Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

420 advisories

Loading
9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass High
CVE-2026-55638 was published for 9router (npm) Aug 28, 2026
dinhvaren Credited to dinhvaren
black-shadow-007 Credited to black-shadow-007
Snipe-IT has an authorization bypass on bulk editing users High
CVE-2026-55460 was published for snipe/snipe-it (Composer) Aug 28, 2026
mamdouhmahfouz Credited to mamdouhmahfouz
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root High
CVE-2026-54563 was published for github.com/cloudreve/Cloudreve/v3 (Go) Aug 26, 2026
riodrwn Credited to riodrwn
Winter: ImportExportController AJAX handlers bypass granular import/export permission gate High
GHSA-fm29-4mq3-phg6 was published for winter/wn-backend-module (Composer) Aug 20, 2026
manus-use Credited to manus-use
tabacitu Credited to tabacitu
Pig-Tail Credited to Pig-Tail, sec-reex, and DavidCarliez sec-reex sec-reex
DavidCarliez DavidCarliez
legobattman Credited to legobattman and Classic298 Classic298 Classic298
Flowise: Cross-Workspace OAuth2 Credential Metadata Leak High
CVE-2026-70474 was published for flowise (npm) Aug 4, 2026
hett-patell Credited to hett-patell
Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store High
CVE-2026-70472 was published for flowise (npm) Aug 4, 2026
Kazamayc Credited to Kazamayc
Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure High
CVE-2026-70471 was published for flowise (npm) Aug 4, 2026
EaEa0001 Credited to EaEa0001
ZITADEL Users Can Self-Verify Email/Phone via API High
CVE-2026-54693 was published for github.com/zitadel/zitadel (Go) Jul 29, 2026
IAM-marco Credited to IAM-marco and livio-a livio-a livio-a
Quarkus: Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities High
CVE-2026-50559 was published for io.quarkus:quarkus-vertx-http (Maven) Jul 29, 2026
geoand Credited to geoand and cescoffier cescoffier cescoffier
anir0y Credited to anir0y
etcd: Watch API authorization bypass via open-ended range requests High
CVE-2026-73499 was published for go.etcd.io/etcd/v3 (Go) Jul 24, 2026
lobuhi Credited to lobuhi and AdamKorcz AdamKorcz AdamKorcz
DavidCarliez Credited to DavidCarliez
Budibase: Privilege escalation via public role assignment API missing app-level authorization High
CVE-2026-73305 was published for @budibase/server (npm) Jul 24, 2026
dinhvaren Credited to dinhvaren
Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials High
CVE-2026-55502 was published for github.com/cloudreve/Cloudreve/v3 (Go) Jul 24, 2026
DavidCarliez Credited to DavidCarliez
@better-auth/stripe: cross-organization billing tampering in organization subscription actions High
GHSA-h3rm-78g3-j7cp was published for @better-auth/stripe (npm) Jul 24, 2026
n8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON High
GHSA-cj9h-qx8g-pq2g was published for n8n (npm) Jul 22, 2026
nlgbao1340 Credited to nlgbao1340
n8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType` High
GHSA-6qc9-mqvw-jg7x was published for n8n (npm) Jul 22, 2026
g4nkd Credited to g4nkd
n8n: Bypass "Allowed HTTP Request Domains" Credential Restriction in Multiple AI and LLM Nodes High
GHSA-64xh-79j6-r5v8 was published for n8n (npm) Jul 22, 2026
nlgbao1340 Credited to nlgbao1340
n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login High
GHSA-8342-988q-86cr was published for n8n (npm) Jul 22, 2026
ProTip! Advisories are also available from the GraphQL API