GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
108 advisories
Filter by severity
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
CVE-2026-75911
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
CVE-2026-75858
was published
for
codewhale
(npm)
Sep 4, 2026
pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on install
High
CVE-2026-82393
was published
for
pnpm
(npm)
Sep 2, 2026
Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props
High
CVE-2026-71320
was published
for
nuxt
(npm)
Aug 5, 2026
AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping
High
CVE-2026-11393
was published
for
@aws/agentcore
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
High
CVE-2026-54666
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped enum string values
High
CVE-2026-54664
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
High
CVE-2026-54661
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
High
CVE-2026-54662
was published
for
swagger-typescript-api
(npm)
Jul 29, 2026
n8n: Expression sandbox escape via arrow-function bodies enabling command execution
High
GHSA-gv7g-jm28-cr3m
was published
for
n8n
(npm)
Jul 22, 2026
Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader
High
CVE-2026-53597
was published
for
@prompty/core
(npm)
Jul 17, 2026
protobufjs-cli: Code injection in pbjs static output from crafted JSON descriptor names
High
CVE-2026-54271
was published
for
protobufjs-cli
(npm)
Jun 15, 2026
DbGate: Remote Code Execution via functionName injection in loadReader endpoint
High
CVE-2026-48017
was published
for
dbgate-api
(npm)
Jun 5, 2026
OpenClaw's marketplace runtime extension metadata could point at unscanned payloads
High
CVE-2026-53810
was published
for
openclaw
(npm)
Jul 2, 2026
@tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels
High
CVE-2026-54074
was published
for
@tinacms/cli
(npm)
Jun 19, 2026
piscina: Prototype Pollution Gadget → RCE via inherited options.filename
High
CVE-2026-55388
was published
for
piscina
(npm)
Jun 18, 2026
axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
High
CVE-2026-44495
was published
for
axios
(npm)
May 29, 2026
OpenZeppelin Contracts Wizard has Code Injection in Generated Hardhat and Foundry Tests via Unsanitized opts.name / opts.uri
High
CVE-2026-48054
was published
for
@openzeppelin/wizard
(npm)
Jun 11, 2026
claude-code-cache-fix vulnerable to local code execution via Python triple-quote injection in tools/quota-statusline.sh
High
CVE-2026-45136
was published
for
claude-code-cache-fix
(npm)
May 13, 2026
@babel/plugin-transform-modules-systemjs generates arbitrary code when compiling malicious input
High
CVE-2026-44728
was published
for
@babel/plugin-transform-modules-systemjs
(npm)
May 8, 2026
browserstack-runner vulnerable to Remote Code Execution via vm sandbox escape in _log HTTP handler
High
CVE-2026-49143
was published
for
browserstack-runner
(npm)
Jun 3, 2026
FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection
High
CVE-2026-43945
was published
for
@frangoteam/fuxa
(npm)
May 26, 2026
OpenClaw vulnerable to arbitrary code execution via attacker-controlled setup-api.js loaded from cwd during env-key resolution
High
CVE-2026-45004
was published
for
openclaw
(npm)
May 5, 2026
protobuf.js: Code injection in pbjs static output from crafted schema names
High
CVE-2026-44295
was published
for
protobufjs-cli
(npm)
May 12, 2026
protobuf.js: Code generation gadget after prototype pollution
High
CVE-2026-44291
was published
for
protobufjs
(npm)
May 12, 2026
ProTip!
Advisories are also available from the
GraphQL API