Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2,189 advisories

Loading
Mermaid: Improper sanitization of `classDefs` in diagrams leads to CSS injection Moderate
CVE-2026-41148 was published for mermaid (npm) May 11, 2026
matejsmycka Credited to matejsmycka and aloisklink aloisklink aloisklink
Duplicate Advisory: OpenClaw: Hook mapping templates could bypass hook session-key opt-in Moderate
GHSA-9j32-3m66-mc4m was published for openclaw (npm) May 11, 2026 withdrawn
Duplicate Advisory: OpenClaw: Workspace dotenv files cannot override connector endpoint hosts Moderate
GHSA-5jgm-f9wr-9qm7 was published for openclaw (npm) May 11, 2026 withdrawn
Duplicate Advisory: OpenClaw's Webhooks SecretRef route secret remains valid after rotation/reload Moderate
GHSA-v8j2-5f9p-fmh4 was published for openclaw (npm) May 11, 2026 withdrawn
Duplicate Advisory: OpenClaw: MCP stdio server env could load dangerous startup variables from workspace config Moderate
GHSA-p3m6-jr2h-hhxj was published for openclaw (npm) May 11, 2026 withdrawn
Duplicate Advisory: OpenClaw: Workspace dotenv MiniMax host override could redirect credentialed requests Moderate
GHSA-4mhr-cxr4-2prm was published for openclaw (npm) May 11, 2026 withdrawn
Duplicate Advisory: OpenClaw: Isolated cron awareness events were recorded as trusted system events Moderate
GHSA-m5j2-r859-r5cv was published for openclaw (npm) May 11, 2026 withdrawn
Next.js vulnerable to cross-site scripting in App Router applications using CSP nonces Moderate
CVE-2026-44581 was published for next (npm) May 11, 2026
Next.js has cross-site scripting in beforeInteractive scripts with untrusted input Moderate
CVE-2026-44580 was published for next (npm) May 11, 2026
Next.js has a Denial of Service in the Image Optimization API Moderate
CVE-2026-44577 was published for next (npm) May 11, 2026
Next.js vulnerable to cache poisoning in React Server Component responses Moderate
CVE-2026-44576 was published for next (npm) May 11, 2026
Hono has CSS Declaration Injection via Style Object Values in JSX SSR Moderate
CVE-2026-44458 was published for hono (npm) May 9, 2026
Gayang2902 Credited to Gayang2902
Danny-Devs Credited to Danny-Devs
eventsource-encoder vulnerable to SSE event injection via unsanitized `event` and `id` fields Moderate
CVE-2026-44214 was published for eventsource-encoder (npm) May 8, 2026
@cyclonedx/cdxgen: Docker registry auth substring match forwards credentials to a different registry Moderate
GHSA-qhh4-458h-xwh2 was published for @cyclonedx/cdxgen (npm) May 8, 2026
Electerm's full process.env exposed to renderer via window.pre.env Moderate
CVE-2026-43942 was published for electerm (npm) May 8, 2026
osageling Credited to osageling
fast-xml-builder Comment Value regex can be bypassed Moderate
CVE-2026-44664 was published for fast-xml-builder (npm) May 8, 2026
amitguptagwl Credited to amitguptagwl
vm2 has access to `VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL` Moderate
GHSA-2cm2-m3w5-gp2f was published for vm2 (npm) May 8, 2026
XmiliaH Credited to XmiliaH
short-video-maker has a path traversal vulnerability Moderate
CVE-2026-8115 was published for short-video-maker (npm) May 8, 2026
vm2's Transformer Fast-Path Bypass Exposes Internal State Variable Moderate
CVE-2026-44003 was published for vm2 (npm) May 7, 2026
koDove Credited to koDove
vm2 is Vulnerable to Host File Path Disclosure via Stack Trace Information Leak Moderate
CVE-2026-44002 was published for vm2 (npm) May 7, 2026
koDove Credited to koDove
vm2 Host Promise Resolution Preserves Object Identity Across Sandbox Boundary Moderate
CVE-2026-44000 was published for vm2 (npm) May 7, 2026
fasrm Credited to fasrm
Vercel: Non-interactive mode includes CLI arguments in suggested command output Moderate
CVE-2026-44479 was published for vercel (npm) May 7, 2026
Hono: bodyLimit() can be bypassed for chunked / unknown-length requests Moderate
CVE-2026-44456 was published for hono (npm) May 6, 2026
lalalala5678 Credited to lalalala5678 and Jvr2022 Jvr2022 Jvr2022
hono/jsx has Unvalidated JSX Tag Names that May Allow HTML Injection Moderate
CVE-2026-44455 was published for hono (npm) May 6, 2026
TarPeg007 Credited to TarPeg007
ProTip! Advisories are also available from the GraphQL API