Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

5 advisories

Loading
vm2: NodeVM nesting guard accepts array-shaped require and permits host RCE Critical
CVE-2026-92935 was published for vm2 (npm) Oct 1, 2026
lexdotdev Credited to lexdotdev
utcp-http SSRF: HTTP tool invocation follows redirects without re-validating the target High
GHSA-9qhg-99ww-9mqc was published for utcp-http (pip) Aug 25, 2026
lexdotdev Credited to lexdotdev
Prompty: Server-Side Template Injection to Remote Code Execution in the @prompty/core Nunjucks Renderer Critical
GHSA-w28w-gp39-m4p6 was published for @prompty/core (npm) Jul 24, 2026
lexdotdev Credited to lexdotdev
File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup High
CVE-2026-55667 was published for github.com/filebrowser/filebrowser/v2 (Go) Jul 20, 2026
babakizo420 Credited to babakizo420, lexdotdev, and hacdias lexdotdev lexdotdev
hacdias hacdias
Network-AI: Improper Neutralization of Special Elements used in an OS Command Critical
CVE-2026-54051 was published for network-ai (npm) Jun 19, 2026
lexdotdev Credited to lexdotdev
ProTip! Advisories are also available from the GraphQL API