Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7,706 advisories

Loading
@vue/server-renderer: XSS via missing CR in attribute-name blacklist High
GHSA-g2v6-rqmx-r4w6 was published for @vue/server-renderer (npm) Oct 5, 2026
onevilx Credited to onevilx
Tinypool: Prototype Pollution gadget in worker options leads to Remote Code Execution Critical
CVE-2026-104848 was published for tinypool (npm) Oct 5, 2026
ambushneupane Credited to ambushneupane
Tinypool: Prototype Pollution Gadget to RCE in run() options Critical
CVE-2026-104849 was published for tinypool (npm) Oct 5, 2026
Fcmam5 Credited to Fcmam5
stream-json: JSONC parser and verifier re-scan the whole accumulated comment on every input chunk Moderate
CVE-2026-104182 was published for stream-json (npm) Oct 5, 2026
NotAFlightRisk Credited to NotAFlightRisk
stream-json has a prototype pollution issue: Assembler writes this.current[this.key] on plain objects Moderate
CVE-2026-104183 was published for stream-json (npm) Oct 5, 2026
cruzryan Credited to cruzryan
sondt99 Credited to sondt99 and dungNHVhust dungNHVhust dungNHVhust
vm2: Sandbox Escape (NodeVM) Critical
CVE-2026-92955 was published for vm2 (npm) Oct 5, 2026
c0rydoras Credited to c0rydoras
rexpository Credited to rexpository
rexpository Credited to rexpository
manus-use Credited to manus-use and maru1009 maru1009 maru1009
KimiSecurityTeam Credited to KimiSecurityTeam
ProseMirror has a XSS vulnerability in prosemirror-view's paste handling High
CVE-2026-104847 was published for prosemirror-view (npm) Oct 5, 2026
dropn0w Credited to dropn0w
vm2 leaks absolute host filesystem paths to sandbox code via error stack formatting Moderate
CVE-2026-92936 was published for vm2 (npm) Oct 5, 2026
oran-s Credited to oran-s
mausamrijall Credited to mausamrijall
abisheikM1 Credited to abisheikM1, amagesh1, and Den1al amagesh1 amagesh1
Den1al Den1al
vm2: Sandboxed code can read and write host-realm memory via Node's shared Buffer pool Critical
CVE-2026-92947 was published for vm2 (npm) Oct 5, 2026
zolbooo Credited to zolbooo
vm2 sandbox escape via WebAssembly.compileStreaming Promise species bypass Critical
CVE-2026-92956 was published for vm2 (npm) Oct 5, 2026
thesmartshadow Credited to thesmartshadow and zolbooo zolbooo zolbooo
@fastify/busboy vulnerable to CRLF injection via multipart Content-Disposition filename and name Moderate
CVE-2026-74866 was published for @fastify/busboy (npm) Oct 5, 2026
tonghuaroot Credited to tonghuaroot, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
@orpc/zod: Prototype injection in smart coercion Moderate
CVE-2026-103918 was published for @orpc/zod (npm) Oct 5, 2026
probe-image-size: Quadratic-time Denial of Service in the SVG Parser High
CVE-2026-104861 was published for probe-image-size (npm) Oct 2, 2026
@fastify/busboy vulnerable to Denial of Service via prototype-named multipart part header High
CVE-2026-19481 was published for @fastify/busboy (npm) Oct 2, 2026
kq5y Credited to kq5y, mcollina, UlisesGascon, and AdmirBajric mcollina mcollina
UlisesGascon UlisesGascon AdmirBajric AdmirBajric
@fastify/busboy vulnerable to Denial of Service via oversized multipart boundary High
CVE-2026-19484 was published for @fastify/busboy (npm) Oct 2, 2026
LorenzoRD2003 Credited to LorenzoRD2003, mcollina, and UlisesGascon mcollina mcollina
UlisesGascon UlisesGascon
@a2ui/web_core: `openUrl` permits `javascript:` URI execution via agent-supplied button actions Critical
CVE-2026-10032 was published for @a2ui/web_core (npm) Oct 2, 2026
EQSTLab Credited to EQSTLab and 232-323 232-323 232-323
Trigger.dev: Trigger CLI debug deployment logs expose resolved environment secret values Moderate
GHSA-fj2x-mqqp-3v2w was published for trigger.dev (npm) Oct 2, 2026
Trigger.dev: Cross-environment deployment cancel Moderate
GHSA-4672-hwv6-gq62 was published for trigger.dev (npm) Oct 2, 2026
CyberKareem Credited to CyberKareem
ProTip! Advisories are also available from the GraphQL API