Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

36,231 advisories

Loading
Trigger.dev: Server-side request forgery via unvalidated webhook alert-channel URL High
GHSA-xxv7-2vv3-h682 was published for trigger.dev (npm) Oct 2, 2026
geo-chen Credited to geo-chen
Trigger.dev: Run replay injects a task run into an attacker-chosen environment (cross-tenant write) High
GHSA-qxpp-qjg8-x4jv was published for trigger.dev (npm) Oct 2, 2026
geo-chen Credited to geo-chen
Composer: GHSA-gjfg-22fp-rrxx fix bypass via symlinked package bin path Moderate
CVE-2026-59944 was published for composer/composer (Composer) Oct 2, 2026
DavidCarliez Credited to DavidCarliez, manus-use, and arpitjain099 manus-use manus-use
arpitjain099 arpitjain099
Dulwich: Arbitrary File Write (RCE) on Windows via Unvalidated Drive Letters in Tree Paths High
GHSA-8mcx-5rqc-vhmf was published for dulwich (pip) Oct 2, 2026
LukeBanto Credited to LukeBanto and jelmer jelmer jelmer
Dulwich: Infinite Loop Denial of Service (DoS) in Packfile Object Resolution Moderate
GHSA-35mr-4567-66vg was published for dulwich (pip) Oct 2, 2026
LukeBanto Credited to LukeBanto
Dulwich: Symlink write-through in checkout(paths=[]) via raw os.open bypasses all symlink protections High
GHSA-8w8g-wq8h-fq33 was published for dulwich (pip) Oct 2, 2026
manus-use Credited to manus-use and jelmer jelmer jelmer
Dulwich: Symlink directory traversal in filter-branch index_filter via cross-commit state persistence High
GHSA-5fqc-mrg8-w798 was published for dulwich (pip) Oct 2, 2026
manus-use Credited to manus-use and jelmer jelmer jelmer
manus-use Credited to manus-use and jelmer jelmer jelmer
xxhash-rust: Safe xxh3 custom-secret API accepts too-short secret in release Low
GHSA-6g2r-675j-hx59 was published for xxhash-rust (Rust) Oct 2, 2026
Copernik XML Factory (stock JDK provider) has Improper restriction of XInclude resource resolution High
CVE-2026-61586 was published for eu.copernik:copernik-xml-factory (Maven) Oct 2, 2026
thientd Credited to thientd and gladiator9797 gladiator9797 gladiator9797
Anubis: Policy bypass via client controlled X-Original-URI header Moderate
CVE-2026-62314 was published for github.com/TecharoHQ/anubis (Go) Oct 2, 2026
Zerotistic Credited to Zerotistic
rmcp OAuth client fetches server-controlled resource_metadata URLs Moderate
GHSA-c9xm-49cp-xcr9 was published for rmcp (Rust) Oct 2, 2026
Shirshakhtml Credited to Shirshakhtml
Shirshakhtml Credited to Shirshakhtml
SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering Moderate
CVE-2026-73609 was published for github.com/siyuan-note/siyuan/kernel (Go) Oct 1, 2026
Shirshakhtml Credited to Shirshakhtml
Shirshakhtml Credited to Shirshakhtml
Shirshakhtml Credited to Shirshakhtml
vm2: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks Moderate
CVE-2026-92952 was published for vm2 (npm) Oct 1, 2026
rexpository Credited to rexpository
vm2: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandbox escape Critical
CVE-2026-92948 was published for vm2 (npm) Oct 1, 2026
the-vibe-dev Credited to the-vibe-dev
oran-s Credited to oran-s
vm2 exposes host HTTPS credentials and TLS traffic through globalAgent Critical
CVE-2026-92940 was published for vm2 (npm) Oct 1, 2026
Forrof Credited to Forrof
XlabAITeam Credited to XlabAITeam, keenanwgn, and liangjs keenanwgn keenanwgn
liangjs liangjs
nasaa0x Credited to nasaa0x, rexpository, sangnigege, and manus-use rexpository rexpository
sangnigege sangnigege manus-use manus-use
vm2: NodeVM node:-prefixed negative builtin deny bypass exposes child_process Critical
CVE-2026-92957 was published for vm2 (npm) Oct 1, 2026
nasaa0x Credited to nasaa0x, sangnigege, and manus-use sangnigege sangnigege
manus-use manus-use
vm2: vm.freeze()/vm.readonly() bypass via accessor descriptor Moderate
CVE-2026-92949 was published for vm2 (npm) Oct 1, 2026
oran-s Credited to oran-s
ProTip! Advisories are also available from the GraphQL API