GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,786
Maven
5,000+
npm
4,393
NuGet
772
pip
4,166
Pub
12
RubyGems
965
Rust
1,073
Swift
45
Unreviewed advisories
All unreviewed
5,000+
4,394 advisories
Filter by severity
AdonisJS Path Traversal in Multipart File Handling
Critical
CVE-2026-21440
was published
for
@adonisjs/bodyparser
(npm)
Jan 2, 2026
Signal K Server vulnerable to JWT Token Theft via WebSocket Enumeration and Unauthenticated Polling
Critical
CVE-2025-68620
was published
for
signalk-server
(npm)
Jan 2, 2026
Signal K Server Vulnerable to Access Request Spoofing
Moderate
CVE-2025-69203
was published
for
signalk-server
(npm)
Jan 2, 2026
Signal K Server Vulnerable to Remote Code Execution via Malicious npm Package
High
CVE-2025-68619
was published
for
signalk-server
(npm)
Jan 2, 2026
Signal K Server Vulnerable to Unauthenticated Information Disclosure via Exposed Endpoints
Moderate
CVE-2025-68273
was published
for
signalk-server
(npm)
Jan 2, 2026
Signal K Server Vulnerable to Denial of Service via Unrestricted Access Request Flooding
High
CVE-2025-68272
was published
for
signalk-server
(npm)
Jan 2, 2026
Signal K Server has Unauthenticated State Pollution leading to Remote Code Execution (RCE)
Critical
CVE-2025-66398
was published
for
signalk-server
(npm)
Jan 2, 2026
Trix has a stored XSS vulnerability through its attachment attribute
Moderate
GHSA-g9jg-w8vm-g96v
was published
for
action_text-trix
(RubyGems)
Dec 31, 2025
serverless MCP Server vulnerable to Command Injection in list-projects tool
High
CVE-2025-69256
was published
for
serverless
(npm)
Dec 31, 2025
qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion
High
CVE-2025-15284
was published
for
qs
(npm)
Dec 30, 2025
PsiTransfer has Zip Slip Path Traversal via TAR Archive Download
High
GHSA-xphh-5v4r-r3rx
was published
for
psitransfer
(npm)
Dec 30, 2025
axios-cache-interceptor Vulnerable to Cache Poisoning via Ignored HTTP Vary Header
Moderate
CVE-2025-69202
was published
for
axios-cache-interceptor
(npm)
Dec 30, 2025
Nest has a Fastify URL Encoding Middleware Bypass (TOCTOU)
Moderate
CVE-2025-69211
was published
for
@nestjs/platform-fastify
(npm)
Dec 30, 2025
hemmelig allows SSRF Filter bypass via Secret Request functionality
Moderate
CVE-2025-69206
was published
for
hemmelig
(npm)
Dec 29, 2025
apidoc-core has a prototype pollution vulnerability
Critical
CVE-2025-13158
was published
for
apidoc-core
(npm)
Dec 26, 2025
Self-hosted n8n has Legacy Code node that enables arbitrary file read/write
High
CVE-2025-68697
was published
for
n8n
(npm)
Dec 26, 2025
n8n Vulnerable to Arbitrary Command Execution in Pyodide based Python Code Node
Critical
CVE-2025-68668
was published
for
n8n
(npm)
Dec 26, 2025
n8n's Possible Stored XSS in "Respond to Webhook" Node May Execute Outside iframe Sandbox
High
CVE-2025-61914
was published
for
n8n
(npm)
Dec 26, 2025
libxmljs has segmentation fault, potentially leading to a denial-of-service (DoS)
High
CVE-2025-25341
was published
for
libxmljs
(npm)
Dec 26, 2025
LangChain serialization injection vulnerability enables secret extraction
High
CVE-2025-68665
was published
for
@langchain/core
(npm)
Dec 23, 2025
Fedify has ReDoS Vulnerability in HTML Parsing Regex
High
CVE-2025-68475
was published
for
@fedify/fedify
(npm)
Dec 22, 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
Critical
CVE-2025-68613
was published
for
n8n
(npm)
Dec 22, 2025
Tuta Mail has DOM attribute and CSS injection in its Contact Viewer feature
Low
GHSA-24v3-254g-jv85
was published
for
@tutao/tutanota-utils
(npm)
Dec 19, 2025
Orejime has executable code in HTML attributes
Low
CVE-2025-68457
was published
for
orejime
(npm)
Dec 19, 2025
Storybook manager bundle may expose environment variables during build
High
CVE-2025-68429
was published
for
storybook
(npm)
Dec 18, 2025
ProTip!
Advisories are also available from the
GraphQL API