Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

223 advisories

Loading
Handlebars: JavaScript Injection via Own Property Check Bypass Critical
CVE-2026-106445 was published for handlebars (npm) Oct 8, 2026
brandon-t-elliott Credited to brandon-t-elliott
Ghost: Private IP Filtering Bypass via IPv6 Transition Addresses Moderate
CVE-2026-105648 was published for ghost (npm) Oct 7, 2026
nhattanhh Credited to nhattanhh
Ghost: Stored XSS via oEmbed Photo Responses High
CVE-2026-105650 was published for ghost (npm) Oct 7, 2026
nhattanhh Credited to nhattanhh
Hydra instantiate target blacklist bypasses permit code execution High
CVE-2026-106442 was published for hydra-core (pip) Oct 7, 2026
hash3liZer Credited to hash3liZer and eros938 eros938 eros938
simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection Critical
CVE-2026-102829 was published for @simple-git/argv-parser (npm) Oct 5, 2026
simple-git unsafe-operation guard does not block trailer command configuration Critical
CVE-2026-102828 was published for simple-git (npm) Oct 5, 2026
sec-reex Credited to sec-reex
@bytebase/dbhub's read-only mode does not prevent database writes High
CVE-2026-61788 was published for @bytebase/dbhub (npm) Sep 24, 2026
ixNyf Credited to ixNyf
A flaw was found in the automation-controller input-validation guard... High Unreviewed
CVE-2026-84714 was published Sep 23, 2026
Grav: XSS Blueprint Validation Bypass via Twig String Concatenation Moderate
CVE-2026-61453 was published for getgrav/grav (Composer) Sep 16, 2026
alienkeric Credited to alienkeric and gemstone-source gemstone-source gemstone-source
ProTip! Advisories are also available from the GraphQL API