GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,407
Maven
5,000+
npm
5,000+
NuGet
1,048
pip
5,000+
Pub
13
RubyGems
1,127
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
4,733 advisories
Filter by severity
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`)
High
GHSA-pppj-hq3g-57pj
was published
for
jupyterlab
(pip)
Jul 22, 2026
JupyterLab: Image viewer allows XSS when opening malicious image in new browser tab
High
GHSA-gx64-gj6p-pc4c
was published
for
jupyterlab
(pip)
Jul 22, 2026
n8n: Stored DOM XSS via Resource Locator `cachedResultUrl`
High
CVE-2026-65592
was published
for
n8n
(npm)
Jul 22, 2026
n8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
High
CVE-2026-65597
was published
for
n8n
(npm)
Jul 22, 2026
Duplicate Advisory: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview
High
GHSA-vhcw-f978-xjjg
was published
for
n8n
(npm)
Jul 22, 2026
•
withdrawn
Duplicate Advisory: Stored DOM XSS via Resource Locator `cachedResultUrl`
High
GHSA-h5xr-fqvj-253p
was published
for
n8n
(npm)
Jul 22, 2026
•
withdrawn
Rails HTML Sanitizers: Possible XSS vulnerability with certain configurations
Moderate
GHSA-cj75-f6xr-r4g7
was published
for
rails-html-sanitizer
(RubyGems)
Jul 21, 2026
Loofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
Low
GHSA-5qhf-9phg-95m2
was published
for
loofah
(RubyGems)
Jul 21, 2026
Loofah: SVG `href` attribute bypasses local-reference restriction
Moderate
GHSA-9wjq-cp2p-hrgf
was published
for
loofah
(RubyGems)
Jul 21, 2026
SVGO removeScripts plugin leaves some executable scripts intact
High
GHSA-2p49-hgcm-8545
was published
for
svgo
(npm)
Jul 21, 2026
DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.
Low
GHSA-c2j3-45gr-mqc4
was published
for
dompurify
(npm)
Jul 21, 2026
Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
Moderate
CVE-2026-59895
was published
for
hono
(npm)
Jul 21, 2026
Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)
Moderate
CVE-2026-59729
was published
for
astro
(npm)
Jul 20, 2026
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands
Low
CVE-2026-59727
was published
for
astro
(npm)
Jul 20, 2026
Mistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and chained schemes that historically chain to `javascript:` execution
Moderate
CVE-2026-59929
was published
for
mistune
(pip)
Jul 20, 2026
Mistune: XSS via unescaped class option in Admonition directive
Moderate
CVE-2026-59926
was published
for
mistune
(pip)
Jul 20, 2026
Mistune: XSS via percent-encoded javascript URI bypass in safe_url()
Moderate
CVE-2026-59923
was published
for
mistune
(pip)
Jul 20, 2026
Astro: Reflected XSS via unescaped View Transition animation properties
Moderate
GHSA-4g3v-8h47-v7g6
was published
for
astro
(npm)
Jul 20, 2026
Tornado vulnerable to Header Injection and XSS via reason argument
Moderate
CVE-2025-67724
was published
for
tornado
(pip)
Jul 20, 2026
ViewComponent: around_render HTML-Safety Bypass
High
CVE-2026-54498
was published
for
view_component
(RubyGems)
Jul 15, 2026
MantisBT: Stored XSS in print_all_bug_page_word.php
High
CVE-2026-62944
was published
for
mantisbt/mantisbt
(Composer)
Jul 15, 2026
MantisBT: Reflected XSS in admin/install.php via unescaped printf
Critical
CVE-2026-52881
was published
for
mantisbt/mantisbt
(Composer)
Jul 15, 2026
MantisBT: Reflected XSS in admin/install.php
Critical
CVE-2026-52847
was published
for
mantisbt/mantisbt
(Composer)
Jul 15, 2026
EasyAdmin: Stored Cross-Site Scripting (XSS) via uploaded files served inline in FileField and ImageField
High
CVE-2026-54087
was published
for
easycorp/easyadmin-bundle
(Composer)
Jul 14, 2026
FacturaScripts: Stored XSS in WidgetVariante and WidgetSubcuenta modal lists via HTML-attribute decoding of `Tools::noHtml`-escaped quotes inside `onclick=`
Low
CVE-2026-45710
was published
for
facturascripts/facturascripts
(Composer)
Jul 14, 2026
ProTip!
Advisories are also available from the
GraphQL API