GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,950
Maven
5,000+
npm
4,596
NuGet
787
pip
4,301
Pub
12
RubyGems
982
Rust
1,121
Swift
49
Unreviewed advisories
All unreviewed
5,000+
4,596 advisories
Filter by severity
AdonisJS vulnerable to Denial of Service (DoS) via Unrestricted Memory Buffering in PartHandler during File Type Detection
High
CVE-2026-25762
was published
for
@adonisjs/bodyparser
(npm)
Feb 6, 2026
AdonisJS multipart body parsing has Prototype Pollution issue
High
CVE-2026-25754
was published
for
@adonisjs/bodyparser
(npm)
Feb 6, 2026
Claude Code has Sandbox Escape via Persistent Configuration Injection in settings.json
High
CVE-2026-25725
was published
for
@anthropic-ai/claude-code
(npm)
Feb 6, 2026
Claude Code has Permission Deny Bypass Through Symbolic Links
Low
CVE-2026-25724
was published
for
@anthropic-ai/claude-code
(npm)
Feb 6, 2026
Claude Code Vulnerable to Command Injection via Piped sed Command Bypasses File Write Restrictions
High
CVE-2026-25723
was published
for
@anthropic-ai/claude-code
(npm)
Feb 6, 2026
Claude Code Vulnerable to Command Injection via Directory Change Bypasses Write Protection
High
CVE-2026-25722
was published
for
@anthropic-ai/claude-code
(npm)
Feb 6, 2026
client-certificate-auth Vulnerable to Open Redirect via Host Header Injection in HTTP-to-HTTPS redirect
Moderate
CVE-2026-25651
was published
for
client-certificate-auth
(npm)
Feb 6, 2026
SCEditor has DOM XSS via emoticon URL/HTML injection
Moderate
CVE-2026-25581
was published
for
sceditor
(npm)
Feb 6, 2026
@nyariv/sandboxjs vulnerable to sandbox escape via TOCTOU bug on keys in property accesses
Critical
CVE-2026-25641
was published
for
@nyariv/sandboxjs
(npm)
Feb 5, 2026
@nyariv/sandboxjs has a Sandbox Escape vulnerability
Critical
CVE-2026-25587
was published
for
@nyariv/sandboxjs
(npm)
Feb 5, 2026
@nyariv/sandboxjs has Sandbox Escape via Prototype Whitelist Bypass and Host Prototype Pollution
Critical
CVE-2026-25586
was published
for
@nyariv/sandboxjs
(npm)
Feb 5, 2026
payload-preferences has Cross-Collection IDOR in Access Control (Multi-Auth Environments)
Moderate
CVE-2026-25574
was published
for
payload
(npm)
Feb 5, 2026
@payloadcms/drizzle has SQL Injection in JSON/RichText Queries on PostgreSQL/SQLite Adapters
Critical
CVE-2026-25544
was published
for
@payloadcms/drizzle
(npm)
Feb 5, 2026
@nyariv/sandboxjs has a Sandbox Escape issue
Critical
CVE-2026-25520
was published
for
@nyariv/sandboxjs
(npm)
Feb 5, 2026
webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior
Low
CVE-2025-68458
was published
for
webpack
(npm)
Feb 5, 2026
webpack buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects → SSRF + cache persistence
Low
CVE-2025-68157
was published
for
webpack
(npm)
Feb 5, 2026
Sandbox escape via infinite recursion and error objects
Moderate
CVE-2026-25533
was published
for
@enclave-vm/core
(npm)
Feb 5, 2026
FUXA Unauthenticated Remote Arbitrary Device Tag Write
Critical
CVE-2026-25752
was published
for
fuxa-server
(npm)
Feb 5, 2026
FUXA Unauthenticated Remote Code Execution via Arbitrary File Write in Upload API
Critical
GHSA-88qh-cphv-996c
was published
for
fuxa-server
(npm)
Feb 5, 2026
FUXA Unauthenticated Remote Code Execution via Hardcoded JWT Secret in Default Configuration
Critical
GHSA-32cc-x95p-fxcg
was published
for
fuxa-server
(npm)
Feb 5, 2026
FUXA Unauthenticated Exposure of Plaintext Database Credentials
Critical
CVE-2026-25751
was published
for
fuxa-server
(npm)
Feb 5, 2026
FUXA Unauthenticated Remote Code Execution via Admin JWT Minting
Critical
GHSA-vwcg-c828-9822
was published
for
fuxa-server
(npm)
Feb 5, 2026
n8n's domain allowlist bypass enables credential exfiltration
Moderate
CVE-2026-25631
was published
for
n8n
(npm)
Feb 4, 2026
survey-pdf Upgraded jsPDF Version Due to Security Vulnerability
Critical
CVE-2026-25630
was published
for
survey-pdf
(npm)
Feb 4, 2026
OpenClaw vulnerable to Unauthenticated Local RCE via WebSocket config.apply
High
CVE-2026-25593
was published
for
openclaw
(npm)
Feb 4, 2026
ProTip!
Advisories are also available from the
GraphQL API