GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            488 advisories
        Filter by severity
        
      
      
    
                    
                      messageformat prototype pollution vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-57353
                      
                      was published
                        for
                        
                          @messageformat/runtime
                        
                        (npm)
                      Sep 24, 2025 
                    
                  
                    
                      CSVTOJSON has a prototype pollution vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-57350
                      
                      was published
                        for
                        
                          csvtojson
                        
                        (npm)
                      Sep 24, 2025 
                    
                  
                    
                      Vulnerability of exposing object heap addresses in the Ark eTS module.
Impact: Successful...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-58280
                      
                      was published
                      Sep 5, 2025 
                    
                  
                    
                      devalue prototype pollution vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2025-57820
                      
                      was published
                        for
                        
                          devalue
                        
                        (npm)
                      Aug 26, 2025 
                    
                  
                    
                      Spreecommerce versions prior to 0.60.2 contains a remote command execution vulnerability in its...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2011-10019
                      
                      was published
                      Aug 13, 2025 
                    
                  
                    
                      content-security-policy-parser Prototype Pollution Vulnerability May Lead to RCE
                    
                      
  High
                    
                
                      
                        CVE-2025-55164
                      
                      was published
                        for
                        
                          content-security-policy-parser
                        
                        (npm)
                      Aug 12, 2025 
                    
                  
                    
                      js-toml Prototype Pollution Vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2025-54803
                      
                      was published
                        for
                        
                          js-toml
                        
                        (npm)
                      Aug 4, 2025 
                    
                  
                    
                      @nyariv/sandboxjs has Prototype Pollution vulnerability that may lead to RCE
                    
                      
  High
                    
                
                      
                        CVE-2025-34146
                      
                      was published
                        for
                        
                          @nyariv/sandboxjs
                        
                        (npm)
                      Jul 31, 2025 
                    
                  
                    
                      Linkify Allows Prototype Pollution & HTML Attribute Injection (XSS)
                    
                      
  High
                    
                
                      
                        CVE-2025-8101
                      
                      was published
                        for
                        
                          linkifyjs
                        
                        (npm)
                      Jul 26, 2025 
                    
                  
                    
                      @pdfme/common vulnerable to to XSS and Prototype Pollution through its expression evaluation
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-53626
                      
                      was published
                        for
                        
                          @pdfme/common
                        
                        (npm)
                      Jul 10, 2025 
                    
                  
                    
                      billboard.js allows prototype pollution via the function generate
                    
                      
  Critical
                    
                
                      
                        CVE-2025-49223
                      
                      was published
                        for
                        
                          billboard.js
                        
                        (npm)
                      Jun 4, 2025 
                    
                  
                    
                      radashi Allows Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-48054
                      
                      was published
                        for
                        
                          radashi
                        
                        (npm)
                      May 27, 2025 
                    
                  
                    
                      A Prototype pollution vulnerability in Kibana leads to arbitrary code execution via crafted HTTP...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-25014
                      
                      was published
                      May 6, 2025 
                    
                  
                    
                      A vulnerability, which was classified as problematic, was found in nortikin Sverchok 1.3.0....
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-3982
                      
                      was published
                      Apr 27, 2025 
                    
                  
                    
                      Prototype Pollution in Kibana can lead to code injection via unrestricted file upload combined...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-12556
                      
                      was published
                      Apr 8, 2025 
                    
                  
                    
                      estree-util-value-to-estree allows prototype pollution in generated ESTree
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-32014
                      
                      was published
                        for
                        
                          estree-util-value-to-estree
                        
                        (npm)
                      Apr 7, 2025 
                    
                  
                    
                      js-object-utilities Vulnerable to Prototype Pollution
                    
                      
  High
                    
                
                      
                        CVE-2025-28269
                      
                      was published
                        for
                        
                          js-object-utilities
                        
                        (npm)
                      Apr 7, 2025 
                    
                  
                    
                      tarteaucitron.js allows prototype pollution via custom text injection
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-31475
                      
                      was published
                        for
                        
                          tarteaucitronjs
                        
                        (npm)
                      Apr 7, 2025 
                    
                  
                    
                      expand-object Vulnerable to Prototype Pollution via the expand() Function
                    
                      
  Moderate
                    
                
                      
                        CVE-2025-3197
                      
                      was published
                        for
                        
                          expand-object
                        
                        (npm)
                      Apr 4, 2025 
                    
                  
                    
                      @alizeait/unflatto Prototype Pollution
                    
                      
  High
                    
                
                      
                        CVE-2024-38988
                      
                      was published
                        for
                        
                          @alizeait/unflatto
                        
                        (npm)
                      Apr 1, 2025 
                    
                  
                    
                      Redoc Prototype Pollution via `Module.mergeObjects` Component
                    
                      
  High
                    
                
                      
                        CVE-2024-57083
                      
                      was published
                        for
                        
                          redoc
                        
                        (npm)
                      Mar 28, 2025 
                    
                  
                    
                      Duplicate Advisory: @alizeait/unflatto Prototype Pollution via `exports.unflatto` Method
                    
                      
  High
                    
                
                      
                        GHSA-799q-f2px-wx8c
                      
                      was published
                        for
                        
                          @alizeait/unflatto
                        
                        (npm)
                      Mar 28, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      A Prototype Pollution issue in Aliconnect /sdk v.0.0.6 allows an attacker to execute arbitrary...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-24292
                      
                      was published
                      Mar 28, 2025 
                    
                  
                    
                      depath and cool-path vulnerable to Prototype Pollution via `set()` Method
                    
                      
  High
                    
                
                      
                        CVE-2024-38985
                      
                      was published
                        for
                        
                          cool-path
                        
                        (npm)
                      Mar 28, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API