GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
7,318 advisories
Filter by severity
TypeSpec: Unauthenticated Remote Shutdown of Spector Mock Server via POST /.admin/stop
High
GHSA-7q9c-hpx7-9cwm
was published
for
@typespec/spector
(npm)
Sep 4, 2026
CodeWhale: Project config `allow_shell` override enables arbitrary shell command execution via cloned repository
High
CVE-2026-75911
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: rlm_eval auto-approves arbitrary Python execution, bypassing the user's approval policy (RCE)
High
CVE-2026-75858
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: Argument Injection in `git_blame` Tool Allows Arbitrary File Read Without Approval
High
CVE-2026-75912
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: SSRF bypass - TOCTOU on DNS failure for DNS pinning
Critical
CVE-2026-75856
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: js_execution leaks parent environment to model context via missing env scrub
High
CVE-2026-75915
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: Argument Injection in `git_show` Tool Allows Arbitrary File Write Without Approval
High
CVE-2026-75913
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: exec_shell_interact sends LLM-controlled input to a running shell without an approval prompt (privilege escalation)
High
CVE-2026-75857
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: Project config `instructions` override enables arbitrary file read into AI system prompt via cloned repository
High
CVE-2026-75859
was published
for
codewhale
(npm)
Sep 4, 2026
CodeWhale: image_analyze follows workspace symlinks, leaking external file bytes
High
CVE-2026-75914
was published
for
codewhale
(npm)
Sep 4, 2026
SimpleWebAuthn: Registration verification does not sufficiently ensure that attestation certificates chain to a trust anchor
Low
GHSA-6hxq-p678-4hr2
was published
for
@simplewebauthn/server
(npm)
Sep 4, 2026
toml-node: Prototype Pollution Leads to `Object.prototype` Corruption via `__proto__` Key-Path Desynchronization
High
CVE-2026-63376
was published
for
toml
(npm)
Sep 3, 2026
Phoenix: Presence keys colliding with `Object.prototype` members break existence checks
Moderate
CVE-2026-56812
was published
for
phoenix
(Erlang)
Sep 3, 2026
stream-json: pick/ignore/filter/replace filters are O(depth²) on nested input — small crafted JSON blocks the event loop for seconds→minutes (DoS)
Moderate
CVE-2026-71429
was published
for
stream-json
(npm)
Sep 3, 2026
ApostropheCMS: Mutation-XSS / allowedTags bypass via literal `</textarea/>` solidus close
Moderate
CVE-2026-63670
was published
for
sanitize-html
(npm)
Sep 3, 2026
ApostropheCMS: Missing destination-parent authorization in page `move()` allows a low-privileged editor to move and re-rank pages inside a restricted subtree
Moderate
CVE-2026-63669
was published
for
apostrophe
(npm)
Sep 3, 2026
TOON: Prototype pollution when decoding untrusted TOON input
High
CVE-2026-82404
was published
for
@toon-format/toon
(npm)
Sep 3, 2026
Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio)
High
CVE-2026-73222
was published
for
claude-code-templates
(npm)
Sep 3, 2026
Orval: RCE via OpenAPI path -> unescaped request-URL template literal (backtick breakout)
Critical
CVE-2026-62681
was published
for
orval
(npm)
Sep 3, 2026
Orval: RCE via servers[].url -> unescaped request-URL template literal (with getBaseUrlFromSpecification)
Critical
CVE-2026-62682
was published
for
orval
(npm)
Sep 3, 2026
Orval: Import-time RCE via schema default -> zod module-level template literal
Critical
CVE-2026-72717
was published
for
orval
(npm)
Sep 3, 2026
Orval: Import-time RCE via array-items default -> zod module-level template literal
Critical
CVE-2026-71869
was published
for
orval
(npm)
Sep 3, 2026
Orval: Import-time RCE via header-parameter default -> zod module-level template literal
Critical
CVE-2026-71871
was published
for
orval
(npm)
Sep 3, 2026
Orval: RCE via schema property name -> computed-property-key injection in the MSW mock generator
Critical
CVE-2026-71867
was published
for
orval
(npm)
Sep 3, 2026
ProTip!
Advisories are also available from the
GraphQL API