Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

36,222 advisories

Loading
xxhash-rust: Safe xxh3 custom-secret API accepts too-short secret in release Low
GHSA-6g2r-675j-hx59 was published for xxhash-rust (Rust) Oct 2, 2026
Copernik XML Factory (stock JDK provider) has Improper restriction of XInclude resource resolution High
CVE-2026-61586 was published for eu.copernik:copernik-xml-factory (Maven) Oct 2, 2026
thientd Credited to thientd and gladiator9797 gladiator9797 gladiator9797
Anubis: Policy bypass via client controlled X-Original-URI header Moderate
CVE-2026-62314 was published for github.com/TecharoHQ/anubis (Go) Oct 2, 2026
Zerotistic Credited to Zerotistic
rmcp OAuth client fetches server-controlled resource_metadata URLs Moderate
GHSA-c9xm-49cp-xcr9 was published for rmcp (Rust) Oct 2, 2026
Shirshakhtml Credited to Shirshakhtml
Shirshakhtml Credited to Shirshakhtml
SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering Moderate
CVE-2026-73609 was published for github.com/siyuan-note/siyuan/kernel (Go) Oct 1, 2026
Shirshakhtml Credited to Shirshakhtml
Shirshakhtml Credited to Shirshakhtml
Shirshakhtml Credited to Shirshakhtml
vm2: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks Moderate
CVE-2026-92952 was published for vm2 (npm) Oct 1, 2026
rexpository Credited to rexpository
vm2: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandbox escape Critical
CVE-2026-92948 was published for vm2 (npm) Oct 1, 2026
the-vibe-dev Credited to the-vibe-dev
oran-s Credited to oran-s
vm2 exposes host HTTPS credentials and TLS traffic through globalAgent Critical
CVE-2026-92940 was published for vm2 (npm) Oct 1, 2026
Forrof Credited to Forrof
XlabAITeam Credited to XlabAITeam, keenanwgn, and liangjs keenanwgn keenanwgn
liangjs liangjs
nasaa0x Credited to nasaa0x, rexpository, sangnigege, and manus-use rexpository rexpository
sangnigege sangnigege manus-use manus-use
vm2: NodeVM node:-prefixed negative builtin deny bypass exposes child_process Critical
CVE-2026-92957 was published for vm2 (npm) Oct 1, 2026
nasaa0x Credited to nasaa0x, sangnigege, and manus-use sangnigege sangnigege
manus-use manus-use
vm2: vm.freeze()/vm.readonly() bypass via accessor descriptor Moderate
CVE-2026-92949 was published for vm2 (npm) Oct 1, 2026
oran-s Credited to oran-s
vm2: NodeVM nesting guard accepts array-shaped require and permits host RCE Critical
CVE-2026-92935 was published for vm2 (npm) Oct 1, 2026
lexdotdev Credited to lexdotdev
vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirection Critical
CVE-2026-92937 was published for vm2 (npm) Oct 1, 2026
oran-s Credited to oran-s
vm2 allows a sandboxed plugin to execute native code through `node:sqlite` Critical
CVE-2026-92938 was published for vm2 (npm) Oct 1, 2026
Forrof Credited to Forrof
vm2 crypto builtin loads attacker native code through setEngine Critical
CVE-2026-92939 was published for vm2 (npm) Oct 1, 2026
Forrof Credited to Forrof
vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector Critical
CVE-2026-92944 was published for vm2 (npm) Oct 1, 2026
YMs0ra Credited to YMs0ra
vm2 NodeVM can replace the host process TLS trust store Critical
CVE-2026-92941 was published for vm2 (npm) Oct 1, 2026
Forrof Credited to Forrof
arpitjain099 Credited to arpitjain099
JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language package (jupyterlab.json) Moderate
CVE-2026-102830 was published for jupyterlab (pip) Oct 1, 2026
mingijunggrape Credited to mingijunggrape, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
ProTip! Advisories are also available from the GraphQL API