Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

388 advisories

Loading
mathlive's Lack of Escaping of HTML allows for XSS Moderate
CVE-2026-54705 was published for mathlive (npm) Jul 29, 2026
CosmicCrusader23 Credited to CosmicCrusader23
Shescape: Home-directory disclosure in assignment context on Unix with Dash Moderate
GHSA-q53c-4prm-w95q was published for shescape (npm) Jul 24, 2026
oran-s Credited to oran-s and ericcornelissen ericcornelissen ericcornelissen
ImageMagick: Code injection in HTML encoder due to incomplete fix of CVE-2026-25797 Moderate
GHSA-hc76-7mpc-qjqh was published for Magick.NET-Q16-AnyCPU (NuGet) Jul 24, 2026
rexpository Credited to rexpository
JupyterLab: Cross-site scripting (XSS) via crafted settings file (`overrides.json`) High
GHSA-pppj-hq3g-57pj was published for jupyterlab (pip) Jul 22, 2026
de3erve-hunter Credited to de3erve-hunter, MUFFANUJ, and krassowski MUFFANUJ MUFFANUJ
krassowski krassowski
yorukot Credited to yorukot
Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility Moderate
CVE-2026-59895 was published for hono (npm) Jul 21, 2026
a-tt-om Credited to a-tt-om and teebow1e teebow1e teebow1e
Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands Low
CVE-2026-59727 was published for astro (npm) Jul 20, 2026
jlgore Credited to jlgore
Microsoft Security Advisory CVE-2026-50659 – .NET Spoofing Vulnerability Moderate
CVE-2026-50659 was published for Microsoft.NetCore.App.Runtime.linux-arm (NuGet) Jul 20, 2026
Tesla vulnerable to multipart part smuggling via unescaped `content-disposition` values Low
CVE-2026-48598 was published for tesla (Erlang) Jul 10, 2026
PJUllrich Credited to PJUllrich, yordis, and maennchen yordis yordis
maennchen maennchen
YesWiki has stored XSS in Bazar form-field templates via unescaped field.label / field.hint (|raw('html')) Moderate
CVE-2026-52772 was published for yeswiki/yeswiki (Composer) Jul 9, 2026
offset Credited to offset
rama has Stored XSS in ServeDir HTML directory listing via unescaped file names and URI path Low
GHSA-cwv4-h3j5-w3cf was published for rama (Rust) Jul 7, 2026
chaitanyagarware Credited to chaitanyagarware
printenv: environment variables with invalid UTF-8 are silently skipped (evades inspection) Moderate
CVE-2026-35366 was published for uu_printenv (Rust) Jul 6, 2026
comm: lossy UTF-8 conversion silently corrupts non-UTF-8 output Low
CVE-2026-35346 was published for uu_comm (Rust) Jul 6, 2026
justhtml: to_markdown() code-span blank-line breakout enables XSS Moderate
GHSA-jf6w-2mvx-633j was published for justhtml (pip) Jun 25, 2026
seankohjs Credited to seankohjs and yueyueL yueyueL yueyueL
ProTip! Advisories are also available from the GraphQL API