Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

451 advisories

Loading
Contao: Cross-site scripting in the comments bundle Critical
CVE-2026-107845 was published for contao/comments-bundle (Composer) Oct 9, 2026
HDWSec Credited to HDWSec
PraisonAI: API deploy code generator embeds unescaped YAML fields into Python source High
CVE-2026-61433 was published for praisonai (pip) Oct 8, 2026
rexpository Credited to rexpository
Handlebars: JavaScript Injection via Unsafe Inline Embedding of Precompiled Templates Moderate
CVE-2026-106444 was published for handlebars (npm) Oct 8, 2026
amwhoi Credited to amwhoi
PraisonAI: Prompt Injection Defense Bypassed for HIGH-Level Threats High
CVE-2026-61439 was published for PraisonAI (pip) Oct 7, 2026
chakrapani150 Credited to chakrapani150
Quasar Framework: App Vite SSR and SSG nonce attributes are not safely constrained High
CVE-2026-106107 was published for @quasar/app-vite (npm) Oct 7, 2026
hawkeye64 Credited to hawkeye64
Quasar Framework: Stored/Reflected XSS via unescaped SSR meta tag rendering in getHead() Critical
CVE-2026-106102 was published for quasar (npm) Oct 7, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
openapi-python-client: Malicious OpenAPI Documents can cause Arbitrary Code Generation High
CVE-2026-105801 was published for openapi-python-client (pip) Oct 6, 2026
Gal3m Credited to Gal3m, iabdullah215, and 0xsharz iabdullah215 iabdullah215
0xsharz 0xsharz
@vue/server-renderer: XSS via missing CR in attribute-name blacklist High
GHSA-g2v6-rqmx-r4w6 was published for @vue/server-renderer (npm) Oct 5, 2026
onevilx Credited to onevilx
Vibe-Trading LLM-callable tools permit command execution, code injection, and SSRF Critical
GHSA-jqmf-mx4f-hfr6 was published for vibe-trading-ai (pip) Oct 2, 2026
lemi9090 Credited to lemi9090
fast-uri vulnerable to authority injection via an unvalidated port in serialize High
CVE-2026-84292 was published for fast-uri (npm) Sep 28, 2026
YashvantHange Credited to YashvantHange, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
Angular SSR: XSS via Unescaped Processing Instruction (<?...?>) Nodes in Fallback Raw-Content Elements High
CVE-2026-88058 was published for @angular/platform-server (npm) Sep 28, 2026
VenkatKwest Credited to VenkatKwest and alan-agius4 alan-agius4 alan-agius4
xhtml-purifier has HTML attribute-injection (sanitizer bypass) that leads to XSS Moderate
CVE-2026-61784 was published for xhtml-purifier (npm) Sep 24, 2026
EchoTydes Credited to EchoTydes
Klever-Go: Elasticsearch bulk / painless injection via on-chain account name -> explorer/indexer data forgery High
CVE-2026-82409 was published for github.com/klever-io/klever-go (Go) Sep 23, 2026
mabdullah22 Credited to mabdullah22
djust: A template binding inherits a context safety grant it never earned (XSS) High
GHSA-xjw9-38cr-6372 was published for djust (pip) Sep 17, 2026
djust: Six template-layer defects emit attacker-controlled markup unescaped (XSS) High
GHSA-9395-2g46-rj3f was published for djust (pip) Sep 17, 2026
RabbitMQ amqp091-go: Connection Configuration Overwrite via Unsanitized TLS Path Parameter Injection High
CVE-2026-77404 was published for github.com/rabbitmq/amqp091-go (Go) Sep 17, 2026
suchitd Credited to suchitd
Angular: SSR XSS via Unescaped <template> Content Across DocumentFragment Boundaries in Fallback Raw-Content Elements High
CVE-2026-88060 was published for @angular/platform-server (npm) Sep 10, 2026
mabjr33 Credited to mabjr33 and alan-agius4 alan-agius4 alan-agius4
ProTip! Advisories are also available from the GraphQL API