Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

291 advisories

Loading
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
sai-sh Credited to sai-sh
Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout) Critical
CVE-2026-62681 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m and mrostamipoor mrostamipoor mrostamipoor
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via schema default -> zod module-level template literal Critical
CVE-2026-72717 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via array-items default -> zod module-level template literal Critical
CVE-2026-71869 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via header-parameter default -> zod module-level template literal Critical
CVE-2026-71871 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via enum-typed default -> zod module-level template literal Critical
CVE-2026-71868 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via query parameter name -> computed-property-key injection in the zod cli Critical
CVE-2026-71865 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Gal3m Credited to Gal3m, mrostamipoor, aqeelat, and mohammad228 mrostamipoor mrostamipoor
aqeelat aqeelat mohammad228 mohammad228
YouTransfer has an issue in the sendmail transport integration that allows arbitrary code execution Critical
CVE-2026-50880 was published for youtransfer (npm) Jun 15, 2026
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions Critical
CVE-2026-77415 was published for jsonata (npm) Aug 21, 2026
c0rydoras Credited to c0rydoras
JSONata vulnerable to Arbitrary Code Execution via crafted JSONata expressions Critical
CVE-2026-77414 was published for jsonata (npm) Aug 21, 2026
c0rydoras Credited to c0rydoras
JSONata: Arbitrary Code Execution via crafted JSONata expressions Critical
CVE-2026-77413 was published for jsonata (npm) Aug 21, 2026
peaktwilight Credited to peaktwilight and c0rydoras c0rydoras c0rydoras
TypeORM: migration:generate template-literal code injection Moderate
CVE-2026-73651 was published for typeorm (npm) Jul 21, 2026
smith-xyz Credited to smith-xyz
cruzryan Credited to cruzryan and cuauht cuauht cuauht
Mermaid allows CSS injection applying to sibling elements of the diagram Moderate
CVE-2026-50159 was published for mermaid (npm) Aug 6, 2026
h3ri0s Credited to h3ri0s and aloisklink aloisklink aloisklink
Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host Critical
CVE-2026-71319 was published for @nuxt/devtools (npm) Aug 5, 2026
TazmiDev Credited to TazmiDev and anzuukino anzuukino anzuukino
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter Moderate
CVE-2026-70609 was published for electron (npm) Aug 5, 2026
hackerman70000 Credited to hackerman70000
Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability Critical
CVE-2026-70477 was published for flowise (npm) Aug 4, 2026
zdi-disclosures Credited to zdi-disclosures
Flowise: Remote Code Execution Vulnerability in CSVAgent Critical
CVE-2026-69256 was published for flowise (npm) Aug 4, 2026
jia-elttam Credited to jia-elttam
amwhoi Credited to amwhoi
Flowise RCE via SQLite Record Manager Node Critical
CVE-2026-69259 was published for flowise (npm) Aug 4, 2026
alex-elttam Credited to alex-elttam
ProTip! Advisories are also available from the GraphQL API