Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

21 advisories

Loading
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
Shescape: Home-directory disclosure in assignment context on Unix with Dash Moderate
CVE-2026-73411 was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
Electron: DevTools JavaScript Injection via Unsanitized Dock State Parameter Moderate
CVE-2026-70609 was published for electron (npm) Aug 5, 2026
hackerman70000 Credited to hackerman70000
mathlive's Lack of Escaping of HTML allows for XSS Moderate
CVE-2026-54705 was published for mathlive (npm) Jul 29, 2026
CosmicCrusader23 Credited to CosmicCrusader23
yorukot Credited to yorukot
Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility Moderate
CVE-2026-59895 was published for hono (npm) Jul 21, 2026
a-tt-om Credited to a-tt-om and teebow1e teebow1e teebow1e
Rootingg Credited to Rootingg and cookesan cookesan cookesan
Fabric.js improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization Moderate
CVE-2026-44311 was published for fabric (npm) Jun 12, 2026
HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution and token theft Moderate
CVE-2026-46496 was published for @haxtheweb/haxcms-nodejs (npm) May 19, 2026
trigerman Credited to trigerman
CryptPad has a Sanitizer Bypass in Diffmarked.js that Allows Arbitrary HTML Injection and Potential XSS Moderate
CVE-2026-26028 was published for cryptpad (npm) May 26, 2026
ixSly Credited to ixSly
Hono has CSS Declaration Injection via Style Object Values in JSX SSR Moderate
CVE-2026-44458 was published for hono (npm) May 9, 2026
Gayang2902 Credited to Gayang2902
OpenClaw has ACP CLI approval prompt ANSI escape sequence injection Moderate
CVE-2026-35651 was published for openclaw (npm) Mar 29, 2026
nexrin Credited to nexrin, KeenSecurityLab, qclawer, anlakii, and simon-reisinger-dynatrace KeenSecurityLab KeenSecurityLab
qclawer qclawer anlakii anlakii simon-reisinger-dynatrace simon-reisinger-dynatrace
h3 has a Path Traversal via Percent-Encoded Dot Segments in serveStatic Allows Arbitrary File Read Moderate
GHSA-wr4h-v87w-p3r7 was published for h3 (npm) Mar 18, 2026
0xkakash1 Credited to 0xkakash1
Element Plus Link component (el-link) implements insufficient input validation for the href attribute Moderate
CVE-2025-57665 was published for element-plus (npm) Sep 9, 2025
EwenDC Credited to EwenDC
KaTeX \htmlData does not validate attribute names Moderate
CVE-2025-23207 was published for katex (npm) Jan 17, 2025
nsysean Credited to nsysean and edemaine edemaine edemaine
MathLive's Lack of Escaping of HTML allows for XSS Moderate
CVE-2025-29049 was published for mathlive (npm) Jan 21, 2025
nsysean Credited to nsysean and arnog arnog arnog
React Developer Tools extension Improper Authorization vulnerability Moderate
CVE-2023-5654 was published for react-devtools-core (npm) Oct 19, 2023
KaTeX's `\includegraphics` does not escape filename Moderate
CVE-2024-28245 was published for katex (npm) Mar 25, 2024
martinvks Credited to martinvks, edemaine, and jupenur edemaine edemaine
jupenur jupenur
Misinterpretation of malicious XML input Moderate
CVE-2021-32796 was published for @xmldom/xmldom (npm) Aug 3, 2021
diptendur2c Credited to diptendur2c
Critters Cross-site Scripting Vulnerability Moderate
CVE-2023-3481 was published for critters (npm) Aug 11, 2023
OpenZeppelin Contracts vulnerable to Improper Escaping of Output Moderate
CVE-2023-40014 was published for @openzeppelin/contracts (npm) Aug 11, 2023
ProTip! Advisories are also available from the GraphQL API