GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,717
Maven
5,000+
npm
4,328
NuGet
761
pip
4,105
Pub
12
RubyGems
958
Rust
1,065
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,674 advisories
Filter by severity
Finance.js vulnerable to DoS via the seekZero() parameter
High
CVE-2025-56572
was published
for
financejs
(npm)
Sep 30, 2025
Finance.js vulnerable to DoS via the IRR function’s depth parameter
High
CVE-2025-56571
was published
for
financejs
(npm)
Sep 30, 2025
figma-developer-mcp vulnerable to command injection in get_figma_data tool
High
CVE-2025-53967
was published
for
figma-developer-mcp
(npm)
Sep 30, 2025
@nubosoftware/node-static failure to catch exception can result in server crash
High
CVE-2025-11149
was published
for
@nubosoftware/node-static
(npm)
Sep 30, 2025
Apollo Embedded Sandbox and Explorer vulnerable to CSRF via window.postMessage origin-validation bypass
High
CVE-2025-59845
was published
for
@apollo/explorer
(npm)
Sep 26, 2025
apidoc-core is vulnerable to prototype pollution
High
CVE-2025-57317
was published
for
apidoc-core
(npm)
Sep 25, 2025
dref is vulnerable to prototype pollution
High
CVE-2025-26278
was published
for
dref
(npm)
Sep 25, 2025
csvjson vulnerable to prototype injection
High
CVE-2025-57318
was published
for
csvjson
(npm)
Sep 24, 2025
mpregular vulnerable to prototype pollution
High
CVE-2025-57323
was published
for
mpregular
(npm)
Sep 24, 2025
Claude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn Versions
High
CVE-2025-59828
was published
for
@anthropic-ai/claude-code
(npm)
Sep 24, 2025
tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball
High
CVE-2025-59343
was published
for
tar-fs
(npm)
Sep 24, 2025
Mesh Connect JS SDK Vulnerable to Cross Site Scripting via createLink.openLink
High
CVE-2025-59430
was published
for
@meshconnect/web-link-sdk
(npm)
Sep 22, 2025
`git-comiters` Command Injection vulnerability
High
CVE-2025-59831
was published
for
git-commiters
(npm)
Sep 22, 2025
Codex has sandbox bypass due to bug in path configuration logic
High
CVE-2025-59532
was published
for
@openai/codex
(npm)
Sep 19, 2025
@executeautomation/database-server does not properly restrict access, bypassing a "read-only" mode
High
CVE-2025-59333
was published
for
@executeautomation/database-server
(npm)
Sep 16, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59331
was published
for
is-arrayish
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59330
was published
for
error-ex
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59162
was published
for
color-convert
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59145
was published
for
color-name
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59144
was published
for
debug
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59143
was published
for
color
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59142
was published
for
color-string
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59141
was published
for
simple-swizzle
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59140
was published
for
backslash
(npm)
Sep 15, 2025
Flowise has unsandboxed remote code execution via Custom MCP
High
GHSA-6933-jpx5-q87q
was published
for
flowise
(npm)
Sep 15, 2025
ProTip!
Advisories are also available from the
GraphQL API