GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,781
Maven
5,000+
npm
4,386
NuGet
772
pip
4,164
Pub
12
RubyGems
965
Rust
1,073
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,046 advisories
Filter by severity
apidoc-core has a prototype pollution vulnerability
Critical
CVE-2025-13158
was published
for
apidoc-core
(npm)
Dec 26, 2025
n8n Vulnerable to Arbitrary Command Execution in Pyodide based Python Code Node
Critical
CVE-2025-68668
was published
for
n8n
(npm)
Dec 26, 2025
n8n Vulnerable to Remote Code Execution via Expression Injection
Critical
CVE-2025-68613
was published
for
n8n
(npm)
Dec 22, 2025
Withdrawn Advisory: LikeC4 has RCE through vulnerable React and Next.js versions
Critical
GHSA-vr6p-vq2p-6j74
was published
for
likec4
(npm)
Dec 15, 2025
•
withdrawn
Elysia vulnerable to prototype pollution with multiple standalone schema validation
Critical
CVE-2025-66456
was published
for
elysia
(npm)
Dec 9, 2025
@vitejs/plugin-rsc Remote Code Execution through unsafe dynamic imports in RSC server function APIs on development server
Critical
CVE-2025-67489
was published
for
@vitejs/plugin-rsc
(npm)
Dec 8, 2025
n8n vulnerable to Remote Code Execution via Git Node Custom Pre-Commit Hook
Critical
CVE-2025-65964
was published
for
n8n
(npm)
Dec 8, 2025
React Server Components are Vulnerable to RCE
Critical
GHSA-fmh4-wr37-44fp
was published
for
@vitejs/plugin-rsc
(npm)
Dec 3, 2025
React Server Components are Vulnerable to RCE
Critical
CVE-2025-55182
was published
for
react-server-dom-parcel
(npm)
Dec 3, 2025
Next.js is vulnerable to RCE in React flight protocol
Critical
GHSA-9qr9-h5gf-34mp
was published
for
next
(npm)
Dec 3, 2025
MCP Watch has a Critical Command Injection in cloneRepo allows Remote Code Execution (RCE) via malicious URL
Critical
CVE-2025-66401
was published
for
mcp-watch
(npm)
Dec 2, 2025
md-to-pdf vulnerable to arbitrary JavaScript code execution when parsing front matter
Critical
CVE-2025-65108
was published
for
md-to-pdf
(npm)
Nov 20, 2025
@hpke/core reuses AEAD nonces
Critical
CVE-2025-64767
was published
for
@hpke/core
(npm)
Nov 20, 2025
@react-native-community/cli has arbitrary OS command injection
Critical
CVE-2025-11953
was published
for
@react-native-community/cli
(npm)
Nov 3, 2025
Duplicate Advisory: FlowiseAI Pre-Auth Arbitrary Code Execution
Critical
GHSA-3g4j-r53p-22wx
was published
for
flowise
(npm)
Oct 17, 2025
•
withdrawn
happy-dom's `--disallow-code-generation-from-strings` is not sufficient for isolating untrusted JavaScript
Critical
CVE-2025-62410
was published
for
happy-dom
(npm)
Oct 15, 2025
Happy DOM: VM Context Escape can lead to Remote Code Execution
Critical
CVE-2025-61927
was published
for
happy-dom
(npm)
Oct 10, 2025
Flowise is vulnerable to arbitrary file write through its WriteFileTool
Critical
CVE-2025-61913
was published
for
Flowise
(npm)
Oct 9, 2025
SillyTavern Web Interface Vulnerable DNS Rebinding
Critical
CVE-2025-59159
was published
for
sillytavern
(npm)
Oct 6, 2025
Flowise vulnerable to RCE via Dynamic function constructor injection
Critical
CVE-2025-55346
was published
for
flowise
(npm)
Oct 6, 2025
Flowise is vulnerable to stored XSS via "View Messages" allows credential theft in FlowiseAI admin panel
Critical
CVE-2025-50538
was published
for
flowise
(npm)
Oct 3, 2025
check-branches is vulnerable to command Injection
Critical
CVE-2025-11148
was published
for
check-branches
(npm)
Sep 30, 2025
get-jwks: poisoned JWKS cache allows post-fetch issuer validation bypass
Critical
CVE-2025-59936
was published
for
get-jwks
(npm)
Sep 26, 2025
cors-anywhere vulnerable to server-side request forgery
Critical
CVE-2020-36851
was published
for
cors-anywhere
(npm)
Sep 25, 2025
Duplicate Advisory: Malicious versions of Nx were published
Critical
GHSA-8mjq-32x3-22qf
was published
for
nx
(npm)
Sep 25, 2025
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API