Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

12,672 advisories

Loading
TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop High
GHSA-7q9c-hpx7-9cwm was published for @typespec/spector (npm) Sep 4, 2026
EQSTLab Credited to EQSTLab
Shirshakhtml Credited to Shirshakhtml
SiYuan: The session-cookie signing key (Conf.CookieKey) is returned to anonymous readers by /api/system/getConf High
CVE-2026-72794 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 4, 2026
Shirshakhtml Credited to Shirshakhtml
Shirshakhtml Credited to Shirshakhtml
sondt99 Credited to sondt99
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
sai-sh Credited to sai-sh
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval High
CVE-2026-75912 was published for codewhale (npm) Sep 4, 2026
0xEr3n Credited to 0xEr3n
CodeWhale: js_execution leaks parent environment to model context via missing env scrub High
CVE-2026-75915 was published for codewhale (npm) Sep 4, 2026
fg0x0 Credited to fg0x0
CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval High
CVE-2026-75913 was published for codewhale (npm) Sep 4, 2026
0xEr3n Credited to 0xEr3n
sondt99 Credited to sondt99, dungNHVhust, and sai-sh dungNHVhust dungNHVhust
sai-sh sai-sh
CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes High
CVE-2026-75914 was published for codewhale (npm) Sep 4, 2026
fg0x0 Credited to fg0x0
Shirshakhtml Credited to Shirshakhtml
SiYuan: Graph endpoints omit the publish-password tier: anonymous readers receive block-level content of password-protected documents High
CVE-2026-72804 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 3, 2026
Shirshakhtml Credited to Shirshakhtml
Shirshakhtml Credited to Shirshakhtml
SiYuan: Localhost-trust admin bypass on auth-code-gated endpoints, with potential remote reachability via the fixed-port proxy High
CVE-2026-72809 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 3, 2026
Shirshakhtml Credited to Shirshakhtml
Shirshakhtml Credited to Shirshakhtml
SiYuan: Anonymous publish-password authentication bypass via getHeadingChildrenDOM / getHeading*Transaction / getBacklinkDoc (publish mode) High
GHSA-7j72-f6wg-cxw6 was published for github.com/siyuan-note/siyuan/kernel (Go) Sep 3, 2026
Shirshakhtml Credited to Shirshakhtml
Shirshakhtml Credited to Shirshakhtml
toml-node: Uncontrolled Recursion High
CVE-2026-77465 was published for toml (npm) Sep 3, 2026
seok-hee97 Credited to seok-hee97
Shirshakhtml Credited to Shirshakhtml
ProTip! Advisories are also available from the GraphQL API