Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7,706 advisories

Loading
knowns OS Command Injection via Insecure LSP Binary Path Config in .knowns/config.json High
CVE-2026-86540 was published for knowns (npm) Oct 6, 2026
uziii2208 Credited to uziii2208 and hoanggxyuuki hoanggxyuuki hoanggxyuuki
Payload didn't enforce field-level password update restrictions High
CVE-2026-105855 was published for payload (npm) Oct 6, 2026
pavelkohout396 Credited to pavelkohout396
Payload: ReDoS in Multipart Content-Type Validation High
CVE-2026-105854 was published for payload (npm) Oct 6, 2026
hwpark6804-gif Credited to hwpark6804-gif
Payload vulnerable to API key disclosure through ordinary document reads High
CVE-2026-105849 was published for payload (npm) Oct 6, 2026
Zerotistic Credited to Zerotistic
Payload Ecommerce has an order confirmation validation issue High
CVE-2026-105850 was published for @payloadcms/plugin-ecommerce (npm) Oct 6, 2026
Payload relationship-query authorization bypass Moderate
CVE-2026-105852 was published for payload (npm) Oct 6, 2026
Payload: Token refresh and password reset responses may expose restricted user fields High
CVE-2026-105853 was published for payload (npm) Oct 6, 2026
Payload: Field access control bypass on auth collections Critical
CVE-2026-105851 was published for payload (npm) Oct 6, 2026
Zerotistic Credited to Zerotistic
Payload: Insufficient Access Control in Stripe REST Proxy Moderate
CVE-2026-105848 was published for @payloadcms/plugin-stripe (npm) Oct 6, 2026
Payload: Improper access control for MCP API keys High
CVE-2026-105806 was published for @payloadcms/plugin-mcp (npm) Oct 6, 2026
pavelkohout396 Credited to pavelkohout396
Payload: Prototype pollution in Payload Import Export plugin Critical
CVE-2026-105844 was published for @payloadcms/plugin-import-export (npm) Oct 6, 2026
iamnoooob Credited to iamnoooob
Payload: SQL Injection in SQLite and Postgres Critical
CVE-2026-105845 was published for payload (npm) Oct 6, 2026
Payload: Untrusted redirect URL parameter exploit Moderate
CVE-2026-105846 was published for @payloadcms/next (npm) Oct 6, 2026
kullai-secasure Credited to kullai-secasure and yuvraj-secasure yuvraj-secasure yuvraj-secasure
Payload: Polymorphic join queries could disclose hidden fields High
CVE-2026-105847 was published for payload (npm) Oct 6, 2026
Payload: Password hashes use insufficient PBKDF2 iterations Moderate
CVE-2026-105804 was published for payload (npm) Oct 6, 2026
georgelzrc Credited to georgelzrc
Payload: Sort queries could expose protected field information Moderate
CVE-2026-105805 was published for payload (npm) Oct 6, 2026
braintxx Credited to braintxx
MCP TypeScript SDK: OAuth client could send credentials to an authorization server chosen by the MCP server High
CVE-2026-104850 was published for @modelcontextprotocol/client (npm) Oct 6, 2026
Aviral2642 Credited to Aviral2642, AlexMelanFromRingo, Gal3m, JosephDoUrden, Igfray, OriginalKazdov, and lwebmedia AlexMelanFromRingo AlexMelanFromRingo
Gal3m Gal3m JosephDoUrden JosephDoUrden Igfray Igfray OriginalKazdov OriginalKazdov lwebmedia lwebmedia
i18next-http-backend incomplete URL validation permits SSRF Low
CVE-2026-105800 was published for i18next-http-backend (npm) Oct 6, 2026
avrlab233 Credited to avrlab233
LangChain: RediSearch Filter Injection via Unescaped Tag/Text Values Low
CVE-2026-105799 was published for @langchain/redis (npm) Oct 6, 2026
thesanjok Credited to thesanjok and shovanchakraborty shovanchakraborty shovanchakraborty
sharp : Vulnerability in librsvg dependency CVE-2026-96889 High
GHSA-wq5f-xc86-pv6w was published for sharp (npm) Oct 6, 2026
shell-quote: `quote()` command injection via a line terminator in a token after a `{ comment }` token Critical
CVE-2026-102422 was published for shell-quote (npm) Oct 6, 2026
euriconicacio Credited to euriconicacio and ljharb ljharb ljharb
pbkdf2 rehashes long passwords on every iteration, enabling denial of service Moderate
CVE-2026-102414 was published for pbkdf2 (npm) Oct 6, 2026
ljharb Credited to ljharb
simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection Critical
CVE-2026-102829 was published for @simple-git/argv-parser (npm) Oct 5, 2026
simple-git unsafe-operation guard does not block trailer command configuration Critical
CVE-2026-102828 was published for simple-git (npm) Oct 5, 2026
sec-reex Credited to sec-reex
simple-git allows command execution through unblocked Git configuration includes High
CVE-2026-102826 was published for simple-git (npm) Oct 5, 2026
bhaswanthc Credited to bhaswanthc and NotAFlightRisk NotAFlightRisk NotAFlightRisk
ProTip! Advisories are also available from the GraphQL API