Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

169 advisories

Loading
Ghost: Path Traversal via Locale Setting Moderate
CVE-2026-105676 was published for ghost (npm) Oct 7, 2026
DONG2209 Credited to DONG2209 and msegoviag msegoviag msegoviag
Backstage: Improper input validation in Confluence to Markdown scaffolder module Moderate
CVE-2026-106559 was published for @backstage/plugin-scaffolder-backend-module-confluence-to-markdown (npm) Oct 7, 2026
Backstage: Improper authorization enforcement for TechDocs static content Moderate
CVE-2026-106489 was published for @backstage/plugin-techdocs-backend (npm) Oct 7, 2026
Backstage: Improper input validation in TechDocs static content requests Moderate
CVE-2026-106490 was published for @backstage/plugin-techdocs-backend (npm) Oct 7, 2026
Backstage: Improper input validation in proxy-backend Moderate
CVE-2026-106491 was published for @backstage/plugin-proxy-backend (npm) Oct 7, 2026
Backstage: Improper input validation in cloud storage URL readers Moderate
CVE-2026-106494 was published for @backstage/backend-defaults (npm) Oct 7, 2026
Backstage has potential file exposure through local TechDocs publisher Moderate
CVE-2026-106508 was published for @backstage/plugin-techdocs-node (npm) Oct 7, 2026
Quasar Framework: App Vite SSG page output paths can escape the configured distribution directory Moderate
CVE-2026-106108 was published for @quasar/app-vite (npm) Oct 7, 2026
hawkeye64 Credited to hawkeye64
Quasar Framework: App Vite build cleanup can recursively remove unsafe configured output directories Moderate
CVE-2026-106109 was published for @quasar/app-vite (npm) Oct 7, 2026
hawkeye64 Credited to hawkeye64
Nx: Path traversal in nx migrate package-migrations extraction Moderate
CVE-2026-104853 was published for nx (npm) Oct 5, 2026
arkmarta Credited to arkmarta
Angular SSR: Path Traversal to Sibling Directories in CommonEngine on Windows Moderate
CVE-2026-104871 was published for @angular/ssr (npm) Oct 5, 2026
srkyn Credited to srkyn and alan-agius4 alan-agius4 alan-agius4
arpitjain099 Credited to arpitjain099
Redocly CLI: Path traversal when using `split` command Moderate
CVE-2026-63225 was published for @redocly/cli (npm) Sep 17, 2026
thegr1ffyn Credited to thegr1ffyn
miauzxw Credited to miauzxw and geo-chen geo-chen geo-chen
Masofgon Credited to Masofgon
n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers Moderate
CVE-2026-86079 was published for n8n (npm) Sep 10, 2026
vonypeto Credited to vonypeto
pacocartones Credited to pacocartones and LeonMAG LeonMAG LeonMAG
Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock Moderate
CVE-2026-84373 was published for @vitest/mocker (npm) Sep 8, 2026
1491342590 Credited to 1491342590
ApostropheCMS: Arbitrary file read via import-export attachment-name path traversal Moderate
CVE-2026-63667 was published for @apostrophecms/import-export (npm) Sep 2, 2026
kah-ja Credited to kah-ja and luuhung1217 luuhung1217 luuhung1217
humanfs: Recursive copy follows symlinked files and copies data from outside the source tree Moderate
GHSA-p498-v437-472g was published for @humanfs/node (npm) Sep 2, 2026
Jvr2022 Credited to Jvr2022
libreoffice-convert vulnerable to path traversal / arbitrary file write Moderate
CVE-2026-54732 was published for libreoffice-convert (npm) Aug 27, 2026
Santoshkumarpuppala Credited to Santoshkumarpuppala
n8n-nodes-sqlite3 vulnerable to path traversal via user-controlled database file path (db_path parameter) Moderate
CVE-2026-54687 was published for n8n-nodes-sqlite3 (npm) Aug 27, 2026
dyingman1 Credited to dyingman1
chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots Moderate
CVE-2026-53766 was published for chrome-devtools-mcp (npm) Aug 17, 2026
enable7997 Credited to enable7997
Etherpad addressed weak token RNG, login timing, plugin path handling, API request handling Moderate
GHSA-92hr-gmr6-h8cp was published for ep_etherpad-lite (npm) Aug 17, 2026
Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints Moderate
CVE-2026-55156 was published for @ooples/token-optimizer-mcp (npm) Aug 14, 2026
232-323 Credited to 232-323
ProTip! Advisories are also available from the GraphQL API