GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,904
Maven
5,000+
npm
5,000+
NuGet
967
pip
5,000+
Pub
13
RubyGems
1,062
Rust
1,374
Swift
54
Unreviewed advisories
All unreviewed
5,000+
17 advisories
Filter by severity
LiquidJS is Vulnerable to Remote Code Execution
Critical
CVE-2026-45618
was published
for
liquidjs
(npm)
May 27, 2026
vm2 Access to Host Object Enables Sandbox Escape
Critical
CVE-2026-43997
was published
for
vm2
(npm)
May 7, 2026
vm2 has a Sandbox Escape Vulnerability
Critical
CVE-2026-44006
was published
for
vm2
(npm)
May 7, 2026
n8n has Multiple Remote Code Execution Vulnerabilities in Merge Node AlaSQL SQL Mode
Critical
CVE-2026-33660
was published
for
n8n
(npm)
Mar 25, 2026
n8n has In-Process Memory Disclosure in its Task Runner
High
CVE-2026-27496
was published
for
n8n
(npm)
Mar 25, 2026
SandboxJS affected by a Sandbox Escape
Critical
CVE-2026-26954
was published
for
@nyariv/sandboxjs
(npm)
Mar 13, 2026
n8n: Expression Sandbox Escape Leads to RCE
Critical
CVE-2026-27577
was published
for
n8n
(npm)
Feb 25, 2026
n8n has a Sandbox Escape in its JavaScript Task Runner
Critical
CVE-2026-27495
was published
for
n8n
(npm)
Feb 25, 2026
@enclave-vm/core is vulnerable to Sandbox Escape
Critical
CVE-2026-27597
was published
for
@enclave-vm/core
(npm)
Feb 25, 2026
@nyariv/sandboxjs has a Sandbox Escape vulnerability
Critical
CVE-2026-25587
was published
for
@nyariv/sandboxjs
(npm)
Feb 5, 2026
@nyariv/sandboxjs has a Sandbox Escape issue
Critical
CVE-2026-25520
was published
for
@nyariv/sandboxjs
(npm)
Feb 5, 2026
SandboxJS Vulnerable to Prototype Pollution -> Sandbox Escape -> RCE
Critical
CVE-2026-25142
was published
for
@nyariv/sandboxjs
(npm)
Feb 2, 2026
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events
Moderate
CVE-2024-47003
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Sep 26, 2024
Mattermost Plugin Channel Export excessive resource consumption
Moderate
CVE-2024-43105
was published
for
github.com/mattermost/mattermost-plugin-channel-export
(Go)
Aug 23, 2024
document-merge-service vulnerable to Remote Code Execution via Server-Side Template Injection
High
CVE-2024-37301
was published
for
document-merge-service
(pip)
Jun 11, 2024
Mattermost vulnerable to denial of service via large number of emoji reactions
Moderate
CVE-2024-1402
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Feb 9, 2024
ProTip!
Advisories are also available from the
GraphQL API