Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7,184 advisories

Loading
SearXNG Basic Authentication Credentials Exposed Through MCP Logs and JSON-RPC Error Responses Moderate
GHSA-hjwh-xvfw-qrwj was published for mcp-searxng (npm) Aug 19, 2026
NARKHEDE-VAIBHAV Credited to NARKHEDE-VAIBHAV
SearXNG MCP Server: Additional hardened-mode SSRF bypasses Moderate
CVE-2026-54689 was published for mcp-searxng (npm) Aug 19, 2026
geo-chen Credited to geo-chen
claude-faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools High
GHSA-rr55-jp92-8wp2 was published for claude-faf-mcp (npm) Aug 19, 2026
faf-mcp has an arbitrary local file read/write via unconfined `path` argument in FAF tools High
GHSA-j4r7-8ph4-43g3 was published for faf-mcp (npm) Aug 19, 2026
grok-faf-mcp has an arbitrary local file read via unconfined `path` argument in FAF tools High
GHSA-cc2g-gq8c-r332 was published for grok-faf-mcp (npm) Aug 19, 2026
Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect High
CVE-2026-44503 was published for Microsoft.Kiota.Abstractions (Go) May 7, 2026
MIchaelMainer Credited to MIchaelMainer
fast-uri vulnerable to host confusion via failed IDN canonicalization High
CVE-2026-13676 was published for fast-uri (npm) Jul 21, 2026
celinke97 Credited to celinke97 and UlisesGascon UlisesGascon UlisesGascon
fast-uri vulnerable to path traversal via percent-encoded dot segments High
CVE-2026-6321 was published for fast-uri (npm) May 8, 2026
Jvr2022 Credited to Jvr2022, mcollina, UlisesGascon, climba03003, zakaryan2004, and jlang-ih mcollina mcollina
UlisesGascon UlisesGascon climba03003 climba03003 zakaryan2004 zakaryan2004 jlang-ih jlang-ih
fast-uri vulnerable to host confusion via percent-encoded authority delimiters High
CVE-2026-6322 was published for fast-uri (npm) May 8, 2026
Jvr2022 Credited to Jvr2022, mcollina, UlisesGascon, climba03003, zakaryan2004, and jlang-ih mcollina mcollina
UlisesGascon UlisesGascon climba03003 climba03003 zakaryan2004 zakaryan2004 jlang-ih jlang-ih
n8n: LDAP Email-Based Account Linking Allows Privilege Escalation and Account Takeover High
CVE-2026-33665 was published for n8n (npm) Mar 25, 2026
weblover12 Credited to weblover12, 34selen, B0RI, bde574786, and jh-hack 34selen 34selen
B0RI B0RI bde574786 bde574786 jh-hack jh-hack
Ghost: Cross-Site Scripting in Universal Import Moderate
CVE-2026-70588 was published for ghost (npm) Aug 4, 2026
meifukun Credited to meifukun
Ghost: Session Fixation in Ghost Admin Moderate
CVE-2026-70594 was published for ghost (npm) Aug 4, 2026
meifukun Credited to meifukun
Ghost: Database Backup Path Traversal Moderate
CVE-2026-70592 was published for ghost (npm) Aug 4, 2026
meifukun Credited to meifukun
sfwani Credited to sfwani
MeshCentral has unsanitized data fields High
GHSA-c7hr-448w-65px was published for meshcentral (npm) Aug 18, 2026
kevthehermit Credited to kevthehermit
MagicMirror socket payload secret placeholder expansion can disclose SECRET_* environment variables Moderate
CVE-2026-63640 was published for magicmirror (npm) Aug 18, 2026
sondt99 Credited to sondt99
MagicMirror: ssrf calendar .js Moderate
CVE-2026-63643 was published for magicmirror (npm) Aug 18, 2026
gabrie0x6c Credited to gabrie0x6c
MagicMirror newsfeed Socket.IO notification allows blind server-side request forgery Moderate
CVE-2026-63642 was published for magicmirror (npm) Aug 18, 2026
gabrie0x6c Credited to gabrie0x6c
sondt99 Credited to sondt99
@rhinostone/swig: arbitrary local file read via include/extends path traversal High
GHSA-2mf3-mr2r-r4vf was published for @rhinostone/swig (npm) Aug 18, 2026
Martin-Luther Credited to Martin-Luther
geo-chen Credited to geo-chen
MLflow: LogInputs endpoint bypasses per-run UPDATE authorization in basic-auth Moderate
CVE-2026-69146 was published for mlflow (npm) Aug 17, 2026
geo-chen Credited to geo-chen
ProTip! Advisories are also available from the GraphQL API