Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

340 advisories

Loading
Payload: Incomplete validation during the upload file lifecycle High
CVE-2026-105865 was published for payload (npm) Oct 7, 2026
EchoSkorJjj Credited to EchoSkorJjj
Ghost: Remote Code Execution via Theme Translation Files High
CVE-2026-105677 was published for ghost (npm) Oct 7, 2026
Alemmi Credited to Alemmi, Tomer-PL, and msegoviag Tomer-PL Tomer-PL
msegoviag msegoviag
Backstage: Improper repository path validation in a Scaffolder backend module High
CVE-2026-106560 was published for @backstage/plugin-scaffolder-backend-module-confluence-to-markdown (npm) Oct 7, 2026
Backstage has iImproper filesystem validation in Bitbucket pull-request scaffolder actions High
CVE-2026-106486 was published for @backstage/plugin-scaffolder-backend-module-bitbucket-cloud (npm) Oct 7, 2026
Backstage has improper input validation in TechDocs Markdown extension configuration High
CVE-2026-106557 was published for @backstage/plugin-techdocs-node (npm) Oct 7, 2026
Quasar Framework: Path Traversal / Arbitrary File Write via crafted Icon Genie profile High
CVE-2026-106103 was published for @quasar/icongenie (npm) Oct 7, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
webpack-dev-middleware vulnerable to Path Traversal via non-slash-terminated publicPath High
CVE-2026-76844 was published for webpack-dev-middleware (npm) Sep 29, 2026
UlisesGascon Credited to UlisesGascon, avivkeller, bjohansebas, and evenstensberg avivkeller avivkeller
bjohansebas bjohansebas evenstensberg evenstensberg
uziii2208 Credited to uziii2208 and hoanggxyuuki hoanggxyuuki hoanggxyuuki
mcfly-zzh Credited to mcfly-zzh
@openhop/server: Path Traversal in Flow ID File Operations High
CVE-2026-59179 was published for @openhop/server (npm) Sep 9, 2026
EQSTLab Credited to EQSTLab and useworld useworld useworld
OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree High
GHSA-2q42-4q24-7rgv was published for @typespec/compiler (npm) Sep 8, 2026
NLx64 Credited to NLx64
portyu9 Credited to portyu9
sondt99 Credited to sondt99, dungNHVhust, and sai-sh dungNHVhust dungNHVhust
sai-sh sai-sh
CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes High
CVE-2026-75914 was published for codewhale (npm) Sep 4, 2026
fg0x0 Credited to fg0x0
Orval: Generation-time SSRF + remote/local file inclusion via unrestricted $ref High
CVE-2026-62680 was published for orval (npm) Sep 2, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
manus-use Credited to manus-use
pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project High
GHSA-2rx9-3g3h-c2jv was published for pnpm (npm) Sep 1, 2026
Whistle vulnerable to path traversal High
CVE-2026-55629 was published for whistle (npm) Aug 25, 2026
researchersongwu Credited to researchersongwu
browse-mcp has an arbitrary file write via unconfined download and state paths High
CVE-2026-55557 was published for browse-mcp (npm) Aug 25, 2026
novice-22 Credited to novice-22
Duplicate Advisory: webpack-dev-middleware vulnerable to Path Traversal via non-slash-terminated publicPath High
GHSA-p3f5-w63m-mxph was published for webpack-dev-middleware (npm) Aug 24, 2026 • withdrawn
logto-tunnel serves files outside --experience-path via path traversal High
CVE-2026-63188 was published for @logto/tunnel (npm) Aug 19, 2026
pyuysig Credited to pyuysig
claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools High
GHSA-rr55-jp92-8wp2 was published for claude-faf-mcp (npm) Aug 19, 2026
faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools High
GHSA-j4r7-8ph4-43g3 was published for faf-mcp (npm) Aug 19, 2026
grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools High
GHSA-cc2g-gq8c-r332 was published for grok-faf-mcp (npm) Aug 19, 2026
ProTip! Advisories are also available from the GraphQL API