Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

36,288 advisories

Loading
Xray-core: Pinning a CA certificate via pinnedPeerCertSha256 can lead to the success of MITM attacks High
GHSA-5wf9-h793-w73c was published for github.com/xtls/xray-core (Go) Oct 2, 2026
Trigger.dev: Blind SSRF via alert-channel webhook Moderate
GHSA-q567-cr4x-96w4 was published for trigger.dev (npm) Oct 2, 2026
CyberKareem Credited to CyberKareem and dizconnectz dizconnectz dizconnectz
Trigger.dev: Missing Authentication in Run Replay Action Allows Cross-Organization Task Execution (IDOR) High
GHSA-pp95-gc86-jq6q was published for trigger.dev (npm) Oct 2, 2026
sajdakabir Credited to sajdakabir and zerotrail-ai zerotrail-ai zerotrail-ai
Trigger.dev: Server-side request forgery via unvalidated webhook alert-channel URL High
GHSA-xxv7-2vv3-h682 was published for trigger.dev (npm) Oct 2, 2026
geo-chen Credited to geo-chen
Trigger.dev: Run replay injects a task run into an attacker-chosen environment (cross-tenant write) High
GHSA-qxpp-qjg8-x4jv was published for trigger.dev (npm) Oct 2, 2026
geo-chen Credited to geo-chen
Composer: GHSA-gjfg-22fp-rrxx fix bypass via symlinked package bin path Moderate
CVE-2026-59944 was published for composer/composer (Composer) Oct 2, 2026
DavidCarliez Credited to DavidCarliez, manus-use, and arpitjain099 manus-use manus-use
arpitjain099 arpitjain099
Dulwich: Arbitrary File Write (RCE) on Windows via Unvalidated Drive Letters in Tree Paths High
GHSA-8mcx-5rqc-vhmf was published for dulwich (pip) Oct 2, 2026
LukeBanto Credited to LukeBanto and jelmer jelmer jelmer
Dulwich: Infinite Loop Denial of Service (DoS) in Packfile Object Resolution Moderate
GHSA-35mr-4567-66vg was published for dulwich (pip) Oct 2, 2026
LukeBanto Credited to LukeBanto
Dulwich: Symlink write-through in checkout(paths=[]) via raw os.open bypasses all symlink protections High
GHSA-8w8g-wq8h-fq33 was published for dulwich (pip) Oct 2, 2026
manus-use Credited to manus-use and jelmer jelmer jelmer
Dulwich: Symlink directory traversal in filter-branch index_filter via cross-commit state persistence High
GHSA-5fqc-mrg8-w798 was published for dulwich (pip) Oct 2, 2026
manus-use Credited to manus-use and jelmer jelmer jelmer
manus-use Credited to manus-use and jelmer jelmer jelmer
xxhash-rust: Safe xxh3 custom-secret API accepts too-short secret in release Low
GHSA-6g2r-675j-hx59 was published for xxhash-rust (Rust) Oct 2, 2026
Copernik XML Factory (stock JDK provider) has Improper restriction of XInclude resource resolution High
CVE-2026-61586 was published for eu.copernik:copernik-xml-factory (Maven) Oct 2, 2026
thientd Credited to thientd and gladiator9797 gladiator9797 gladiator9797
Anubis: Policy bypass via client controlled X-Original-URI header Moderate
CVE-2026-62314 was published for github.com/TecharoHQ/anubis (Go) Oct 2, 2026
Zerotistic Credited to Zerotistic
rmcp OAuth client fetches server-controlled resource_metadata URLs Moderate
GHSA-c9xm-49cp-xcr9 was published for rmcp (Rust) Oct 2, 2026
Shirshakhtml Credited to Shirshakhtml
Shirshakhtml Credited to Shirshakhtml
SiYuan: getBookmarkLabels returns every bookmark label in the workspace to anonymous readers, with no publish-access filtering Moderate
CVE-2026-73609 was published for github.com/siyuan-note/siyuan/kernel (Go) Oct 1, 2026
Shirshakhtml Credited to Shirshakhtml
Shirshakhtml Credited to Shirshakhtml
Shirshakhtml Credited to Shirshakhtml
vm2: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks Moderate
CVE-2026-92952 was published for vm2 (npm) Oct 1, 2026
rexpository Credited to rexpository
vm2: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandbox escape Critical
CVE-2026-92948 was published for vm2 (npm) Oct 1, 2026
the-vibe-dev Credited to the-vibe-dev
oran-s Credited to oran-s
vm2 exposes host HTTPS credentials and TLS traffic through globalAgent Critical
CVE-2026-92940 was published for vm2 (npm) Oct 1, 2026
Forrof Credited to Forrof
XlabAITeam Credited to XlabAITeam, keenanwgn, and liangjs keenanwgn keenanwgn
liangjs liangjs
ProTip! Advisories are also available from the GraphQL API