Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

569 advisories

Loading
Trix: Stored XSS via HTMLParser attribute injection on paste Moderate
GHSA-53g2-mvcc-q9x3 was published for action_text-trix (RubyGems) Jul 24, 2026
newbiefromcoma Credited to newbiefromcoma
React Router: RSCErrorHandler Missing Protocol Validation (XSS) Moderate
CVE-2026-53667 was published for react-router (npm) Jul 23, 2026
unknownhad Credited to unknownhad
Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility Moderate
CVE-2026-59895 was published for hono (npm) Jul 21, 2026
a-tt-om Credited to a-tt-om and teebow1e teebow1e teebow1e
thientd Credited to thientd
Astro: Reflected XSS via unescaped View Transition animation properties Moderate
GHSA-4g3v-8h47-v7g6 was published for astro (npm) Jul 20, 2026
Ryoga-exe Credited to Ryoga-exe
@asymmetric-effort/specifyjs: CSS expression sanitization is bypassable in renderToString Moderate
CVE-2026-50290 was published for @asymmetric-effort/specifyjs (npm) Jul 2, 2026
devbridge-autocomplete has XSS in its default formatters: formatGroup and formatResult fail to escape HTML in untrusted inputs Moderate
GHSA-hvqh-jw65-wcpq was published for devbridge-autocomplete (npm) Jun 22, 2026
junowilderness Credited to junowilderness
Outerbase Studio: Stored XSS in Text Widget Leads to Authentication Token Exposure Moderate
CVE-2026-55650 was published for @outerbase/studio (npm) Jun 19, 2026
hunt-with-4bh1 Credited to hunt-with-4bh1
OpenClaw: Exported session HTML could keep unsafe markdown links Moderate
CVE-2026-53841 was published for openclaw (npm) Jun 18, 2026
YLChen-007 Credited to YLChen-007
trace37labs Credited to trace37labs and EchoTydes EchoTydes EchoTydes
NocoDB: Stored Cross-Site Scripting via Secure Attachment Moderate
CVE-2026-53929 was published for nocodb (npm) Jun 17, 2026
bugbunny-research Credited to bugbunny-research
sm1ee Credited to sm1ee
Astro: XSS via Unescaped Attribute Names in Spread Props Moderate
CVE-2026-54298 was published for astro (npm) Jun 16, 2026
Texuguinho1234 Credited to Texuguinho1234
Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL Moderate
CVE-2026-53722 was published for nuxt (npm) Jun 16, 2026
manop55555 Credited to manop55555 and sota70 sota70 sota70
DOMPurify IN_PLACE Sanitization Bypass via Attached Shadow Root Inside <template>.content Moderate
CVE-2026-49978 was published for dompurify (npm) Jun 15, 2026
GameZoneHacker Credited to GameZoneHacker
offset Credited to offset
offset Credited to offset
@angular/compiler: Two-Way Property Binding Sanitization Bypass (XSS) Moderate
CVE-2026-54265 was published for @angular/compiler (npm) Jun 15, 2026
SkyZeroZx Credited to SkyZeroZx, alan-agius4, JeanMeche, and JoostK alan-agius4 alan-agius4
JeanMeche JeanMeche JoostK JoostK
Angular: Template and Attribute Namespace Sanitization Bypass (XSS) Moderate
CVE-2026-50557 was published for @angular/compiler (npm) Jun 15, 2026
SkyZeroZx Credited to SkyZeroZx, alan-agius4, josephperrott, and AndrewKushnir alan-agius4 alan-agius4
josephperrott josephperrott AndrewKushnir AndrewKushnir
@angular/core: Angular Template and Dynamic Component Namespace Bypass leading to Cross-Site Scripting (XSS) Moderate
CVE-2026-52725 was published for @angular/core (npm) Jun 15, 2026
SkyZeroZx Credited to SkyZeroZx, AndrewKushnir, alan-agius4, and josephperrott AndrewKushnir AndrewKushnir
alan-agius4 alan-agius4 josephperrott josephperrott
Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization Moderate
CVE-2026-44311 was published for fabric (npm) Jun 12, 2026
NocoDB: Reflected Cross-Site Scripting via Password Reset Token Moderate
CVE-2026-47376 was published for nocodb (npm) Jun 5, 2026
fg0x0 Credited to fg0x0
React Router has stored XSS via unescaped Location header in prerendered redirect HTML Moderate
CVE-2026-33244 was published for react-router (npm) Jun 3, 2026
yuito-it Credited to yuito-it
ProTip! Advisories are also available from the GraphQL API