Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

36,288 advisories

Loading
nasaa0x Credited to nasaa0x, rexpository, sangnigege, and manus-use rexpository rexpository
sangnigege sangnigege manus-use manus-use
vm2: NodeVM node:-prefixed negative builtin deny bypass exposes child_process Critical
CVE-2026-92957 was published for vm2 (npm) Oct 1, 2026
nasaa0x Credited to nasaa0x, sangnigege, and manus-use sangnigege sangnigege
manus-use manus-use
vm2: vm.freeze()/vm.readonly() bypass via accessor descriptor Moderate
CVE-2026-92949 was published for vm2 (npm) Oct 1, 2026
oran-s Credited to oran-s
vm2: NodeVM nesting guard accepts array-shaped require and permits host RCE Critical
CVE-2026-92935 was published for vm2 (npm) Oct 1, 2026
lexdotdev Credited to lexdotdev
vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirection Critical
CVE-2026-92937 was published for vm2 (npm) Oct 1, 2026
oran-s Credited to oran-s
vm2 allows a sandboxed plugin to execute native code through `node:sqlite` Critical
CVE-2026-92938 was published for vm2 (npm) Oct 1, 2026
Forrof Credited to Forrof
vm2 crypto builtin loads attacker native code through setEngine Critical
CVE-2026-92939 was published for vm2 (npm) Oct 1, 2026
Forrof Credited to Forrof
vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector Critical
CVE-2026-92944 was published for vm2 (npm) Oct 1, 2026
YMs0ra Credited to YMs0ra
vm2 NodeVM can replace the host process TLS trust store Critical
CVE-2026-92941 was published for vm2 (npm) Oct 1, 2026
Forrof Credited to Forrof
arpitjain099 Credited to arpitjain099
JupyterLab: Cross-site scripting (XSS) in JupyterLab via crafted language package (jupyterlab.json) Moderate
CVE-2026-102830 was published for jupyterlab (pip) Oct 1, 2026
mingijunggrape Credited to mingijunggrape, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
rexpository Credited to rexpository, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
rexpository Credited to rexpository, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
jackson-core: UTF8DataInputJsonParser._reportInvalidToken() missing maxErrorTokenLength limit -> unbounded StringBuilder growth (DoS) High
CVE-2026-89425 was published for com.fasterxml.jackson.core:jackson-core (Maven) Oct 1, 2026
manqingzhou Credited to manqingzhou
jackson-core: ReDoS: quadratic backtracking in NumberInput.PATTERN_FLOAT via looksLikeValidNumber() High
CVE-2026-89407 was published for com.fasterxml.jackson.core:jackson-core (Maven) Oct 1, 2026
manqingzhou Credited to manqingzhou
devalue: `stringify`/`uneval` serialize shared memory High
CVE-2026-92708 was published for devalue (npm) Oct 1, 2026
LipezJ Credited to LipezJ and elliott-with-the-longest-name-on-github elliott-with-the-longest-name-on-github elliott-with-the-longest-name-on-github
devalue: Residual sparse-array CPU amplification in uneval Moderate
GHSA-hx4r-w6wj-j8fg was published for devalue (npm) Oct 1, 2026
elliott-with-the-longest-name-on-github Credited to elliott-with-the-longest-name-on-github
devalue: Repeated primitive strings cause quadratic expansion in uneval High
GHSA-mcm9-63f2-9j32 was published for devalue (npm) Oct 1, 2026
elliott-with-the-longest-name-on-github Credited to elliott-with-the-longest-name-on-github
devalue: Sparse arrays emitted by uneval cause eager allocation when evaluated Low
GHSA-wf3x-273g-mvxv was published for devalue (npm) Oct 1, 2026
elliott-with-the-longest-name-on-github Credited to elliott-with-the-longest-name-on-github
devalue: stringifyAsync can cause an unhandled rejection despite a caught returned promise High
GHSA-x5rw-q4pp-hg5g was published for devalue (npm) Oct 1, 2026
elliott-with-the-longest-name-on-github Credited to elliott-with-the-longest-name-on-github
devalue: Malformed null-prototype object keys bypass __proto__ rejection via property-key coercion Moderate
GHSA-4q55-j62x-fr9h was published for devalue (npm) Oct 1, 2026
elliott-with-the-longest-name-on-github Credited to elliott-with-the-longest-name-on-github
virtualenv bash and fish activation scripts execute commands embedded in paths High
CVE-2026-102925 was published for virtualenv (pip) Oct 1, 2026
gaborbernat Credited to gaborbernat
virtualenv: Command injection via --prompt in activate.bat (batch activator) High
CVE-2026-102937 was published for virtualenv (pip) Oct 1, 2026
gaborbernat Credited to gaborbernat
pypdf: Possible long runtimes with large amount of embedded files High
CVE-2026-102999 was published for pypdf (pip) Oct 1, 2026
jungmingi-lab Credited to jungmingi-lab
pypdf: Possible long runtimes when generating appearance streams High
CVE-2026-102998 was published for pypdf (pip) Oct 1, 2026
manop55555 Credited to manop55555
ProTip! Advisories are also available from the GraphQL API