GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,800
Maven
5,000+
npm
4,426
NuGet
773
pip
4,199
Pub
12
RubyGems
968
Rust
1,086
Swift
47
Unreviewed advisories
All unreviewed
5,000+
4,426 advisories
Filter by severity
Angular has XSS Vulnerability via Unsanitized SVG Script Attributes
High
CVE-2026-22610
was published
for
@angular/compiler
(npm)
Jan 9, 2026
JavaScript SDK v2 users should add validation to the region parameter value in or migrate to v3
Low
GHSA-j965-2qgj-vjmq
was published
for
aws-sdk
(npm)
Jan 8, 2026
AWS SDK for JavaScript v3 adopted defense in depth enhancement for region parameter value
Low
GHSA-6475-r3vj-m8vf
was published
for
@smithy/config-resolver
(npm)
Jan 8, 2026
Ghost has SQL Injection in Members Activity Feed
Moderate
CVE-2026-22596
was published
for
ghost
(npm)
Jan 8, 2026
Ghost has SSRF via External Media Inliner
Moderate
CVE-2026-22597
was published
for
ghost
(npm)
Jan 8, 2026
Ghost has Staff Token permission bypass
High
CVE-2026-22595
was published
for
ghost
(npm)
Jan 8, 2026
Elliptic Uses a Cryptographic Primitive with a Risky Implementation
Low
CVE-2025-14505
was published
for
elliptic
(npm)
Jan 8, 2026
Shakapacker has environment variable leak via EnvironmentPlugin that exposes secrets to client-side bundles
High
GHSA-96qw-h329-v5rg
was published
for
shakapacker
(RubyGems)
Jan 8, 2026
React Router has CSRF issue in Action/Server Action Request Processing
Moderate
CVE-2026-22030
was published
for
@remix-run/server-runtime
(npm)
Jan 8, 2026
React Router vulnerable to XSS via Open Redirects
High
CVE-2026-22029
was published
for
@remix-run/router
(npm)
Jan 8, 2026
React Router SSR XSS in ScrollRestoration
High
CVE-2026-21884
was published
for
@remix-run/react
(npm)
Jan 8, 2026
React Router has unexpected external redirect via untrusted paths
Moderate
CVE-2025-68470
was published
for
react-router
(npm)
Jan 8, 2026
React Router has Path Traversal in File Session Storage
Critical
CVE-2025-61686
was published
for
@react-router/node
(npm)
Jan 8, 2026
React Router has XSS Vulnerability
High
CVE-2025-59057
was published
for
@remix-run/react
(npm)
Jan 8, 2026
Preact has JSON VNode Injection issue
High
CVE-2026-22028
was published
for
preact
(npm)
Jan 7, 2026
n8n's Missing Stripe-Signature Verification Allows Unauthenticated Forged Webhooks
Moderate
CVE-2026-21894
was published
for
n8n
(npm)
Jan 7, 2026
n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling
Critical
CVE-2026-21858
was published
for
n8n
(npm)
Jan 7, 2026
pnpm v10+ Bypass "Dependency lifecycle scripts execution disabled by default"
High
CVE-2025-69264
was published
for
pnpm
(npm)
Jan 7, 2026
pnpm Has Lockfile Integrity Bypass that Allows Remote Dynamic Dependencies
High
CVE-2025-69263
was published
for
pnpm
(npm)
Jan 7, 2026
pnpm vulnerable to Command Injection via environment variable substitution
High
CVE-2025-69262
was published
for
pnpm
(npm)
Jan 7, 2026
fast-filesystem-mcp has a Path Traversal vulnerability
High
CVE-2025-67364
was published
for
fast-filesystem-mcp
(npm)
Jan 7, 2026
Microsoft Playwright MCP Server vulnerable to DNS Rebinding Attack; Allows Attackers Access to All Server Tools
High
CVE-2025-9611
was published
for
@playwright/mcp
(npm)
Jan 7, 2026
Directus has open redirect in SAML
Moderate
CVE-2026-22032
was published
for
@directus/api
(npm)
Jan 6, 2026
ProTip!
Advisories are also available from the
GraphQL API