GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,506
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,511
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
94 advisories
Filter by severity
Ghost: Paid gift memberships obtainable at minimal cost via the donations feature
Moderate
CVE-2026-59817
was published
for
ghost
(npm)
Aug 4, 2026
Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation
High
CVE-2026-70476
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API
High
CVE-2026-69258
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration
High
CVE-2026-69250
was published
for
flowise
(npm)
Aug 4, 2026
Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint
Moderate
GHSA-2364-jh4q-m9vm
was published
for
flowise
(npm)
Aug 4, 2026
Budibase: Email Change IDOR via POST /api/v2/email allows full Account Takeover (accountId not validated against session)
High
GHSA-c8vc-7pv3-g98p
was published
for
@budibase/server
(npm)
Jul 24, 2026
@better-auth/stripe: cross-organization billing tampering in organization subscription actions
High
GHSA-h3rm-78g3-j7cp
was published
for
@better-auth/stripe
(npm)
Jul 24, 2026
@better-auth/scim: account takeover and stale access via SCIM provider-id collision
Critical
GHSA-rjg6-39jm-rgg4
was published
for
@better-auth/scim
(npm)
Jul 24, 2026
n8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects
Moderate
CVE-2026-59253
was published
for
n8n
(npm)
Jul 22, 2026
n8n: External Secrets Accessible via Workflow Expressions Outside Credentials
Moderate
CVE-2026-59254
was published
for
n8n
(npm)
Jul 22, 2026
n8n: External Secrets Permission Bypass via Expression Parser Mismatch
Moderate
CVE-2026-59259
was published
for
n8n
(npm)
Jul 22, 2026
n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
High
CVE-2026-65016
was published
for
n8n
(npm)
Jul 22, 2026
Duplicate Advisory: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
High
GHSA-mwq7-vcmc-cm4q
was published
for
n8n
(npm)
Jul 22, 2026
•
withdrawn
Directus: Authorization-dependent response served from unsegmented cache key
High
CVE-2026-61836
was published
for
directus
(npm)
Jul 20, 2026
Duplicate Advisory: n8n: External Secrets Accessible via Workflow Expressions Outside Credentials
Moderate
GHSA-3j7v-fhjg-6rh2
was published
for
n8n
(npm)
Jul 15, 2026
•
withdrawn
Duplicate Advisory: External Secrets Permission Bypass via Expression Parser Mismatch
Moderate
GHSA-q6mx-qvhp-fqmg
was published
for
n8n
(npm)
Jul 15, 2026
•
withdrawn
n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments
Critical
CVE-2026-54052
was published
for
n8n-mcp
(npm)
Jul 14, 2026
Duplicate Advisory: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects
Moderate
GHSA-gqcv-rfj6-r29g
was published
for
n8n
(npm)
Jul 8, 2026
•
withdrawn
@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers
High
GHSA-j8v8-g9cx-5qf4
was published
for
@better-auth/scim
(npm)
Jul 7, 2026
Grackle: Fail-open authorization in the MCP tool layer lets scoped agents perform cross-task and cross-session mutations (IDOR)
High
GHSA-f9ff-5x35-7gfw
was published
for
@grackle-ai/auth
(npm)
Jul 2, 2026
parse-server: Relation `$relatedTo` query bypasses `protectedFields` and owning-object ACL
Moderate
CVE-2026-53726
was published
for
parse-server
(npm)
Jun 19, 2026
AgenticMail: Cross-agent task authorization bypass in AgenticMail API
High
CVE-2026-57494
was published
for
@agenticmail/api
(npm)
Jun 18, 2026
OpenClaw: Tool group policy callers could accept unvalidated group IDs
Moderate
CVE-2026-53863
was published
for
openclaw
(npm)
Jun 18, 2026
Duplicate Advisory: Tool group policy callers could accept unvalidated group IDs
Moderate
GHSA-8wmm-344f-mpjg
was published
for
openclaw
(npm)
Jun 16, 2026
•
withdrawn
NocoDB: Missing Ownership Check in MCP Attachment Read
Low
CVE-2026-47388
was published
for
nocodb
(npm)
Jun 5, 2026
ProTip!
Advisories are also available from the
GraphQL API