GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,894
Erlang
38
GitHub Actions
38
Go
2,556
Maven
5,000+
npm
4,228
NuGet
747
pip
4,000
Pub
12
RubyGems
953
Rust
1,041
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,635 advisories
Filter by severity
Flowise: Authenticated Command Execution and Sandbox Bypass via Puppeteer and Playwright Packages
High
CVE-2025-34267
was published
for
flowise
(npm)
Oct 14, 2025
FlowiseAI/Flosise has File Upload vulnerability
High
CVE-2025-61687
was published
for
flowise
(npm)
Oct 8, 2025
cross-zip is vulnerable to Directory Traversal through selective use of zip/unzip operations
High
CVE-2025-11569
was published
for
cross-zip
(npm)
Oct 10, 2025
Flowise is vulnerable to arbitrary file exposure through its ReadFileTool
High
GHSA-j44m-5v8f-gc9c
was published
for
flowise
(npm)
Oct 10, 2025
n8n: Execute Command Node Allows Authenticated Users to Run Arbitrary Commands on Host
High
GHSA-365g-vjw2-grx8
was published
for
n8n
(npm)
Oct 9, 2025
Duplicate Advisory: Flowise is vulnerable to stored XSS via "View Messages" allows credential theft in FlowiseAI admin panel
High
GHSA-7rgr-72hp-9wp3
was published
for
flowise
(npm)
Oct 6, 2025
•
withdrawn
Duplicate Advisory: Flowise Stored XSS vulnerability through logs in chatbot
High
GHSA-wq95-wr7m-26h4
was published
for
flowise
(npm)
Oct 6, 2025
•
withdrawn
pdfmake is vulnerable to Throttling via repeatedly redirecting URL in file embedding
High
CVE-2025-11362
was published
for
pdfmake
(npm)
Oct 7, 2025
Finance.js vulnerable to DoS via the IRR function’s depth parameter
High
CVE-2025-56571
was published
for
financejs
(npm)
Sep 30, 2025
@nubosoftware/node-static failure to catch exception can result in server crash
High
CVE-2025-11149
was published
for
@nubosoftware/node-static
(npm)
Sep 30, 2025
Claude Code can execute commands prior to the startup trust dialog
High
CVE-2025-59536
was published
for
@anthropic-ai/claude-code
(npm)
Oct 3, 2025
@plone/volto vulnerable to potential DoS by invoking specific URL by anonymous user
High
CVE-2025-61668
was published
for
@plone/volto
(npm)
Oct 1, 2025
@backstage/backend-app-api leaks GitLab access tokens
High
CVE-2023-6944
was published
for
@backstage/backend-app-api
(npm)
Jan 4, 2024
Finance.js vulnerable to DoS via the seekZero() parameter
High
CVE-2025-56572
was published
for
financejs
(npm)
Sep 30, 2025
figma-developer-mcp vulnerable to command injection in get_figma_data tool
High
CVE-2025-53967
was published
for
figma-developer-mcp
(npm)
Sep 30, 2025
Axios is vulnerable to DoS attack through lack of data size check
High
CVE-2025-58754
was published
for
axios
(npm)
Sep 11, 2025
tar-fs Vulnerable to Link Following and Path Traversal via Extracting a Crafted tar File
High
CVE-2024-12905
was published
for
tar-fs
(npm)
Mar 27, 2025
Apollo Embedded Sandbox and Explorer vulnerable to CSRF via window.postMessage origin-validation bypass
High
CVE-2025-59845
was published
for
@apollo/explorer
(npm)
Sep 26, 2025
messageformat prototype pollution vulnerability
High
CVE-2025-57353
was published
for
@messageformat/runtime
(npm)
Sep 24, 2025
Prototype Pollution in @hapi/subtext
High
GHSA-g9cg-h3jm-cwrc
was published
for
@hapi/pez
(npm)
Sep 3, 2020
node-static and @nubosoftware/node-static vulnerable to Directory Traversal
High
CVE-2023-26111
was published
for
@nubosoftware/node-static
(npm)
Mar 6, 2023
files-bucket-server vulnerable to Directory Traversal
High
CVE-2025-8021
was published
for
files-bucket-server
(npm)
Jul 23, 2025
ProTip!
Advisories are also available from the
GraphQL API