Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

33 advisories

Loading
mufeedvh Credited to mufeedvh
n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion High
GHSA-2x35-3fw4-9jr4 was published for n8n (npm) Jul 22, 2026
simonkoeck Credited to simonkoeck
TanStack Start - Server Core: Inbound server-function request deserialization could invoke a sibling client-referenced server function Moderate
GHSA-9m65-766c-r333 was published for @tanstack/start-server-core (npm) May 14, 2026
mufeedvh Credited to mufeedvh
@babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input High
CVE-2026-44728 was published for @babel/plugin-transform-modules-systemjs (npm) May 8, 2026
JLHwung Credited to JLHwung, daniel-msft, and nicolo-ribaudo daniel-msft daniel-msft
nicolo-ribaudo nicolo-ribaudo
Parse Server has a LiveQuery protected-field guard bypass via array-like logical operator value Moderate
CVE-2026-34595 was published for parse-server (npm) Apr 1, 2026
bugbunny-research Credited to bugbunny-research and mtrezza mtrezza mtrezza
evanj2357 Credited to evanj2357
Handlebars.js has JavaScript Injection via AST Type Confusion by tampering @partial-block High
CVE-2026-33938 was published for handlebars (npm) Mar 27, 2026
evanj2357 Credited to evanj2357
Handlebars.js has JavaScript Injection via AST Type Confusion Critical
CVE-2026-33937 was published for handlebars (npm) Mar 27, 2026
RealHurrison Credited to RealHurrison
Qwik City has array method pollution in FormData processing allows type confusion and DoS High
CVE-2026-32701 was published for @builder.io/qwik-city (npm) Mar 20, 2026
Y4tacker Credited to Y4tacker
CPU exhaustion in SvelteKit remote form deserialization (experimental only) Moderate
GHSA-88qp-p4qg-rqm6 was published for @sveltejs/kit (npm) Feb 19, 2026
elliott-with-the-longest-name-on-github Credited to elliott-with-the-longest-name-on-github
Preact has JSON VNode Injection issue High
CVE-2026-22028 was published for preact (npm) Jan 7, 2026
Xvezda Credited to Xvezda
@digitalocean/do-markdownit has Type Confusion vulnerability Moderate
CVE-2025-59717 was published for @digitalocean/do-markdownit (npm) Sep 19, 2025
cai0duque Credited to cai0duque
libxmljs2 vulnerable to type confusion when parsing specially crafted XML Critical
CVE-2024-34394 was published for libxmljs2 (npm) May 2, 2024
macariomartins Credited to macariomartins
libxmljs vulnerable to type confusion when parsing specially crafted XML Critical
CVE-2024-34391 was published for libxmljs (npm) May 2, 2024
libxmljs2 type confusion vulnerability when parsing specially crafted XML Critical
CVE-2024-34393 was published for libxmljs2 (npm) May 2, 2024
libxmljs vulnerable to type confusion when parsing specially crafted XML Critical
CVE-2024-34392 was published for libxmljs (npm) May 2, 2024
Unsafe fall-through in getWhereConditions Critical
CVE-2023-22579 was published for @sequelize/core (npm) Feb 23, 2023
Duplicate advisory: Sequelize - Unsafe fall-through in getWhereConditions High
GHSA-r3vq-92c6-3mqf was published for @sequelize/core (npm) Feb 16, 2023 withdrawn
Access of Resource Using Incompatible Type in Facebook Hermes Critical
CVE-2020-1911 was published for hermes-engine (npm) May 24, 2022
Access of Resource Using Incompatible Type in Hermes Critical
CVE-2021-24044 was published for hermes-engine (npm) Jan 16, 2022
Prototype Pollution in dotty Moderate
CVE-2021-23624 was published for dotty (npm) Nov 8, 2021
Cross-site Scripting in bootstrap-table Low
CVE-2021-23472 was published for bootstrap-table (npm) Nov 8, 2021
Prototype Pollution in node-jsonpointer Moderate
CVE-2021-23807 was published for jsonpointer (npm) Nov 8, 2021
Prototype Pollution in json-ptr Moderate
CVE-2021-23509 was published for json-ptr (npm) Nov 8, 2021
Prototype Pollution in json-pointer Moderate
CVE-2021-23820 was published for json-pointer (npm) Nov 8, 2021
G-Rath Credited to G-Rath
ProTip! Advisories are also available from the GraphQL API