Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

68 advisories

Loading
Waku: Cross-Origin CSRF on RSC Server Action Dispatch Moderate
CVE-2026-49455 was published for waku (npm) Jul 8, 2026
j0hndo Credited to j0hndo
Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF High
CVE-2026-50132 was published for @budibase/server (npm) Jun 22, 2026
VishaaLlKumaaRr Credited to VishaaLlKumaaRr
Uni-CLI: Legacy HTTP MCP transport accepted browser-originated localhost requests High
GHSA-v3f4-w7r7-v3hm was published for @zenalexa/unicli (npm) Jun 19, 2026
dodge1218 Credited to dodge1218
Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions Moderate
GHSA-mxjx-28vx-xjjj was published for network-ai (npm) Jun 19, 2026
EchoSkorJjj Credited to EchoSkorJjj
React Router: Potential CSRF via PUT/PATCH/DELETE document requests Low
CVE-2026-53663 was published for @remix-run/server-runtime (npm) Jun 15, 2026
gasbugs Credited to gasbugs
Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker Moderate
CVE-2026-48147 was published for @budibase/backend-core (npm) Jun 12, 2026
b-hermes Credited to b-hermes
Turbo: Login callback CSRF/session fixation Moderate
CVE-2026-45773 was published for turbo (npm) May 19, 2026
DanStuartDept Credited to DanStuartDept, jpleyden98, and ToshB jpleyden98 jpleyden98
ToshB ToshB
dynoxide: DNS rebinding and cross-origin CSRF via MCP HTTP transport High
GHSA-fvh2-gm75-j4j7 was published for dynoxide (npm) May 18, 2026
hicksy Credited to hicksy
Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCE Moderate
GHSA-wxw3-q3m9-c3jr was published for better-auth (npm) May 15, 2026
Jvr2022 Credited to Jvr2022 and alavesa alavesa alavesa
OpenClaude MCP OAuth Callback: State Check Bypass via error Param Leads to DoS Moderate
CVE-2026-42073 was published for @gitlawb/openclaude (npm) May 12, 2026
xancyber Credited to xancyber
RedwoodSDK has Same-site CSRF through lack of origin validation in its server actions Moderate
CVE-2026-42190 was published for rwsdk (npm) Apr 24, 2026
mthx Credited to mthx
Duplicate Advisory: OpenClaw: HTTP operator endpoints lack browser-origin validation in trusted-proxy mode Low
GHSA-2xp4-qhr4-xqm2 was published for openclaw (npm) Apr 24, 2026 withdrawn
gabiudrescu Credited to gabiudrescu
RedwoodSDK has a CSRF vulnerability in server function dispatch via GET requests High
CVE-2026-39371 was published for rwsdk (npm) Apr 8, 2026
zebbern Credited to zebbern
OpenClaw: HTTP operator endpoints lack browser-origin validation in trusted-proxy mode Low
CVE-2026-41347 was published for openclaw (npm) Apr 3, 2026
AntAISecurityLab Credited to AntAISecurityLab
Payload has a CSRF Protection Bypass in Authentication Flow Moderate
CVE-2026-34749 was published for payload (npm) Apr 1, 2026
Next.js: null origin can bypass Server Actions CSRF checks Moderate
CVE-2026-27978 was published for next (npm) Mar 17, 2026
Mercurius: Incorrect Content-Type parsing can lead to CSRF attack Moderate
CVE-2025-64166 was published for mercurius (npm) Mar 5, 2026
simone-sanfratello Credited to simone-sanfratello
Ghost has incomplete CSRF protections around OTC use High
CVE-2026-29784 was published for ghost (npm) Mar 5, 2026
Parse Dashboard is Missing CSRF Protection for its Agent Endpoint High
CVE-2026-27609 was published for parse-dashboard (npm) Feb 25, 2026
mtrezza Credited to mtrezza
OpenClaw Chutes manual OAuth state validation bypass can cause credential substitution Moderate
CVE-2026-28477 was published for openclaw (npm) Feb 18, 2026
vincentkoc Credited to vincentkoc
unity-cli Exposes Plaintext Credentials in Debug Logs (sign-package command) Moderate
CVE-2026-25918 was published for @rage-against-the-pixel/unity-cli (npm) Feb 10, 2026
Qwik City has a CSRF Protection Bypass via Content-Type Header Validation Moderate
CVE-2026-25151 was published for @builder.io/qwik-city (npm) Feb 3, 2026
KageShiron Credited to KageShiron
ProTip! Advisories are also available from the GraphQL API