GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,876
Erlang
37
GitHub Actions
36
Go
2,521
Maven
5,000+
npm
4,167
NuGet
741
pip
3,963
Pub
12
RubyGems
946
Rust
1,028
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,616 advisories
Filter by severity
Claude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn Versions
High
CVE-2025-59828
was published
for
@anthropic-ai/claude-code
(npm)
Sep 24, 2025
tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball
High
CVE-2025-59343
was published
for
tar-fs
(npm)
Sep 24, 2025
messageformat prototype pollution vulnerability
High
CVE-2025-57353
was published
for
@messageformat/runtime
(npm)
Sep 24, 2025
Mesh Connect JS SDK Vulnerable to Cross Site Scripting via createLink.openLink
High
CVE-2025-59430
was published
for
@meshconnect/web-link-sdk
(npm)
Sep 22, 2025
`git-comiters` Command Injection vulnerability
High
CVE-2025-59831
was published
for
git-commiters
(npm)
Sep 22, 2025
Codex has sandbox bypass due to bug in path configuration logic
High
CVE-2025-59532
was published
for
@openai/codex
(npm)
Sep 19, 2025
@executeautomation/database-server does not properly restrict access, bypassing a "read-only" mode
High
CVE-2025-59333
was published
for
@executeautomation/database-server
(npm)
Sep 16, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59331
was published
for
is-arrayish
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59330
was published
for
error-ex
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59162
was published
for
color-convert
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59145
was published
for
color-name
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59144
was published
for
debug
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59143
was published
for
color
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59142
was published
for
color-string
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59141
was published
for
simple-swizzle
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59140
was published
for
backslash
(npm)
Sep 15, 2025
Flowise has unsandboxed remote code execution via Custom MCP
High
GHSA-6933-jpx5-q87q
was published
for
flowise
(npm)
Sep 15, 2025
FlowiseAI/Flowise has Server-Side Request Forgery (SSRF) vulnerability
High
CVE-2025-59527
was published
for
flowise
(npm)
Sep 15, 2025
Axios is vulnerable to DoS attack through lack of data size check
High
CVE-2025-58754
was published
for
axios
(npm)
Sep 11, 2025
Prebid.js NPM package briefly compromised
High
CVE-2025-59038
was published
for
prebid.js
(npm)
Sep 11, 2025
Angular SSR: Global Platform Injector Race Condition Leads to Cross-Request Data Leakage
High
CVE-2025-59052
was published
for
@angular/platform-server
(npm)
Sep 10, 2025
Claude Code vulnerable to arbitrary code execution caused by maliciously configured git email
High
CVE-2025-59041
was published
for
@anthropic-ai/claude-code
(npm)
Sep 10, 2025
Webrecorder packages are vulnerable to XSS through 404 error handling logic
High
CVE-2025-58765
was published
for
@webrecorder/archivewebpage
(npm)
Sep 10, 2025
Claude Code rg vulnerability does not protect against approval prompt bypass
High
CVE-2025-58764
was published
for
@anthropic-ai/claude-code
(npm)
Sep 10, 2025
Cattown is Vulnerable to Uncontrolled Resource Consumption through Inefficient Regular Expression Complexity
High
CVE-2025-58451
was published
for
cattown
(npm)
Sep 9, 2025
ProTip!
Advisories are also available from the
GraphQL API