GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,536
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,516
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
7,184 advisories
Filter by severity
SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses
Moderate
GHSA-hjwh-xvfw-qrwj
was published
for
mcp-searxng
(npm)
Aug 19, 2026
SearXNG MCP Server: Additional hardened-mode SSRF bypasses
Moderate
CVE-2026-54689
was published
for
mcp-searxng
(npm)
Aug 19, 2026
SearXNG MCP Server is Vulnerable to SSRF in web_url_read: the internal-address guard is disabled by default (MCP_HTTP_HARDEN off)
Moderate
CVE-2026-54688
was published
for
mcp-searxng
(npm)
Aug 19, 2026
Contentful MCP Server: export_space/import_space tools pass LLM-controlled `host`/`proxy` args to CMA client, redirecting server PAT to attacker-controlled endpoint
High
CVE-2026-53957
was published
for
@contentful/mcp-server
(npm)
Aug 19, 2026
claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
High
GHSA-rr55-jp92-8wp2
was published
for
claude-faf-mcp
(npm)
Aug 19, 2026
faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools
High
GHSA-j4r7-8ph4-43g3
was published
for
faf-mcp
(npm)
Aug 19, 2026
grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools
High
GHSA-cc2g-gq8c-r332
was published
for
grok-faf-mcp
(npm)
Aug 19, 2026
Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect
High
CVE-2026-44503
was published
for
Microsoft.Kiota.Abstractions
(Go)
May 7, 2026
fast-uri vulnerable to host confusion via failed IDN canonicalization
High
CVE-2026-13676
was published
for
fast-uri
(npm)
Jul 21, 2026
fast-uri vulnerable to path traversal via percent-encoded dot segments
High
CVE-2026-6321
was published
for
fast-uri
(npm)
May 8, 2026
fast-uri vulnerable to host confusion via percent-encoded authority delimiters
High
CVE-2026-6322
was published
for
fast-uri
(npm)
May 8, 2026
n8n: LDAP Email-Based Account Linking Allows Privilege Escalation and Account Takeover
High
CVE-2026-33665
was published
for
n8n
(npm)
Mar 25, 2026
Ghost: Cross-Site Scripting in Universal Import
Moderate
CVE-2026-70588
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Session Fixation in Ghost Admin
Moderate
CVE-2026-70594
was published
for
ghost
(npm)
Aug 4, 2026
Ghost: Database Backup Path Traversal
Moderate
CVE-2026-70592
was published
for
ghost
(npm)
Aug 4, 2026
Budibase: Missing RBAC on GET /api/global/groups allows BASIC users to enumerate all tenant groups and role mappings
Moderate
CVE-2026-73301
was published
for
@budibase/server
(npm)
Jul 24, 2026
MeshCentral has unsanitized data fields
High
GHSA-c7hr-448w-65px
was published
for
meshcentral
(npm)
Aug 18, 2026
MagicMirror socket payload secret placeholder expansion can disclose SECRET_* environment variables
Moderate
CVE-2026-63640
was published
for
magicmirror
(npm)
Aug 18, 2026
GeoLens: Cross-dataset authorization bypass discloses private dataset metadata, schema, sample values, table rows, and raster/vector tile data
High
CVE-2026-55178
was published
for
@geolens/sdk
(npm)
Aug 18, 2026
MagicMirror: ssrf calendar .js
Moderate
CVE-2026-63643
was published
for
magicmirror
(npm)
Aug 18, 2026
MagicMirror newsfeed Socket.IO notification allows blind server-side request forgery
Moderate
CVE-2026-63642
was published
for
magicmirror
(npm)
Aug 18, 2026
MagicMirror Socket.IO module namespaces bypass configured IP whitelist and allow unauthenticated server-side actions
Low
CVE-2026-63641
was published
for
magicmirror
(npm)
Aug 18, 2026
@rhinostone/swig: arbitrary local file read via include/extends path traversal
High
GHSA-2mf3-mr2r-r4vf
was published
for
@rhinostone/swig
(npm)
Aug 18, 2026
MLflow: CreateModelVersion source validation does not check READ permission on referenced run_id
High
CVE-2026-69148
was published
for
mlflow
(npm)
Aug 17, 2026
MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth
Moderate
CVE-2026-69146
was published
for
mlflow
(npm)
Aug 17, 2026
ProTip!
Advisories are also available from the
GraphQL API