electron (npm) Aug 5, 2026
rushitgit Credited to rushitgit
Electron: HTTP redirect followed into local file loader Moderate
CVE-2026-70605 was published for electron (npm) Aug 5, 2026
Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads High
CVE-2026-70604 was published for electron (npm) Aug 5, 2026
proxydom Credited to proxydom
Electron: Extension tab APIs operate across session boundaries Moderate
CVE-2026-70602 was published for electron (npm) Aug 5, 2026
Electron: shell.openPath path validation bypass via embedded null byte Moderate
CVE-2026-70603 was published for electron (npm) Aug 5, 2026
yassine-doyensec Credited to yassine-doyensec, ikkisoft, and maxence-Doyensec ikkisoft ikkisoft
maxence-Doyensec maxence-Doyensec
Electron: Context isolation bypass via Function.prototype.bind hijack High
CVE-2026-70601 was published for electron (npm) Aug 5, 2026
Electron: Cross-origin iframe can position native autofill popup Low
CVE-2026-70600 was published for electron (npm) Aug 5, 2026
Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin Moderate
CVE-2026-70599 was published for electron (npm) Aug 5, 2026
offset Credited to offset
ProTip! Advisories are also available from the GraphQL API