Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

268 advisories

Loading
9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass High
CVE-2026-55638 was published for 9router (npm) Aug 28, 2026
dinhvaren Credited to dinhvaren
Pig-Tail Credited to Pig-Tail, sec-reex, and DavidCarliez sec-reex sec-reex
DavidCarliez DavidCarliez
Flowise: Cross-Workspace OAuth2 Credential Metadata Leak High
CVE-2026-70474 was published for flowise (npm) Aug 4, 2026
hett-patell Credited to hett-patell
Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store High
CVE-2026-70472 was published for flowise (npm) Aug 4, 2026
Kazamayc Credited to Kazamayc
Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure High
CVE-2026-70471 was published for flowise (npm) Aug 4, 2026
EaEa0001 Credited to EaEa0001
DavidCarliez Credited to DavidCarliez
Budibase: Privilege escalation via public role assignment API missing app-level authorization High
CVE-2026-73305 was published for @budibase/server (npm) Jul 24, 2026
dinhvaren Credited to dinhvaren
@better-auth/stripe: cross-organization billing tampering in organization subscription actions High
GHSA-h3rm-78g3-j7cp was published for @better-auth/stripe (npm) Jul 24, 2026
n8n: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction Moderate
CVE-2026-65596 was published for n8n (npm) Jul 22, 2026
34selen Credited to 34selen
momenashrafff Credited to momenashrafff
n8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON High
GHSA-cj9h-qx8g-pq2g was published for n8n (npm) Jul 22, 2026
nlgbao1340 Credited to nlgbao1340
n8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType` High
GHSA-6qc9-mqvw-jg7x was published for n8n (npm) Jul 22, 2026
g4nkd Credited to g4nkd
n8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes High
GHSA-64xh-79j6-r5v8 was published for n8n (npm) Jul 22, 2026
nlgbao1340 Credited to nlgbao1340
n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login High
GHSA-8342-988q-86cr was published for n8n (npm) Jul 22, 2026
n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool High
CVE-2026-65015 was published for n8n (npm) Jul 22, 2026
trap-bytes Credited to trap-bytes
Duplicate Advisory: AI Agents Project Viewer Privilege Escalation via run_node_tool High
GHSA-w46p-w7w2-fr9g was published for n8n (npm) Jul 22, 2026 withdrawn
Malayke Credited to Malayke
Duplicate Advisory: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction Moderate
GHSA-88c4-pcqm-3r9p was published for n8n (npm) Jul 22, 2026 withdrawn
@better-auth/sso: SSO provider may allow registration for any org member without a checking their role High
CVE-2026-53515 was published for @better-auth/sso (npm) Jul 20, 2026
Nadav0077 Credited to Nadav0077
DavidCarliez Credited to DavidCarliez
@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators Moderate
GHSA-p2fr-6hmx-4528 was published for @better-auth/oauth-provider (npm) Jul 7, 2026
dvanmali Credited to dvanmali
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins Critical
CVE-2026-53512 was published for better-auth (npm) Jul 7, 2026
subhanUmer Credited to subhanUmer
OpenClaw: Native command authorization could skip owner-command enforcement High
GHSA-p73f-w79w-jqr5 was published for openclaw (npm) Jul 2, 2026
zsxsoft Credited to zsxsoft, KeenSecurityLab, and qclawer KeenSecurityLab KeenSecurityLab
qclawer qclawer
OpenClaw: Telegram interactive callbacks could skip commands.allowFrom High
GHSA-w5ww-7chg-mxcq was published for openclaw (npm) Jul 2, 2026
zsxsoft Credited to zsxsoft, KeenSecurityLab, and qclawer KeenSecurityLab KeenSecurityLab
qclawer qclawer
ProTip! Advisories are also available from the GraphQL API