GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,970
Maven
5,000+
npm
5,000+
NuGet
1,143
pip
5,000+
Pub
13
RubyGems
1,161
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
21
47 advisories
Filter by severity
Payload: Field-level write access bypass in Payload on MongoDB
High
CVE-2026-106100
was published
for
@payloadcms/db-mongodb
(npm)
Oct 7, 2026
Prototype Pollution via parse() in NodeJS flatted
High
CVE-2026-33228
was published
for
flatted
(npm)
Mar 19, 2026
9router: Mass assignment in PATCH /api/settings allows authenticated authorization downgrade
High
CVE-2026-56679
was published
for
9router
(npm)
Sep 23, 2026
Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API
High
CVE-2026-69258
was published
for
flowise
(npm)
Aug 4, 2026
Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override
High
CVE-2026-54351
was published
for
@budibase/server
(npm)
Jun 22, 2026
FlowiseAI: Evaluation create+update mass-assignment allows cross-workspace evaluation takeover
High
CVE-2026-46479
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI: DatasetRow create+update mass-assignment allows cross-workspace row takeover
High
CVE-2026-46478
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI: Dataset create+update mass-assignment allows cross-workspace dataset takeover
High
CVE-2026-46477
was published
for
flowise
(npm)
May 14, 2026
flat-to-nested: Prototype pollution in flat-to-nested convert() via __proto__ parent/id key
High
CVE-2026-55091
was published
for
flat-to-nested
(npm)
Jun 19, 2026
FlowiseAI: Assistant create+update mass-assignment allows cross-workspace assistant takeover
High
CVE-2026-46475
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI: Evaluator create+update mass-assignment allows cross-workspace evaluator takeover
High
CVE-2026-46480
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI: CustomTemplate create+update mass-assignment allows cross-workspace template takeover
High
CVE-2026-46476
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI has Mass Assignment in Assistant Update Endpoint that Allows Cross-Workspace Resource Reassignment
High
CVE-2026-46441
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI has Mass Assignment in Chatflow Update Endpoint that Allows Cross-Workspace AgentFlow Reassignment
High
CVE-2026-42863
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI has Mass Assignment in Tool Update Endpoint that Allows Cross-Workspace Resource Reassignment
High
CVE-2026-42862
was published
for
flowise
(npm)
May 14, 2026
FlowiseAI has Mass Assignment in Variable Update Endpoint that Allows Cross-Workspace Resource Reassignment
High
CVE-2026-42861
was published
for
flowise
(npm)
May 14, 2026
Kysely: JSON-path traversal injection via unsanitized path-leg metacharacters in `JSONPathBuilder.key()` / `.at()`
High
CVE-2026-44635
was published
for
kysely
(npm)
May 11, 2026
mathjs Allows Improperly Controlled Modification of Dynamically-Determined Object Attributes
High
CVE-2026-41139
was published
for
mathjs
(npm)
Apr 10, 2026
Unsafe object property setter in mathjs
High
CVE-2026-40897
was published
for
mathjs
(npm)
Apr 16, 2026
Flowise: Mass Assignment in DocumentStore Create Endpoint Leads to Cross-Workspace Object Takeover (IDOR)
High
CVE-2026-41277
was published
for
flowise
(npm)
Apr 17, 2026
Flowise: Improper Mass Assignment in Account Registration Enables Unauthorized Organization Association
High
CVE-2026-41267
was published
for
flowise
(npm)
Apr 16, 2026
Directus: Path Traversal and Broken Access Control in File Management API
High
CVE-2026-39942
was published
for
directus
(npm)
Apr 4, 2026
Flowise Allows Mass Assignment in `/api/v1/leads` Endpoint
High
CVE-2026-30822
was published
for
flowise
(npm)
Mar 6, 2026
Mass Assignment in AdonisJS Lucid Allows Overwriting Internal ORM State
High
CVE-2026-22814
was published
for
@adonisjs/lucid
(npm)
Jan 13, 2026
angular Prototype Pollution vulnerability
High
CVE-2019-10768
was published
for
angular
(npm)
Nov 20, 2019
ProTip!
Advisories are also available from the
GraphQL API