GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,893
Erlang
38
GitHub Actions
38
Go
2,550
Maven
5,000+
npm
4,222
NuGet
745
pip
3,998
Pub
12
RubyGems
953
Rust
1,039
Swift
45
Unreviewed advisories
All unreviewed
5,000+
4,222 advisories
Filter by severity
CommandKit has incorrect command name exposure in context object for message command aliases
Moderate
GHSA-fhwm-pc6r-4h2f
was published
for
commandkit
(npm)
Oct 13, 2025
Happy DOM: VM Context Escape can lead to Remote Code Execution
Critical
CVE-2025-61927
was published
for
happy-dom
(npm)
Oct 10, 2025
Astro's `X-Forwarded-Host` is reflected without validation
Moderate
CVE-2025-61925
was published
for
astro
(npm)
Oct 10, 2025
Flowise is vulnerable to arbitrary file exposure through its ReadFileTool
High
GHSA-j44m-5v8f-gc9c
was published
for
flowise
(npm)
Oct 10, 2025
cross-zip is vulnerable to Directory Traversal through selective use of zip/unzip operations
High
CVE-2025-11569
was published
for
cross-zip
(npm)
Oct 10, 2025
Better Auth: Unauthenticated API key creation through api-key plugin
Critical
CVE-2025-61928
was published
for
better-auth
(npm)
Oct 9, 2025
n8n: Execute Command Node Allows Authenticated Users to Run Arbitrary Commands on Host
High
GHSA-365g-vjw2-grx8
was published
for
n8n
(npm)
Oct 9, 2025
Flowise is vulnerable to arbitrary file write through its WriteFileTool
Critical
CVE-2025-61913
was published
for
flowise
(npm)
Oct 9, 2025
FlowiseAI/Flosise has File Upload vulnerability
High
CVE-2025-61687
was published
for
flowise
(npm)
Oct 8, 2025
Nodemailer: Email to an unintended domain can occur due to Interpretation Conflict
Moderate
GHSA-mm7p-fcc7-pg87
was published
for
nodemailer
(npm)
Oct 7, 2025
pdfmake is vulnerable to Throttling via repeatedly redirecting URL in file embedding
High
CVE-2025-11362
was published
for
pdfmake
(npm)
Oct 7, 2025
SillyTavern Web Interface Vulnerable DNS Rebinding
Critical
CVE-2025-59159
was published
for
sillytavern
(npm)
Oct 6, 2025
Flowise vulnerable to RCE via Dynamic function constructor injection
Critical
CVE-2025-55346
was published
for
flowise
(npm)
Oct 6, 2025
Duplicate Advisory: Flowise is vulnerable to stored XSS via "View Messages" allows credential theft in FlowiseAI admin panel
High
GHSA-7rgr-72hp-9wp3
was published
for
flowise
(npm)
Oct 6, 2025
•
withdrawn
Duplicate Advisory: Flowise Stored XSS vulnerability through logs in chatbot
High
GHSA-wq95-wr7m-26h4
was published
for
flowise
(npm)
Oct 6, 2025
•
withdrawn
MCPHub has an Improper Authorization vulnerability via its handleSseConnection function
Moderate
CVE-2025-11287
was published
for
@samanhappy/mcphub
(npm)
Oct 5, 2025
MCPHub's ServerController is vulnerable to Command Injection
Low
CVE-2025-11285
was published
for
@samanhappy/mcphub
(npm)
Oct 5, 2025
Flowise Stored XSS vulnerability through logs in chatbot
Moderate
CVE-2025-29192
was published
for
flowise
(npm)
Oct 3, 2025
Flowise is vulnerable to stored XSS via "View Messages" allows credential theft in FlowiseAI admin panel
Critical
CVE-2025-50538
was published
for
flowise
(npm)
Oct 3, 2025
Claude Code permission deny bypass through symlink
Low
CVE-2025-59829
was published
for
@anthropic-ai/claude-code
(npm)
Oct 3, 2025
Claude Code can execute commands prior to the startup trust dialog
High
CVE-2025-59536
was published
for
@anthropic-ai/claude-code
(npm)
Oct 3, 2025
Fiora chat user avatar is vulnerable to XSS via SVG files
Low
CVE-2025-56514
was published
for
fiora
(npm)
Oct 1, 2025
Fiora chat group avatar is vulnerable to XSS via SVG files
Low
CVE-2025-56515
was published
for
fiora
(npm)
Oct 1, 2025
@plone/volto vulnerable to potential DoS by invoking specific URL by anonymous user
High
CVE-2025-61668
was published
for
@plone/volto
(npm)
Oct 1, 2025
ProTip!
Advisories are also available from the
GraphQL API