GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
43 advisories
Filter by severity
Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in
High
GHSA-qq9h-g4jm-xgf3
was published
for
better-auth
(npm)
Jul 24, 2026
n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
High
CVE-2026-59208
was published
for
n8n
(npm)
Jul 22, 2026
Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email
High
CVE-2026-53516
was published
for
better-auth
(npm)
Jul 7, 2026
Better Auth vulnerable to unauthorized invitation acceptance via unverified email match in organization plugin
High
CVE-2026-53514
was published
for
better-auth
(npm)
Jul 7, 2026
OpenClaw: Control UI locality spoofing could mint a durable admin device token
High
CVE-2026-53817
was published
for
openclaw
(npm)
Jul 2, 2026
OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers
High
CVE-2026-53832
was published
for
openclaw
(npm)
Jul 2, 2026
npm PraisonAI MCPSecurity Basic/OAuth authentication policies accept invalid credentials without validation
High
CVE-2026-57134
was published
for
praisonai
(npm)
Jun 18, 2026
Flowise: resetPassword Authentication Bypass Vulnerability
High
CVE-2026-41276
was published
for
flowise
(npm)
Apr 16, 2026
OpenClaw: CLI Remote Onboarding Persists Unauthenticated Discovery Endpoint and Exfiltrates Gateway Credentials
High
CVE-2026-41342
was published
for
openclaw
(npm)
Mar 31, 2026
n8n: LDAP Email-Based Account Linking Allows Privilege Escalation and Account Takeover
High
CVE-2026-33665
was published
for
n8n
(npm)
Mar 25, 2026
Parse Server has an auth provider validation bypass on login via partial authData
High
CVE-2026-33409
was published
for
parse-server
(npm)
Mar 19, 2026
ApostropheCMS MFA/TOTP Bypass via Incorrect MongoDB Query in Bearer Token Middleware
High
CVE-2026-32730
was published
for
apostrophe
(npm)
Mar 18, 2026
@siteboon/claude-code-ui Vulnerable to Unauthenticated RCE via WebSocket Shell Injection
High
CVE-2026-31975
was published
for
@siteboon/claude-code-ui
(npm)
Mar 11, 2026
Parse Server OAuth2 authentication adapter account takeover via identity spoofing
High
CVE-2026-30967
was published
for
parse-server
(npm)
Mar 11, 2026
Parse Server missing audience validation in Keycloak authentication adapter
High
CVE-2026-30949
was published
for
parse-server
(npm)
Mar 11, 2026
OpenClaw's andbox browser noVNC observer lacked VNC authentication
High
CVE-2026-32064
was published
for
openclaw
(npm)
Mar 3, 2026
OneUptime has WebAuthn 2FA bypass: server accepts client-supplied challenge instead of server-stored value, allowing credential replay
High
CVE-2026-28787
was published
for
@oneuptime/common
(npm)
Mar 2, 2026
OpenClaw optional voice-call plugin: webhook verification may be bypassed behind certain proxy configurations
High
CVE-2026-28465
was published
for
@clawdbot/voice-call
(npm)
Feb 17, 2026
Flowise has Authentication Bypass Using Unprotected Registration Endpoint (/register)
High
GHSA-v5w9-prxf-w882
was published
for
flowise
(npm)
Nov 17, 2025
@fedify/fedify has Improper Authentication and Incorrect Authorization
High
CVE-2025-54888
was published
for
@fedify/fedify
(npm)
Aug 8, 2025
Alchemy Non-SMA and Webauthn Account Security Advisory
High
GHSA-56r6-ccm5-8hg3
was published
for
@account-kit/smart-contracts
(npm)
Jul 21, 2025
Erxes Incorrect Access Control vulnerability
High
CVE-2024-57190
was published
for
erxes
(npm)
Jun 10, 2025
Passport-wsfed-saml2 allows SAML Authentication Bypass via Attribute Smuggling
High
CVE-2025-46573
was published
for
passport-wsfed-saml2
(npm)
May 6, 2025
Matrix JavaScript SDK's key history sharing could share keys to malicious devices
High
CVE-2024-47080
was published
for
matrix-js-sdk
(npm)
Oct 15, 2024
ProTip!
Advisories are also available from the
GraphQL API