GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,428
Maven
5,000+
npm
5,000+
NuGet
1,088
pip
5,000+
Pub
13
RubyGems
1,129
Rust
1,506
Swift
62
Unreviewed advisories
All unreviewed
5,000+
32 advisories
Filter by severity
Budibase: NoSQL Injection via JSON Parameter Interpolation in MongoDB Query Execution
High
GHSA-qw6m-8fw2-2v64
was published
for
@budibase/server
(npm)
Jul 24, 2026
LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce
High
CVE-2026-55575
was published
for
liquidjs
(npm)
Jul 24, 2026
PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
High
CVE-2026-45623
was published
for
postcss
(npm)
Jul 23, 2026
Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override
High
CVE-2026-54351
was published
for
@budibase/server
(npm)
Jun 22, 2026
LiquidJS Vulnerable to ReDoS via Quadratic Backtracking in `strip_html` Filter Regex
High
CVE-2026-45617
was published
for
liquidjs
(npm)
May 27, 2026
LiquidJS has a memory and render limit bypass via unbounded width padding in `date` filter (strftime)
High
CVE-2026-45357
was published
for
liquidjs
(npm)
May 27, 2026
Budibase: Builder-to-Admin Privilege Escalation via onboardUsers Endpoint Without SMTP Configuration
High
CVE-2026-45716
was published
for
@budibase/worker
(npm)
May 18, 2026
FlowiseAI: Evaluator create+update mass-assignment allows cross-workspace evaluator takeover
High
CVE-2026-46480
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI: Evaluation create+update mass-assignment allows cross-workspace evaluation takeover
High
CVE-2026-46479
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI: DatasetRow create+update mass-assignment allows cross-workspace row takeover
High
CVE-2026-46478
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI: Dataset create+update mass-assignment allows cross-workspace dataset takeover
High
CVE-2026-46477
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI: CustomTemplate create+update mass-assignment allows cross-workspace template takeover
High
CVE-2026-46476
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI: Assistant create+update mass-assignment allows cross-workspace assistant takeover
High
CVE-2026-46475
was published
for
flowise
(npm)
May 14, 2026
@evomap/evolver's validator sandbox allowlist permits `npm`/`npx`, yielding RCE from Hub-delivered validation tasks via lifecycle scripts
High
GHSA-jxh8-jh77-xh6g
was published
for
@evomap/evolver
(npm)
May 5, 2026
@evomap/evolver: Path Traversal in `evolver fetch` default-branch `safeId` allows Hub-controlled overwrite of project files (RCE)
High
GHSA-cfcj-hqpf-hccf
was published
for
@evomap/evolver
(npm)
May 5, 2026
basic-ftp: Incomplete CRLF Injection Protection Allows Arbitrary FTP Command Execution via Credentials and MKD Commands
High
GHSA-6v7q-wjvx-w8wg
was published
for
basic-ftp
(npm)
Apr 10, 2026
Parser Server's streaming file download bypasses afterFind file trigger authorization
High
CVE-2026-34784
was published
for
parse-server
(npm)
Apr 1, 2026
@tinacms/graphql's `FilesystemBridge` Path Validation Can Be Bypassed via Symlinks or Junctions
High
CVE-2026-34604
was published
for
@tinacms/graphql
(npm)
Apr 1, 2026
@tinacms/graphql's Media Endpoints Can Escape the Media Root via Symlinks or Junctions
High
CVE-2026-34603
was published
for
@tinacms/graphql
(npm)
Apr 1, 2026
Parse Server exposes auth data via verify password endpoint
High
CVE-2026-34215
was published
for
parse-server
(npm)
Mar 29, 2026
Kysely has a MySQL SQL Injection via Insufficient Backslash Escaping in `sql.lit(string)` usage or similar methods that append string literal values into the compiled SQL strings
High
CVE-2026-33468
was published
for
kysely
(npm)
Mar 20, 2026
Kysely has a MySQL SQL Injection via Backslash Escape Bypass in non-type-safe usage of JSON path keys.
High
CVE-2026-33442
was published
for
kysely
(npm)
Mar 20, 2026
Parse Server's LiveQuery bypasses CLP pointer permission enforcement
High
CVE-2026-33421
was published
for
parse-server
(npm)
Mar 20, 2026
SVG Dimension Capping Bypass via XML Comment Injection in @dicebear/converter ensureSize()
High
CVE-2026-33418
was published
for
@dicebear/converter
(npm)
Mar 20, 2026
Parse Server has an auth provider validation bypass on login via partial authData
High
CVE-2026-33409
was published
for
parse-server
(npm)
Mar 19, 2026
ProTip!
Advisories are also available from the
GraphQL API