GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            1,035 advisories
        Filter by severity
        
      
      
    
                    
                      Duplicate Advisory: FlowiseAI Pre-Auth Arbitrary Code Execution
                    
                      
  Critical
                    
                
                      
                        GHSA-3g4j-r53p-22wx
                      
                      was published
                        for
                        
                          flowise
                        
                        (npm)
                      Oct 17, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      happy-dom's `--disallow-code-generation-from-strings` is not sufficient for isolating untrusted JavaScript
                    
                      
  Critical
                    
                
                      
                        CVE-2025-62410
                      
                      was published
                        for
                        
                          happy-dom
                        
                        (npm)
                      Oct 15, 2025 
                    
                  
                    
                      Happy DOM: VM Context Escape can lead to Remote Code Execution
                    
                      
  Critical
                    
                
                      
                        CVE-2025-61927
                      
                      was published
                        for
                        
                          happy-dom
                        
                        (npm)
                      Oct 10, 2025 
                    
                  
                    
                      Better Auth: Unauthenticated API key creation through api-key plugin
                    
                      
  Critical
                    
                
                      
                        CVE-2025-61928
                      
                      was published
                        for
                        
                          better-auth
                        
                        (npm)
                      Oct 9, 2025 
                    
                  
                    
                      Flowise is vulnerable to arbitrary file write through its WriteFileTool 
                    
                      
  Critical
                    
                
                      
                        CVE-2025-61913
                      
                      was published
                        for
                        
                          flowise
                        
                        (npm)
                      Oct 9, 2025 
                    
                  
                    
                      SillyTavern Web Interface Vulnerable DNS Rebinding
                    
                      
  Critical
                    
                
                      
                        CVE-2025-59159
                      
                      was published
                        for
                        
                          sillytavern
                        
                        (npm)
                      Oct 6, 2025 
                    
                  
                    
                      Flowise vulnerable to RCE via Dynamic function constructor injection
                    
                      
  Critical
                    
                
                      
                        CVE-2025-55346
                      
                      was published
                        for
                        
                          flowise
                        
                        (npm)
                      Oct 6, 2025 
                    
                  
                    
                      Flowise is vulnerable to stored XSS via "View Messages" allows credential theft in FlowiseAI admin panel
                    
                      
  Critical
                    
                
                      
                        CVE-2025-50538
                      
                      was published
                        for
                        
                          flowise
                        
                        (npm)
                      Oct 3, 2025 
                    
                  
                    
                      check-branches is vulnerable to command Injection
                    
                      
  Critical
                    
                
                      
                        CVE-2025-11148
                      
                      was published
                        for
                        
                          check-branches
                        
                        (npm)
                      Sep 30, 2025 
                    
                  
                    
                      get-jwks: poisoned JWKS cache allows post-fetch issuer validation bypass
                    
                      
  Critical
                    
                
                      
                        CVE-2025-59936
                      
                      was published
                        for
                        
                          get-jwks
                        
                        (npm)
                      Sep 26, 2025 
                    
                  
                    
                      cors-anywhere vulnerable to server-side request forgery
                    
                      
  Critical
                    
                
                      
                        CVE-2020-36851
                      
                      was published
                        for
                        
                          cors-anywhere
                        
                        (npm)
                      Sep 25, 2025 
                    
                  
                    
                      Duplicate Advisory: Malicious versions of Nx were published
                    
                      
  Critical
                    
                
                      
                        GHSA-8mjq-32x3-22qf
                      
                      was published
                        for
                        
                          nx
                        
                        (npm)
                      Sep 25, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      Command Injection in adb-mcp MCP Server
                    
                      
  Critical
                    
                
                      
                        CVE-2025-59834
                      
                      was published
                        for
                        
                          adb-mcp
                        
                        (npm)
                      Sep 24, 2025 
                    
                  
                    
                      Flowise has arbitrary file access due to missing chat flow id validation
                    
                      
  Critical
                    
                
                      
                        GHSA-q67q-549q-p849
                      
                      was published
                        for
                        
                          flowise
                        
                        (npm)
                      Sep 15, 2025 
                    
                  
                    
                      Flowise has an Arbitrary File Read
                    
                      
  Critical
                    
                
                      
                        GHSA-99pg-hqvx-r4gf
                      
                      was published
                        for
                        
                          flowise
                        
                        (npm)
                      Sep 15, 2025 
                    
                  
                    
                      Flowise has Remote Code Execution vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2025-59528
                      
                      was published
                        for
                        
                          flowise
                        
                        (npm)
                      Sep 15, 2025 
                    
                  
                    
                      FlowiseAI Pre-Auth Arbitrary Code Execution
                    
                      
  Critical
                    
                
                      
                        CVE-2025-57164
                      
                      was published
                        for
                        
                          flowise
                        
                        (npm)
                      Sep 15, 2025 
                    
                  
                    
                      Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover
                    
                      
  Critical
                    
                
                      
                        CVE-2025-58434
                      
                      was published
                        for
                        
                          flowise
                        
                        (npm)
                      Sep 12, 2025 
                    
                  
                    
                      Prebid-universal-creative latest on npm briefly compromised
                    
                      
  Critical
                    
                
                      
                        CVE-2025-59039
                      
                      was published
                        for
                        
                          prebid-universal-creative
                        
                        (npm)
                      Sep 11, 2025 
                    
                  
                    
                      interactive-git-checkout has a Command Injection vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2025-59046
                      
                      was published
                        for
                        
                          interactive-git-checkout
                        
                        (npm)
                      Sep 10, 2025 
                    
                  
                    
                      @akoskm/create-mcp-server-stdio is vulnerable to MCP Server Command Injection through `exec` API
                    
                      
  Critical
                    
                
                      
                        CVE-2025-54994
                      
                      was published
                        for
                        
                          @akoskm/create-mcp-server-stdio
                        
                        (npm)
                      Sep 8, 2025 
                    
                  
                    
                      CodeceptJS's incomprehensive sanitation can lead to Command Injection
                    
                      
  Critical
                    
                
                      
                        CVE-2025-57285
                      
                      was published
                        for
                        
                          codeceptjs
                        
                        (npm)
                      Sep 8, 2025 
                    
                  
                    
                      Malicious versions of Nx were published
                    
                      
  Critical
                    
                
                      
                        CVE-2025-10894
                      
                      was published
                        for
                        
                          @nx/devkit
                        
                        (npm)
                      Aug 27, 2025 
                    
                  
                    
                      sha.js is missing type checks leading to hash rewind and passing on crafted data
                    
                      
  Critical
                    
                
                      
                        CVE-2025-9288
                      
                      was published
                        for
                        
                          sha.js
                        
                        (npm)
                      Aug 21, 2025 
                    
                  
                    
                      cipher-base is missing type checks, leading to hash rewind and passing on crafted data
                    
                      
  Critical
                    
                
                      
                        CVE-2025-9287
                      
                      was published
                        for
                        
                          cipher-base
                        
                        (npm)
                      Aug 21, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API