Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7,706 advisories

Loading
sajdakabir Credited to sajdakabir
Trigger.dev: Unauthenticated Realtime Stream Data Injection via Run FriendlyId Moderate
GHSA-59h8-w5q6-mfmp was published for trigger.dev (npm) Oct 2, 2026
sfwani Credited to sfwani, dodge1218, geo-chen, and MatiasTilleriasLey dodge1218 dodge1218
geo-chen geo-chen MatiasTilleriasLey MatiasTilleriasLey
Trigger.dev Self-Hosted Deployment: Default Secrets allow Unauthenticated Infrastructure Compromise High
GHSA-pqxw-g93w-hj9x was published for trigger.dev (npm) Oct 2, 2026
sfwani Credited to sfwani
ismayilamiraslanov555 Credited to ismayilamiraslanov555
Trigger.dev: V1 coordinator default-secret unauth Socket.IO Critical
GHSA-gg6r-gp4c-89hp was published for trigger.dev (npm) Oct 2, 2026
lissy93 Credited to lissy93
Trigger.dev: Blind SSRF via alert-channel webhook Moderate
GHSA-q567-cr4x-96w4 was published for trigger.dev (npm) Oct 2, 2026
CyberKareem Credited to CyberKareem and dizconnectz dizconnectz dizconnectz
Trigger.dev: Missing Authentication in Run Replay Action Allows Cross-Organization Task Execution (IDOR) High
GHSA-pp95-gc86-jq6q was published for trigger.dev (npm) Oct 2, 2026
sajdakabir Credited to sajdakabir and zerotrail-ai zerotrail-ai zerotrail-ai
Trigger.dev: Server-side request forgery via unvalidated webhook alert-channel URL High
GHSA-xxv7-2vv3-h682 was published for trigger.dev (npm) Oct 2, 2026
geo-chen Credited to geo-chen
Trigger.dev: Run replay injects a task run into an attacker-chosen environment (cross-tenant write) High
GHSA-qxpp-qjg8-x4jv was published for trigger.dev (npm) Oct 2, 2026
geo-chen Credited to geo-chen
vm2: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks Moderate
CVE-2026-92952 was published for vm2 (npm) Oct 1, 2026
rexpository Credited to rexpository
vm2: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandbox escape Critical
CVE-2026-92948 was published for vm2 (npm) Oct 1, 2026
the-vibe-dev Credited to the-vibe-dev
oran-s Credited to oran-s
vm2 exposes host HTTPS credentials and TLS traffic through globalAgent Critical
CVE-2026-92940 was published for vm2 (npm) Oct 1, 2026
Forrof Credited to Forrof
XlabAITeam Credited to XlabAITeam, keenanwgn, and liangjs keenanwgn keenanwgn
liangjs liangjs
nasaa0x Credited to nasaa0x, rexpository, sangnigege, and manus-use rexpository rexpository
sangnigege sangnigege manus-use manus-use
vm2: NodeVM node:-prefixed negative builtin deny bypass exposes child_process Critical
CVE-2026-92957 was published for vm2 (npm) Oct 1, 2026
nasaa0x Credited to nasaa0x, sangnigege, and manus-use sangnigege sangnigege
manus-use manus-use
vm2: vm.freeze()/vm.readonly() bypass via accessor descriptor Moderate
CVE-2026-92949 was published for vm2 (npm) Oct 1, 2026
oran-s Credited to oran-s
vm2: NodeVM nesting guard accepts array-shaped require and permits host RCE Critical
CVE-2026-92935 was published for vm2 (npm) Oct 1, 2026
lexdotdev Credited to lexdotdev
vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirection Critical
CVE-2026-92937 was published for vm2 (npm) Oct 1, 2026
oran-s Credited to oran-s
vm2 allows a sandboxed plugin to execute native code through `node:sqlite` Critical
CVE-2026-92938 was published for vm2 (npm) Oct 1, 2026
Forrof Credited to Forrof
vm2 crypto builtin loads attacker native code through setEngine Critical
CVE-2026-92939 was published for vm2 (npm) Oct 1, 2026
Forrof Credited to Forrof
vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector Critical
CVE-2026-92944 was published for vm2 (npm) Oct 1, 2026
YMs0ra Credited to YMs0ra
vm2 NodeVM can replace the host process TLS trust store Critical
CVE-2026-92941 was published for vm2 (npm) Oct 1, 2026
Forrof Credited to Forrof
arpitjain099 Credited to arpitjain099
devalue: `stringify`/`uneval` serialize shared memory High
CVE-2026-92708 was published for devalue (npm) Oct 1, 2026
LipezJ Credited to LipezJ and elliott-with-the-longest-name-on-github elliott-with-the-longest-name-on-github elliott-with-the-longest-name-on-github
ProTip! Advisories are also available from the GraphQL API