GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
280 advisories
Filter by severity
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
Critical
CVE-2026-77415
was published
for
jsonata
(npm)
Aug 21, 2026
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions
Critical
CVE-2026-77414
was published
for
jsonata
(npm)
Aug 21, 2026
JSONata: Arbitrary Code Execution via crafted JSONata expressions
Critical
CVE-2026-77413
was published
for
jsonata
(npm)
Aug 21, 2026
Mermaid allows CSS injection applying to sibling elements of the diagram
Moderate
CVE-2026-50159
was published
for
mermaid
(npm)
Aug 6, 2026
Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
High
CVE-2026-71320
was published
for
nuxt
(npm)
Aug 5, 2026
Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host
Critical
CVE-2026-71319
was published
for
@nuxt/devtools
(npm)
Aug 5, 2026
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter
Moderate
CVE-2026-70609
was published
for
electron
(npm)
Aug 5, 2026
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability
Critical
CVE-2026-70477
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
Critical
CVE-2026-69264
was published
for
flowise
(npm)
Aug 4, 2026
Flowise RCE via SQLite Record Manager Node
Critical
CVE-2026-69259
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: Remote Code Execution Vulnerability in CSVAgent
Critical
CVE-2026-69256
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
Critical
CVE-2026-69255
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
Critical
CVE-2026-69254
was published
for
flowise
(npm)
Aug 4, 2026
Flowise RCE via TypeORM DataSource
Critical
CVE-2026-69251
was published
for
flowise
(npm)
Aug 4, 2026
AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping
High
CVE-2026-11393
was published
for
@aws/agentcore
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
High
CVE-2026-54666
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped enum string values
High
CVE-2026-54664
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
High
CVE-2026-54661
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
High
CVE-2026-54662
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer
Critical
GHSA-w28w-gp39-m4p6
was published
for
@prompty/core
(npm)
Jul 24, 2026
Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)
Critical
CVE-2026-73649
was published
for
velocityjs
(npm)
Jul 24, 2026
n8n: Expression sandbox escape via arrow-function bodies enabling command execution
High
GHSA-gv7g-jm28-cr3m
was published
for
n8n
(npm)
Jul 22, 2026
TypeORM: migration:generate template-literal code injection
Moderate
CVE-2026-73651
was published
for
typeorm
(npm)
Jul 21, 2026
Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader
High
CVE-2026-53597
was published
for
@prompty/core
(npm)
Jul 17, 2026
TidGi Desktop Remote Code Execution via Malicious TiddlyWiki Repository Import — Tiddler Startup Module Auto-Execution
Critical
GHSA-9hc2-hjx8-q6pv
was published
for
tidgi
(npm)
Jul 14, 2026
ProTip!
Advisories are also available from the
GraphQL API