GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            126 advisories
        Filter by severity
        
      
      
    
                    
                      Astro's bypass of image proxy domain validation leads to SSRF and potential XSS
                    
                      
  High
                    
                
                      
                        CVE-2025-59837
                      
                      was published
                        for
                        
                          astro
                        
                        (npm)
                      Oct 28, 2025 
                    
                  
                    
                      Duplicate Advisory: Flowise Stored XSS vulnerability through logs in chatbot
                    
                      
  High
                    
                
                      
                        GHSA-wq95-wr7m-26h4
                      
                      was published
                        for
                        
                          flowise
                        
                        (npm)
                      Oct 6, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      Duplicate Advisory: Flowise is vulnerable to stored XSS via "View Messages" allows credential theft in FlowiseAI admin panel
                    
                      
  High
                    
                
                      
                        GHSA-7rgr-72hp-9wp3
                      
                      was published
                        for
                        
                          flowise
                        
                        (npm)
                      Oct 6, 2025 
                        •
                        
                          withdrawn
                    
                  
                    
                      Mesh Connect JS SDK Vulnerable to Cross Site Scripting via createLink.openLink
                    
                      
  High
                    
                
                      
                        CVE-2025-59430
                      
                      was published
                        for
                        
                          @meshconnect/web-link-sdk
                        
                        (npm)
                      Sep 22, 2025 
                    
                  
                    
                      Webrecorder packages are vulnerable to XSS through 404 error handling logic
                    
                      
  High
                    
                
                      
                        CVE-2025-58765
                      
                      was published
                        for
                        
                          @webrecorder/archivewebpage
                        
                        (npm)
                      Sep 10, 2025 
                    
                  
                    
                      MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server
                    
                      
  High
                    
                
                      
                        CVE-2025-58444
                      
                      was published
                        for
                        
                          @modelcontextprotocol/inspector
                        
                        (npm)
                      Sep 8, 2025 
                    
                  
                    
                      N8N's Chat Trigger component is vulnerable to XSS
                    
                      
  High
                    
                
                      
                        CVE-2025-56265
                      
                      was published
                        for
                        
                          @n8n/n8n-nodes-langchain
                        
                        (npm)
                      Sep 8, 2025 
                    
                  
                    
                      Stored XSS in n8n Form Trigger allows Account Takeover via injected iframe and video/source
                    
                      
  High
                    
                
                      
                        CVE-2025-52478
                      
                      was published
                        for
                        
                          n8n
                        
                        (npm)
                      Aug 19, 2025 
                    
                  
                    
                      NodeJS version of HAX CMS Has Disabled Content Security Policy That Enables Cross-Site Scripting
                    
                      
  High
                    
                
                      
                        CVE-2025-54128
                      
                      was published
                        for
                        
                          @haxtheweb/haxcms-nodejs
                        
                        (npm)
                      Jul 21, 2025 
                    
                  
                    
                      Nuxt MDC has an XSS vulnerability in markdown rendering that bypasses HTML filtering
                    
                      
  High
                    
                
                      
                        CVE-2025-54075
                      
                      was published
                        for
                        
                          @nuxtjs/mdc
                        
                        (npm)
                      Jul 20, 2025 
                    
                  
                    
                      DOM Expressions has a Cross-Site Scripting (XSS) vulnerability due to improper use of string.replace
                    
                      
  High
                    
                
                      
                        CVE-2025-27108
                      
                      was published
                        for
                        
                          dom-expressions
                        
                        (npm)
                      Feb 25, 2025 
                    
                  
                    
                      Solid Lacks Escaping of HTML in JSX Fragments allows for Cross-Site Scripting (XSS)
                    
                      
  High
                    
                
                      
                        CVE-2025-27109
                      
                      was published
                        for
                        
                          solid-js
                        
                        (npm)
                      Feb 25, 2025 
                    
                  
                    
                      DOMpurify has a nesting-based mXSS
                    
                      
  High
                    
                
                      
                        CVE-2024-47875
                      
                      was published
                        for
                        
                          dompurify
                        
                        (npm)
                      Oct 11, 2024 
                    
                  
                    
                      DOM Clobbering Gadget found in rollup bundled scripts that leads to XSS
                    
                      
  High
                    
                
                      
                        CVE-2024-47068
                      
                      was published
                        for
                        
                          rollup
                        
                        (npm)
                      Sep 23, 2024 
                    
                  
                    
                      Plate allows arbitrary DOM attributes in element.attributes and leaf.attributes
                    
                      
  High
                    
                
                      
                        CVE-2024-47061
                      
                      was published
                        for
                        
                          @udecode/plate-core
                        
                        (npm)
                      Sep 20, 2024 
                    
                  
                    
                      gettext.js has a Cross-site Scripting injection 
                    
                      
  High
                    
                
                      
                        CVE-2024-43370
                      
                      was published
                        for
                        
                          gettext.js
                        
                        (npm)
                      Aug 15, 2024 
                    
                  
                    
                      Plate media plugins has a XSS in media embed element when using custom URL parsers
                    
                      
  High
                    
                
                      
                        CVE-2024-40631
                      
                      was published
                        for
                        
                          @udecode/plate-media
                        
                        (npm)
                      Jul 15, 2024 
                    
                  
                    
                      ghtml Cross-Site Scripting (XSS) vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2024-37166
                      
                      was published
                        for
                        
                          ghtml
                        
                        (npm)
                      Jun 10, 2024 
                    
                  
                    
                      Withdrawn Advisory: lunary-ai/lunary XSS in SAML metadata endpoint
                    
                      
  High
                    
                
                      
                        CVE-2024-5478
                      
                      was published
                        for
                        
                          lunary
                        
                        (npm)
                      Jun 6, 2024 
                        •
                        
                          withdrawn
                    
                  
                    
                      NocoDB Vulnerable to Stored Cross-Site Scripting in Formula.vue
                    
                      
  High
                    
                
                      
                        CVE-2023-49781
                      
                      was published
                        for
                        
                          nocodb
                        
                        (npm)
                      May 13, 2024 
                    
                  
                    
                      react-pdf vulnerable to arbitrary JavaScript execution upon opening a malicious PDF with PDF.js
                    
                      
  High
                    
                
                      
                        CVE-2024-34342
                      
                      was published
                        for
                        
                          react-pdf
                        
                        (npm)
                      May 7, 2024 
                    
                  
                    
                      Cross-site Scripting in electron-pdf
                    
                      
  High
                    
                
                      
                        CVE-2024-1648
                      
                      was published
                        for
                        
                          electron-pdf
                        
                        (npm)
                      Feb 20, 2024 
                    
                  
                    
                      @urql/next Cross-site Scripting vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2024-24556
                      
                      was published
                        for
                        
                          @urql/next
                        
                        (npm)
                      Jan 30, 2024 
                    
                  
                    
                      react-query-streamed-hydration Cross-site Scripting vulnerability
                    
                      
  High
                    
                
                      
                        CVE-2024-24558
                      
                      was published
                        for
                        
                          @tanstack/react-query-next-experimental
                        
                        (npm)
                      Jan 30, 2024 
                    
                  
                    
                      Improper Neutralization of Script in Attributes in @dcl/single-sign-on-client
                    
                      
  High
                    
                
                      
                        CVE-2023-41049
                      
                      was published
                        for
                        
                          @dcl/single-sign-on-client
                        
                        (npm)
                      Sep 4, 2023 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API