Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

94 advisories

Loading
Ghost: Paid gift memberships obtainable at minimal cost via the donations feature Moderate
CVE-2026-59817 was published for ghost (npm) Aug 4, 2026
sane100400 Credited to sane100400 and P4P3R-HAK P4P3R-HAK P4P3R-HAK
berkdedekarginoglu Credited to berkdedekarginoglu
Aviral2642 Credited to Aviral2642
Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration High
CVE-2026-69250 was published for flowise (npm) Aug 4, 2026
b-hermes Credited to b-hermes
Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint Moderate
GHSA-2364-jh4q-m9vm was published for flowise (npm) Aug 4, 2026
truongvip1 Credited to truongvip1
themudhaxk Credited to themudhaxk and Ardeey-code Ardeey-code Ardeey-code
@better-auth/stripe: cross-organization billing tampering in organization subscription actions High
GHSA-h3rm-78g3-j7cp was published for @better-auth/stripe (npm) Jul 24, 2026
@better-auth/scim: account takeover and stale access via SCIM provider-id collision Critical
GHSA-rjg6-39jm-rgg4 was published for @better-auth/scim (npm) Jul 24, 2026
HO-9 Credited to HO-9
n8n: External Secrets Accessible via Workflow Expressions Outside Credentials Moderate
CVE-2026-59254 was published for n8n (npm) Jul 22, 2026
n8n: External Secrets Permission Bypass via Expression Parser Mismatch Moderate
CVE-2026-59259 was published for n8n (npm) Jul 22, 2026
YLChen-007 Credited to YLChen-007
n8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner High
CVE-2026-65016 was published for n8n (npm) Jul 22, 2026
ttzero25 Credited to ttzero25
Duplicate Advisory: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner High
GHSA-mwq7-vcmc-cm4q was published for n8n (npm) Jul 22, 2026 withdrawn
Directus: Authorization-dependent response served from unsegmented cache key High
CVE-2026-61836 was published for directus (npm) Jul 20, 2026
tr4ce-ju Credited to tr4ce-ju
Duplicate Advisory: n8n: External Secrets Accessible via Workflow Expressions Outside Credentials Moderate
GHSA-3j7v-fhjg-6rh2 was published for n8n (npm) Jul 15, 2026 withdrawn
Duplicate Advisory: External Secrets Permission Bypass via Expression Parser Mismatch Moderate
GHSA-q6mx-qvhp-fqmg was published for n8n (npm) Jul 15, 2026 withdrawn
n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments Critical
CVE-2026-54052 was published for n8n-mcp (npm) Jul 14, 2026
axsharma Credited to axsharma and 0xmagic0 0xmagic0 0xmagic0
Duplicate Advisory: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects Moderate
GHSA-gqcv-rfj6-r29g was published for n8n (npm) Jul 8, 2026 withdrawn
@better-auth/scim: Account/provider takeover via missing owner binding on non-org SCIM providers High
GHSA-j8v8-g9cx-5qf4 was published for @better-auth/scim (npm) Jul 7, 2026
Jvr2022 Credited to Jvr2022
parse-server: Relation `$relatedTo` query bypasses `protectedFields` and owning-object ACL Moderate
CVE-2026-53726 was published for parse-server (npm) Jun 19, 2026
offset Credited to offset and mtrezza mtrezza mtrezza
AgenticMail: Cross-agent task authorization bypass in AgenticMail API High
CVE-2026-57494 was published for @agenticmail/api (npm) Jun 18, 2026
YHalo-wyh Credited to YHalo-wyh
OpenClaw: Tool group policy callers could accept unvalidated group IDs Moderate
CVE-2026-53863 was published for openclaw (npm) Jun 18, 2026
zsxsoft Credited to zsxsoft, KeenSecurityLab, and qclawer KeenSecurityLab KeenSecurityLab
qclawer qclawer
Duplicate Advisory: Tool group policy callers could accept unvalidated group IDs Moderate
GHSA-8wmm-344f-mpjg was published for openclaw (npm) Jun 16, 2026 withdrawn
NocoDB: Missing Ownership Check in MCP Attachment Read Low
CVE-2026-47388 was published for nocodb (npm) Jun 5, 2026
helwor-01 Credited to helwor-01
ProTip! Advisories are also available from the GraphQL API