Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,347 advisories

Loading
juli Credited to juli
Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host Critical
CVE-2026-71319 was published for @nuxt/devtools (npm) Aug 5, 2026
TazmiDev Credited to TazmiDev and anzuukino anzuukino anzuukino
DeathsPirate Credited to DeathsPirate
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability Critical
CVE-2026-70477 was published for flowise (npm) Aug 4, 2026
zdi-disclosures Credited to zdi-disclosures
amwhoi Credited to amwhoi
Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE Critical
CVE-2026-70470 was published for flowise (npm) Aug 4, 2026
fg0x0 Credited to fg0x0
Flowise RCE via SQLite Record Manager Node Critical
CVE-2026-69259 was published for flowise (npm) Aug 4, 2026
alex-elttam Credited to alex-elttam
Flowise: Remote Code Execution Vulnerability in CSVAgent Critical
CVE-2026-69256 was published for flowise (npm) Aug 4, 2026
jia-elttam Credited to jia-elttam
Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified Critical
CVE-2026-69255 was published for flowise (npm) Aug 4, 2026
lexi-core-ai Credited to lexi-core-ai
Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override Critical
CVE-2026-69254 was published for flowise (npm) Aug 4, 2026
akshat-sj Credited to akshat-sj
Flowise Sandbox Escape to RCE Critical
CVE-2026-69253 was published for flowise (npm) Aug 4, 2026
alex-elttam Credited to alex-elttam
Flowise RCE via TypeORM DataSource Critical
CVE-2026-69251 was published for flowise (npm) Aug 4, 2026
alex-elttam Credited to alex-elttam
Sequelize: SQL Injection (Oracle DB) Critical
CVE-2026-69240 was published for sequelize (npm) Aug 3, 2026
t-tera Credited to t-tera
H3xV0rT3x Credited to H3xV0rT3x
NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE Critical
CVE-2026-52887 was published for @nocobase/plugin-notification-in-app-message (npm) Jul 31, 2026
kah-ja Credited to kah-ja
AWS Amplify Studio UI Component Properties Has an Input Validation Issue Critical
CVE-2025-4318 was published for @aws-amplify/codegen-ui-react (npm) Jul 30, 2026
@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution Critical
CVE-2026-54658 was published for @hypequery/clickhouse (npm) Jul 28, 2026
cobyge Credited to cobyge and BarakSrour BarakSrour BarakSrour
Shescape: Shell injection via unescaped parentheses on Windows with CMD Critical
GHSA-w4hw-qcx7-56pr was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock Critical
GHSA-vh45-f885-3848 was published for sm-crypto (npm) Jul 24, 2026
afldl Credited to afldl
Budibase: Unauthenticated REST Datasource Credential Theft via Cross-Origin Auth Leak Critical
GHSA-mqhr-6j6h-74p5 was published for @budibase/server (npm) Jul 24, 2026
Hasinohacker Credited to Hasinohacker
Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified Critical
GHSA-hp6v-6jw7-gv2f was published for @budibase/server (npm) Jul 24, 2026
freeman-bb Credited to freeman-bb
Budibase: SQL Injection via `multipleStatements: true` Critical
GHSA-q6x4-v3qx-85qw was published for @budibase/server (npm) Jul 24, 2026
kaimandalic Credited to kaimandalic
Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer Critical
GHSA-w28w-gp39-m4p6 was published for @prompty/core (npm) Jul 24, 2026
lexdotdev Credited to lexdotdev
Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix) Critical
GHSA-7gfh-x38p-prh3 was published for velocityjs (npm) Jul 24, 2026
cruzryan Credited to cruzryan
mufeedvh Credited to mufeedvh
ProTip! Advisories are also available from the GraphQL API