Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

280 advisories

Loading
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions Critical
CVE-2026-77415 was published for jsonata (npm) Aug 21, 2026
c0rydoras Credited to c0rydoras
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions Critical
CVE-2026-77414 was published for jsonata (npm) Aug 21, 2026
c0rydoras Credited to c0rydoras
JSONata: Arbitrary Code Execution via crafted JSONata expressions Critical
CVE-2026-77413 was published for jsonata (npm) Aug 21, 2026
peaktwilight Credited to peaktwilight and c0rydoras c0rydoras c0rydoras
Mermaid allows CSS injection applying to sibling elements of the diagram Moderate
CVE-2026-50159 was published for mermaid (npm) Aug 6, 2026
h3ri0s Credited to h3ri0s and aloisklink aloisklink aloisklink
Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host Critical
CVE-2026-71319 was published for @nuxt/devtools (npm) Aug 5, 2026
TazmiDev Credited to TazmiDev and anzuukino anzuukino anzuukino
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter Moderate
CVE-2026-70609 was published for electron (npm) Aug 5, 2026
hackerman70000 Credited to hackerman70000
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability Critical
CVE-2026-70477 was published for flowise (npm) Aug 4, 2026
zdi-disclosures Credited to zdi-disclosures
amwhoi Credited to amwhoi
Flowise RCE via SQLite Record Manager Node Critical
CVE-2026-69259 was published for flowise (npm) Aug 4, 2026
alex-elttam Credited to alex-elttam
Flowise: Remote Code Execution Vulnerability in CSVAgent Critical
CVE-2026-69256 was published for flowise (npm) Aug 4, 2026
jia-elttam Credited to jia-elttam
Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified Critical
CVE-2026-69255 was published for flowise (npm) Aug 4, 2026
lexi-core-ai Credited to lexi-core-ai
Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override Critical
CVE-2026-69254 was published for flowise (npm) Aug 4, 2026
akshat-sj Credited to akshat-sj
Flowise RCE via TypeORM DataSource Critical
CVE-2026-69251 was published for flowise (npm) Aug 4, 2026
alex-elttam Credited to alex-elttam
AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping High
CVE-2026-11393 was published for @aws/agentcore (npm) Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies High
CVE-2026-54666 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
swagger-typescript-api vulnerable to code injection via unescaped enum string values High
CVE-2026-54664 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template High
CVE-2026-54661 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template High
CVE-2026-54662 was published for swagger-typescript-api (npm) Jul 29, 2026
thegr1ffyn Credited to thegr1ffyn
Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer Critical
GHSA-w28w-gp39-m4p6 was published for @prompty/core (npm) Jul 24, 2026
lexdotdev Credited to lexdotdev
cruzryan Credited to cruzryan and cuauht cuauht cuauht
n8n: Expression sandbox escape via arrow-function bodies enabling command execution High
GHSA-gv7g-jm28-cr3m was published for n8n (npm) Jul 22, 2026
inaor Credited to inaor
TypeORM: migration:generate template-literal code injection Moderate
CVE-2026-73651 was published for typeorm (npm) Jul 21, 2026
smith-xyz Credited to smith-xyz
Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader High
CVE-2026-53597 was published for @prompty/core (npm) Jul 17, 2026
cristianstaicu Credited to cristianstaicu
nuiifornet Credited to nuiifornet
ProTip! Advisories are also available from the GraphQL API