Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4,597 advisories

Loading
pnpm has Windows-specific tarball Path Traversal Moderate
CVE-2026-23889 was published for pnpm (npm) Jan 26, 2026
mldangelo
Credited to mldangelo
pnpm scoped bin name Path Traversal allows arbitrary file creation outside node_modules/.bin Moderate
CVE-2026-23890 was published for pnpm (npm) Jan 26, 2026
mldangelo
Credited to mldangelo
pnpm has symlink traversal in file:/git dependencies Moderate
CVE-2026-24056 was published for pnpm (npm) Jan 26, 2026
mldangelo
Credited to mldangelo
vm2 has a Sandbox Escape Critical
CVE-2026-22709 was published for vm2 (npm) Jan 26, 2026
dcap-qvl has Missing Verification for QE Identity Critical
CVE-2026-22696 was published for @phala/dcap-qvl (npm) Jan 26, 2026
Withdrawn Advisory: eslint has a Stack Overflow when serializing objects with circular references Moderate
CVE-2025-50537 was published for eslint (npm) Jan 26, 2026 withdrawn
lukemcgregor
Credited to lukemcgregor
Duplicate Advisory: npm cli Uncontrolled Search Path Element Local Privilege Escalation Vulnerability High
CVE-2026-0775 was published for npm (npm) Jan 23, 2026 withdrawn
Mauripache
Credited to Mauripache
Orval Mock Generation Code Injection via const High
CVE-2026-24132 was published for @orval/mock (npm) Jan 22, 2026
k14uz
Credited to k14uz
Seroval affected by Denial of Service via Deeply Nested Objects High
CVE-2026-24006 was published for seroval (npm) Jan 22, 2026
lxsmnsyc tweidinger
Credited to lxsmnsyc and tweidinger
Typebot affected by Credential Theft via Client-Side Script Execution and API Authorization Bypass High
CVE-2025-65098 was published for @typebot.io/js (npm) Jan 22, 2026
Deyvi-dev
Credited to Deyvi-dev
Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions Moderate
CVE-2025-13465 was published for lodash (npm) Jan 21, 2026
lukas-eu ljharb
UlisesGascon falsyvalues jdalton
Credited to lukas-eu, ljharb, UlisesGascon, falsyvalues, and jdalton
Wrangler affected by OS Command Injection in `wrangler pages deploy` High
CVE-2026-0933 was published for wrangler (npm) Jan 21, 2026
yueyueL
Credited to yueyueL
Backstage has a Possible SSRF when reading from allowed URL's in `backend.reading.allow` Low
CVE-2026-24048 was published for @backstage/backend-defaults (npm) Jan 21, 2026
@backstage/cli-common has a possible `resolveSafeChildPath` Symlink Chain Bypass Moderate
CVE-2026-24047 was published for @backstage/cli-common (npm) Jan 21, 2026
Backstage has a Possible Symlink Path Traversal in Scaffolder Actions High
CVE-2026-24046 was published for @backstage/backend-defaults (npm) Jan 21, 2026
Seroval affected by Denial of Service via Array serialization High
CVE-2026-23957 was published for seroval (npm) Jan 21, 2026
tweidinger lxsmnsyc
Credited to tweidinger and lxsmnsyc
seroval affected by Denial of Service via RegExp serialization High
CVE-2026-23956 was published for seroval (npm) Jan 21, 2026
tweidinger lxsmnsyc
Credited to tweidinger and lxsmnsyc
@envelop/graphql-modules has a Race Condition vulnerability High
GHSA-h3hw-29fv-2x75 was published for @envelop/graphql-modules (npm) Jan 21, 2026
DuckThom enisdenjo
ardatan
Credited to DuckThom, enisdenjo, and ardatan
sm-crypto Affected by Signature Forgery in SM2-DSA High
CVE-2026-23965 was published for sm-crypto (npm) Jan 21, 2026
XlabAITeam A7um
tl2cents keenanwgn
Credited to XlabAITeam, A7um, tl2cents, and keenanwgn
sm-crypto Affected by Signature Malleability in SM2-DSA High
CVE-2026-23967 was published for sm-crypto (npm) Jan 21, 2026
XlabAITeam A7um
tl2cents keenanwgn
Credited to XlabAITeam, A7um, tl2cents, and keenanwgn
sm-crypto Affected by Private Key Recovery in SM2-PKE Critical
CVE-2026-23966 was published for sm-crypto (npm) Jan 21, 2026
XlabAITeam A7um
tl2cents keenanwgn
Credited to XlabAITeam, A7um, tl2cents, and keenanwgn
seroval Affected by Remote Code Execution via JSON Deserialization High
CVE-2026-23737 was published for seroval (npm) Jan 21, 2026
GabbeV tweidinger
lxsmnsyc
Credited to GabbeV, tweidinger, and lxsmnsyc
seroval Affected by Prototype Pollution via JSON Deserialization High
CVE-2026-23736 was published for seroval (npm) Jan 21, 2026
lxsmnsyc tweidinger
Credited to lxsmnsyc and tweidinger
tomasilluminati
Credited to tomasilluminati
Orval has a code injection via unsanitized x-enum-descriptions in enum generation Critical
CVE-2026-23947 was published for @orval/core (npm) Jan 21, 2026
k14uz ZipJo
Credited to k14uz and ZipJo
ProTip! Advisories are also available from the GraphQL API