GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
169 advisories
Filter by severity
Ghost: Path Traversal via Locale Setting
Moderate
CVE-2026-105676
was published
for
ghost
(npm)
Oct 7, 2026
Backstage: Improper input validation in Confluence to Markdown scaffolder module
Moderate
CVE-2026-106559
was published
for
@backstage/plugin-scaffolder-backend-module-confluence-to-markdown
(npm)
Oct 7, 2026
Backstage: Improper authorization enforcement for TechDocs static content
Moderate
CVE-2026-106489
was published
for
@backstage/plugin-techdocs-backend
(npm)
Oct 7, 2026
Backstage: Improper input validation in TechDocs static content requests
Moderate
CVE-2026-106490
was published
for
@backstage/plugin-techdocs-backend
(npm)
Oct 7, 2026
Backstage: Improper input validation in proxy-backend
Moderate
CVE-2026-106491
was published
for
@backstage/plugin-proxy-backend
(npm)
Oct 7, 2026
Backstage: Improper input validation in cloud storage URL readers
Moderate
CVE-2026-106494
was published
for
@backstage/backend-defaults
(npm)
Oct 7, 2026
Backstage has potential file exposure through local TechDocs publisher
Moderate
CVE-2026-106508
was published
for
@backstage/plugin-techdocs-node
(npm)
Oct 7, 2026
Quasar Framework: App Vite SSG page output paths can escape the configured distribution directory
Moderate
CVE-2026-106108
was published
for
@quasar/app-vite
(npm)
Oct 7, 2026
Quasar Framework: App Vite build cleanup can recursively remove unsafe configured output directories
Moderate
CVE-2026-106109
was published
for
@quasar/app-vite
(npm)
Oct 7, 2026
Nx: Path traversal in nx migrate package-migrations extraction
Moderate
CVE-2026-104853
was published
for
nx
(npm)
Oct 5, 2026
Angular SSR: Path Traversal to Sibling Directories in CommonEngine on Windows
Moderate
CVE-2026-104871
was published
for
@angular/ssr
(npm)
Oct 5, 2026
vm2: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted
Moderate
CVE-2026-92945
was published
for
vm2
(npm)
Oct 1, 2026
Redocly CLI: Path traversal when using `split` command
Moderate
CVE-2026-63225
was published
for
@redocly/cli
(npm)
Sep 17, 2026
@Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)
Moderate
CVE-2026-59149
was published
for
@mockoon/cli
(npm)
Sep 11, 2026
n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
Moderate
CVE-2026-86995
was published
for
n8n
(npm)
Sep 10, 2026
n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers
Moderate
CVE-2026-86079
was published
for
n8n
(npm)
Sep 10, 2026
Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory
Moderate
CVE-2026-84365
was published
for
hono
(npm)
Sep 8, 2026
Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock
Moderate
CVE-2026-84373
was published
for
@vitest/mocker
(npm)
Sep 8, 2026
ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal
Moderate
CVE-2026-63667
was published
for
@apostrophecms/import-export
(npm)
Sep 2, 2026
humanfs: Recursive copy follows symlinked files and copies data from outside the source tree
Moderate
GHSA-p498-v437-472g
was published
for
@humanfs/node
(npm)
Sep 2, 2026
libreoffice-convert vulnerable to path traversal / arbitrary file write
Moderate
CVE-2026-54732
was published
for
libreoffice-convert
(npm)
Aug 27, 2026
n8n-nodes-sqlite3 vulnerable to path traversal via user-controlled database file path (db_path parameter)
Moderate
CVE-2026-54687
was published
for
n8n-nodes-sqlite3
(npm)
Aug 27, 2026
chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots
Moderate
CVE-2026-53766
was published
for
chrome-devtools-mcp
(npm)
Aug 17, 2026
Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling
Moderate
GHSA-92hr-gmr6-h8cp
was published
for
ep_etherpad-lite
(npm)
Aug 17, 2026
Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints
Moderate
CVE-2026-55156
was published
for
@ooples/token-optimizer-mcp
(npm)
Aug 14, 2026
ProTip!
Advisories are also available from the
GraphQL API