GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,883
Maven
5,000+
npm
5,000+
NuGet
1,134
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,595
Swift
64
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,555
Rust
20
7,706 advisories
Filter by severity
Trigger.dev: Cross-tenant SQL injection in the TSQL query compiler (POST /api/v1/query) via unsanitized window-function name
High
GHSA-9q4r-4842-93vw
was published
for
trigger.dev
(npm)
Oct 2, 2026
Trigger.dev: Unauthenticated Realtime Stream Data Injection via Run FriendlyId
Moderate
GHSA-59h8-w5q6-mfmp
was published
for
trigger.dev
(npm)
Oct 2, 2026
Trigger.dev Self-Hosted Deployment: Default Secrets allow Unauthenticated Infrastructure Compromise
High
GHSA-pqxw-g93w-hj9x
was published
for
trigger.dev
(npm)
Oct 2, 2026
figlet is vulnerable to denial of service via unbounded loop when whitespaceBreak is used with a small width
High
CVE-2026-96780
was published
for
figlet
(npm)
Oct 2, 2026
Trigger.dev: V1 coordinator default-secret unauth Socket.IO
Critical
GHSA-gg6r-gp4c-89hp
was published
for
trigger.dev
(npm)
Oct 2, 2026
Trigger.dev: Blind SSRF via alert-channel webhook
Moderate
GHSA-q567-cr4x-96w4
was published
for
trigger.dev
(npm)
Oct 2, 2026
Trigger.dev: Missing Authentication in Run Replay Action Allows Cross-Organization Task Execution (IDOR)
High
GHSA-pp95-gc86-jq6q
was published
for
trigger.dev
(npm)
Oct 2, 2026
Trigger.dev: Server-side request forgery via unvalidated webhook alert-channel URL
High
GHSA-xxv7-2vv3-h682
was published
for
trigger.dev
(npm)
Oct 2, 2026
Trigger.dev: Run replay injects a task run into an attacker-chosen environment (cross-tenant write)
High
GHSA-qxpp-qjg8-x4jv
was published
for
trigger.dev
(npm)
Oct 2, 2026
vm2: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks
Moderate
CVE-2026-92952
was published
for
vm2
(npm)
Oct 1, 2026
vm2: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandbox escape
Critical
CVE-2026-92948
was published
for
vm2
(npm)
Oct 1, 2026
vm2 CLI provides no sandbox isolation - host-realm require() is reachable from sandboxed scripts
High
CVE-2026-92950
was published
for
vm2
(npm)
Oct 1, 2026
vm2 exposes host HTTPS credentials and TLS traffic through globalAgent
Critical
CVE-2026-92940
was published
for
vm2
(npm)
Oct 1, 2026
vm2 Custom Module Resolver Can Bypass the External Package Allowlist by Loading a Colliding Host Package
Critical
CVE-2026-92951
was published
for
vm2
(npm)
Oct 1, 2026
vm2: NodeVM builtin denylist bypass via fs/promises despite -fs, allowing host filesystem writes
High
CVE-2026-92958
was published
for
vm2
(npm)
Oct 1, 2026
vm2: NodeVM node:-prefixed negative builtin deny bypass exposes child_process
Critical
CVE-2026-92957
was published
for
vm2
(npm)
Oct 1, 2026
vm2: vm.freeze()/vm.readonly() bypass via accessor descriptor
Moderate
CVE-2026-92949
was published
for
vm2
(npm)
Oct 1, 2026
vm2: NodeVM nesting guard accepts array-shaped require and permits host RCE
Critical
CVE-2026-92935
was published
for
vm2
(npm)
Oct 1, 2026
vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirection
Critical
CVE-2026-92937
was published
for
vm2
(npm)
Oct 1, 2026
vm2 allows a sandboxed plugin to execute native code through `node:sqlite`
Critical
CVE-2026-92938
was published
for
vm2
(npm)
Oct 1, 2026
vm2 crypto builtin loads attacker native code through setEngine
Critical
CVE-2026-92939
was published
for
vm2
(npm)
Oct 1, 2026
vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector
Critical
CVE-2026-92944
was published
for
vm2
(npm)
Oct 1, 2026
vm2 NodeVM can replace the host process TLS trust store
Critical
CVE-2026-92941
was published
for
vm2
(npm)
Oct 1, 2026
vm2: External module allowlist uses a raw prefix test, so a prefix-sharing sibling package is treated as allowlisted
Moderate
CVE-2026-92945
was published
for
vm2
(npm)
Oct 1, 2026
devalue: `stringify`/`uneval` serialize shared memory
High
CVE-2026-92708
was published
for
devalue
(npm)
Oct 1, 2026
ProTip!
Advisories are also available from the
GraphQL API