Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

1,674 advisories

Loading
Finance.js vulnerable to DoS via the seekZero() parameter High
CVE-2025-56572 was published for financejs (npm) Sep 30, 2025
Finance.js vulnerable to DoS via the IRR function’s depth parameter High
CVE-2025-56571 was published for financejs (npm) Sep 30, 2025
figma-developer-mcp vulnerable to command injection in get_figma_data tool High
CVE-2025-53967 was published for figma-developer-mcp (npm) Sep 30, 2025
dellalibera
Credited to dellalibera
@nubosoftware/node-static failure to catch exception can result in server crash High
CVE-2025-11149 was published for @nubosoftware/node-static (npm) Sep 30, 2025
lirantal
Credited to lirantal
Apollo Embedded Sandbox and Explorer vulnerable to CSRF via window.postMessage origin-validation bypass High
CVE-2025-59845 was published for @apollo/explorer (npm) Sep 26, 2025
ekzyis 0x9x-ui
Credited to ekzyis and 0x9x-ui
apidoc-core is vulnerable to prototype pollution High
CVE-2025-57317 was published for apidoc-core (npm) Sep 25, 2025
dref is vulnerable to prototype pollution High
CVE-2025-26278 was published for dref (npm) Sep 25, 2025
csvjson vulnerable to prototype injection High
CVE-2025-57318 was published for csvjson (npm) Sep 24, 2025
mpregular vulnerable to prototype pollution High
CVE-2025-57323 was published for mpregular (npm) Sep 24, 2025
Claude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn Versions High
CVE-2025-59828 was published for @anthropic-ai/claude-code (npm) Sep 24, 2025
cai0duque
Credited to cai0duque
lukaselmer cai0duque
Credited to lukaselmer and cai0duque
Mesh Connect JS SDK Vulnerable to Cross Site Scripting via createLink.openLink High
CVE-2025-59430 was published for @meshconnect/web-link-sdk (npm) Sep 22, 2025
aptos-security zwxxb
zi0Black
Credited to aptos-security, zwxxb, and zi0Black
`git-comiters` Command Injection vulnerability High
CVE-2025-59831 was published for git-commiters (npm) Sep 22, 2025
lirantal
Credited to lirantal
Codex has sandbox bypass due to bug in path configuration logic High
CVE-2025-59532 was published for @openai/codex (npm) Sep 19, 2025
@executeautomation/database-server does not properly restrict access, bypassing a "read-only" mode High
CVE-2025-59333 was published for @executeautomation/database-server (npm) Sep 16, 2025
lirantal
Credited to lirantal
[email protected] contains malware after npm account takeover High
CVE-2025-59331 was published for is-arrayish (npm) Sep 15, 2025
[email protected] contains malware after npm account takeover High
CVE-2025-59330 was published for error-ex (npm) Sep 15, 2025
[email protected] contains malware after npm account takeover High
CVE-2025-59162 was published for color-convert (npm) Sep 15, 2025
[email protected] contains malware after npm account takeover High
CVE-2025-59145 was published for color-name (npm) Sep 15, 2025
[email protected] contains malware after npm account takeover High
CVE-2025-59144 was published for debug (npm) Sep 15, 2025
[email protected] contains malware after npm account takeover High
CVE-2025-59143 was published for color (npm) Sep 15, 2025
[email protected] contains malware after npm account takeover High
CVE-2025-59142 was published for color-string (npm) Sep 15, 2025
[email protected] contains malware after npm account takeover High
CVE-2025-59141 was published for simple-swizzle (npm) Sep 15, 2025
[email protected] contains malware after npm account takeover High
CVE-2025-59140 was published for backslash (npm) Sep 15, 2025
Flowise has unsandboxed remote code execution via Custom MCP High
GHSA-6933-jpx5-q87q was published for flowise (npm) Sep 15, 2025
assaf-levkovich-jf
Credited to assaf-levkovich-jf
ProTip! Advisories are also available from the GraphQL API