Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

569 advisories

Loading
Payload: Incomplete validation during the upload file lifecycle High
CVE-2026-105865 was published for payload (npm) Oct 7, 2026
EchoSkorJjj Credited to EchoSkorJjj
Ghost: Path Traversal via Locale Setting Moderate
CVE-2026-105676 was published for ghost (npm) Oct 7, 2026
DONG2209 Credited to DONG2209 and msegoviag msegoviag msegoviag
Ghost: Remote Code Execution via Theme Translation Files High
CVE-2026-105677 was published for ghost (npm) Oct 7, 2026
Alemmi Credited to Alemmi, Tomer-PL, and msegoviag Tomer-PL Tomer-PL
msegoviag msegoviag
Backstage: Improper input validation in Confluence to Markdown scaffolder module Moderate
CVE-2026-106559 was published for @backstage/plugin-scaffolder-backend-module-confluence-to-markdown (npm) Oct 7, 2026
Backstage: Improper repository path validation in a Scaffolder backend module High
CVE-2026-106560 was published for @backstage/plugin-scaffolder-backend-module-confluence-to-markdown (npm) Oct 7, 2026
Backstage has iImproper filesystem validation in Bitbucket pull-request scaffolder actions High
CVE-2026-106486 was published for @backstage/plugin-scaffolder-backend-module-bitbucket-cloud (npm) Oct 7, 2026
Backstage: Improper authorization enforcement for TechDocs static content Moderate
CVE-2026-106489 was published for @backstage/plugin-techdocs-backend (npm) Oct 7, 2026
Backstage: Improper input validation in TechDocs static content requests Moderate
CVE-2026-106490 was published for @backstage/plugin-techdocs-backend (npm) Oct 7, 2026
Backstage: Cloud storage catalog locations may cross configured storage boundaries Low
CVE-2026-106493 was published for @backstage/backend-defaults (npm) Oct 7, 2026
Backstage: Improper input validation in proxy-backend Moderate
CVE-2026-106491 was published for @backstage/plugin-proxy-backend (npm) Oct 7, 2026
Backstage: Improper input validation in cloud storage URL readers Moderate
CVE-2026-106494 was published for @backstage/backend-defaults (npm) Oct 7, 2026
Backstage: Inconsistent enforcement of allowed location types during catalog processing Low
CVE-2026-106496 was published for @backstage/plugin-catalog-backend (npm) Oct 7, 2026
Backstage has potential file exposure through local TechDocs publisher Moderate
CVE-2026-106508 was published for @backstage/plugin-techdocs-node (npm) Oct 7, 2026
Backstage has improper input validation in TechDocs Markdown extension configuration High
CVE-2026-106557 was published for @backstage/plugin-techdocs-node (npm) Oct 7, 2026
Quasar Framework: App Vite SSG page output paths can escape the configured distribution directory Moderate
CVE-2026-106108 was published for @quasar/app-vite (npm) Oct 7, 2026
hawkeye64 Credited to hawkeye64
Quasar Framework: App Vite build cleanup can recursively remove unsafe configured output directories Moderate
CVE-2026-106109 was published for @quasar/app-vite (npm) Oct 7, 2026
hawkeye64 Credited to hawkeye64
Quasar Framework: Path Traversal / Arbitrary File Write via crafted Icon Genie profile High
CVE-2026-106103 was published for @quasar/icongenie (npm) Oct 7, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
Nx: Path traversal in nx migrate package-migrations extraction Moderate
CVE-2026-104853 was published for nx (npm) Oct 5, 2026
arkmarta Credited to arkmarta
Angular SSR: Path Traversal to Sibling Directories in CommonEngine on Windows Moderate
CVE-2026-104871 was published for @angular/ssr (npm) Oct 5, 2026
srkyn Credited to srkyn and alan-agius4 alan-agius4 alan-agius4
arpitjain099 Credited to arpitjain099
@xhmikosr/decompress: Path traversal via symlink chain Critical
CVE-2026-101894 was published for @xhmikosr/decompress (npm) Sep 29, 2026
umar0x Credited to umar0x and XhmikosR XhmikosR XhmikosR
webpack-dev-middleware vulnerable to Path Traversal via non-slash-terminated publicPath High
CVE-2026-76844 was published for webpack-dev-middleware (npm) Sep 29, 2026
UlisesGascon Credited to UlisesGascon, avivkeller, bjohansebas, and evenstensberg avivkeller avivkeller
bjohansebas bjohansebas evenstensberg evenstensberg
uziii2208 Credited to uziii2208 and hoanggxyuuki hoanggxyuuki hoanggxyuuki
mcfly-zzh Credited to mcfly-zzh
ProTip! Advisories are also available from the GraphQL API