Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7,318 advisories

Loading
TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop High
GHSA-7q9c-hpx7-9cwm was published for @typespec/spector (npm) Sep 4, 2026
EQSTLab Credited to EQSTLab
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
sai-sh Credited to sai-sh
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval High
CVE-2026-75912 was published for codewhale (npm) Sep 4, 2026
0xEr3n Credited to 0xEr3n
CodeWhale: SSRF‌ bypass - TOCTOU on DNS failure for DNS pinning Critical
CVE-2026-75856 was published for codewhale (npm) Sep 4, 2026
JafarAkhondali Credited to JafarAkhondali
CodeWhale: js_execution leaks parent environment to model context via missing env scrub High
CVE-2026-75915 was published for codewhale (npm) Sep 4, 2026
fg0x0 Credited to fg0x0
CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval High
CVE-2026-75913 was published for codewhale (npm) Sep 4, 2026
0xEr3n Credited to 0xEr3n
sondt99 Credited to sondt99, dungNHVhust, and sai-sh dungNHVhust dungNHVhust
sai-sh sai-sh
CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes High
CVE-2026-75914 was published for codewhale (npm) Sep 4, 2026
fg0x0 Credited to fg0x0
Josh-TantoSec Credited to Josh-TantoSec
toml-node: Uncontrolled Recursion High
CVE-2026-77465 was published for toml (npm) Sep 3, 2026
seok-hee97 Credited to seok-hee97
Phoenix: Presence keys colliding with `Object.prototype` members break existence checks Moderate
CVE-2026-56812 was published for phoenix (Erlang) Sep 3, 2026
PJUllrich Credited to PJUllrich, maennchen, and SteffenDE maennchen maennchen
SteffenDE SteffenDE
ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close Moderate
CVE-2026-63670 was published for sanitize-html (npm) Sep 3, 2026
bibu123456 Credited to bibu123456
TOON: Prototype pollution when decoding untrusted TOON input High
CVE-2026-82404 was published for @toon-format/toon (npm) Sep 3, 2026
ckorhonen Credited to ckorhonen
Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio) High
CVE-2026-73222 was published for claude-code-templates (npm) Sep 3, 2026
spartan8806 Credited to spartan8806
Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout) Critical
CVE-2026-62681 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m and mrostamipoor mrostamipoor mrostamipoor
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via schema default -> zod module-level template literal Critical
CVE-2026-72717 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via array-items default -> zod module-level template literal Critical
CVE-2026-71869 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: Import-time RCE via header-parameter default -> zod module-level template literal Critical
CVE-2026-71871 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generator Critical
CVE-2026-71867 was published for orval (npm) Sep 3, 2026
Gal3m Credited to Gal3m, mrostamipoor, and aqeelat mrostamipoor mrostamipoor
aqeelat aqeelat
ProTip! Advisories are also available from the GraphQL API