GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
268 advisories
Filter by severity
9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass
High
CVE-2026-55638
was published
for
9router
(npm)
Aug 28, 2026
Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)
High
CVE-2026-71315
was published
for
nuxt
(npm)
Aug 5, 2026
Flowise: Cross-Workspace OAuth2 Credential Metadata Leak
High
CVE-2026-70474
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store
High
CVE-2026-70472
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure
High
CVE-2026-70471
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type
High
CVE-2026-69262
was published
for
flowise
(npm)
Aug 4, 2026
Budibase: S3 presigned URL endpoint authorization regression in v3.39.4 allows BASIC users to obtain S3 PutObject presigned URLs
High
GHSA-xcx6-4f2g-hhgx
was published
for
@budibase/server
(npm)
Jul 24, 2026
Budibase: Privilege escalation via public role assignment API missing app-level authorization
High
CVE-2026-73305
was published
for
@budibase/server
(npm)
Jul 24, 2026
@better-auth/stripe: cross-organization billing tampering in organization subscription actions
High
GHSA-h3rm-78g3-j7cp
was published
for
@better-auth/stripe
(npm)
Jul 24, 2026
n8n: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction
Moderate
CVE-2026-65596
was published
for
n8n
(npm)
Jul 22, 2026
n8n: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check
Moderate
CVE-2026-65594
was published
for
n8n
(npm)
Jul 22, 2026
n8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON
High
GHSA-cj9h-qx8g-pq2g
was published
for
n8n
(npm)
Jul 22, 2026
n8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`
High
GHSA-6qc9-mqvw-jg7x
was published
for
n8n
(npm)
Jul 22, 2026
n8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes
High
GHSA-64xh-79j6-r5v8
was published
for
n8n
(npm)
Jul 22, 2026
n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login
High
GHSA-8342-988q-86cr
was published
for
n8n
(npm)
Jul 22, 2026
n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool
High
CVE-2026-65015
was published
for
n8n
(npm)
Jul 22, 2026
Duplicate Advisory: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check
Moderate
GHSA-5vfw-jc4p-fj39
was published
for
n8n
(npm)
Jul 22, 2026
•
withdrawn
Duplicate Advisory: AI Agents Project Viewer Privilege Escalation via run_node_tool
High
GHSA-w46p-w7w2-fr9g
was published
for
n8n
(npm)
Jul 22, 2026
•
withdrawn
Duplicate Advisory: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction
Moderate
GHSA-88c4-pcqm-3r9p
was published
for
n8n
(npm)
Jul 22, 2026
•
withdrawn
@better-auth/sso: SSO provider may allow registration for any org member without a checking their role
High
CVE-2026-53515
was published
for
@better-auth/sso
(npm)
Jul 20, 2026
n8n-MCP: Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP mode
Moderate
CVE-2026-55608
was published
for
n8n-mcp
(npm)
Jul 14, 2026
@better-auth/oauth-provider may provide access tokens for unauthorized audiences via unbound resource indicators
Moderate
GHSA-p2fr-6hmx-4528
was published
for
@better-auth/oauth-provider
(npm)
Jul 7, 2026
Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins
Critical
CVE-2026-53512
was published
for
better-auth
(npm)
Jul 7, 2026
OpenClaw: Native command authorization could skip owner-command enforcement
High
GHSA-p73f-w79w-jqr5
was published
for
openclaw
(npm)
Jul 2, 2026
OpenClaw: Telegram interactive callbacks could skip commands.allowFrom
High
GHSA-w5ww-7chg-mxcq
was published
for
openclaw
(npm)
Jul 2, 2026
ProTip!
Advisories are also available from the
GraphQL API