GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
57 advisories
Filter by severity
Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billing Manipulation
High
CVE-2026-70476
was published
for
flowise
(npm)
Aug 4, 2026
OpenClaw: Paired nodes could forge exec lifecycle events without system.run provenance
High
CVE-2026-53816
was published
for
openclaw
(npm)
Jul 2, 2026
OpenClaw's POSIX node system.run safe-bin allowlist could be widened by shell expansion
High
CVE-2026-53831
was published
for
openclaw
(npm)
Jul 2, 2026
OpenClaw: Hook-triggered CLI runs could receive owner MCP tool authority
High
CVE-2026-53814
was published
for
openclaw
(npm)
Jul 2, 2026
OpenClaw: Control UI locality spoofing could mint a durable admin device token
High
CVE-2026-53817
was published
for
openclaw
(npm)
Jul 2, 2026
OpenClaw: Same-host trusted-proxy deployments could accept local forged identity headers
High
CVE-2026-53832
was published
for
openclaw
(npm)
Jul 2, 2026
OpenClaw's marketplace runtime extension metadata could point at unscanned payloads
High
CVE-2026-53810
was published
for
openclaw
(npm)
Jul 2, 2026
OpenClaw: Shell wrapper argv could change between approval and execution
High
GHSA-2j8v-hwgc-x698
was published
for
Openclaw
(npm)
Jul 2, 2026
OpenClaw: Exec approval display truncation could hide the command being approved
High
GHSA-xww8-gqvh-92x9
was published
for
openclaw
(npm)
Jul 2, 2026
Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF
High
CVE-2026-50132
was published
for
@budibase/server
(npm)
Jun 22, 2026
OpenClaw: Shell positional parameters could weaken strict inline-eval checks
High
CVE-2026-53855
was published
for
openclaw
(npm)
Jun 18, 2026
OpenClaw: Pairing-scoped device session could restore revoked node token authority
High
CVE-2026-53843
was published
for
openclaw
(npm)
Jun 18, 2026
n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints
High
CVE-2026-54305
was published
for
n8n
(npm)
Jun 16, 2026
@hulumi/policies has a HULUMI-H5 bypass via decoy sibling resources targeting a different bucket
High
CVE-2026-48034
was published
for
@hulumi/policies
(npm)
Jun 10, 2026
AgenticMail API/storage and outbound relay hardening fixes
High
CVE-2026-47255
was published
for
@agenticmail/api
(npm)
May 29, 2026
FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection
High
CVE-2026-43945
was published
for
@frangoteam/fuxa
(npm)
May 26, 2026
@hulumi/policies: HULUMI-H1 SecureBucket parent spoof bypass
High
GHSA-g43v-9x7q-83pq
was published
for
@hulumi/policies
(npm)
May 21, 2026
n8n-MCP: Multi-tenant MCP requests fall back to process-level n8n credentials when tenant headers are absent or incomplete
High
CVE-2026-45707
was published
for
n8n-mcp
(npm)
May 18, 2026
FlowiseAI has Mass Assignment in Assistant Update Endpoint that Allows Cross-Workspace Resource Reassignment
High
CVE-2026-46441
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI has Mass Assignment in Chatflow Update Endpoint that Allows Cross-Workspace AgentFlow Reassignment
High
CVE-2026-42863
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI has Mass Assignment in Tool Update Endpoint that Allows Cross-Workspace Resource Reassignment
High
CVE-2026-42862
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI has Mass Assignment in Variable Update Endpoint that Allows Cross-Workspace Resource Reassignment
High
CVE-2026-42861
was published
for
flowise
(npm)
May 14, 2026
OpenClaw: MCP loopback owner context is derived from server-issued bearer tokens
High
CVE-2026-44118
was published
for
openclaw
(npm)
May 4, 2026
OpenLearnX has Critical Remote Code Execution Through Python Sandbox Escape via Code Execution Environment
High
CVE-2026-41900
was published
for
openlearnx
(npm)
Apr 23, 2026
Actual has Privilege Escalation via 'change-password' Endpoint on OpenID-Migrated Servers
High
CVE-2026-33318
was published
for
@actual-app/sync-server
(npm)
Apr 23, 2026
ProTip!
Advisories are also available from the
GraphQL API