GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,820
Maven
5,000+
npm
4,444
NuGet
774
pip
4,215
Pub
12
RubyGems
970
Rust
1,089
Swift
47
Unreviewed advisories
All unreviewed
5,000+
63 advisories
Filter by severity
pnpm vulnerable to Command Injection via environment variable substitution
High
CVE-2025-69262
was published
for
pnpm
(npm)
Jan 7, 2026
Signal K Server Vulnerable to Remote Code Execution via Malicious npm Package
High
CVE-2025-68619
was published
for
signalk-server
(npm)
Jan 2, 2026
Claude Code vulnerable to command execution prior to startup trust dialog
High
CVE-2025-65099
was published
for
@anthropic-ai/claude-code
(npm)
Nov 19, 2025
Lightning Flow Scanner Vulnerable to Code Injection via Unsafe Use of `new Function()` in APIVersion Rule
High
CVE-2025-67750
was published
for
lightning-flow-scanner
(npm)
Dec 12, 2025
tinacms is vulnerable to arbitrary code execution
High
CVE-2025-68278
was published
for
@tinacms/cli
(npm)
Dec 18, 2025
Elysia affected by arbitrary code injection through cookie config
High
CVE-2025-66457
was published
for
elysia
(npm)
Dec 9, 2025
expr-eval does not restrict functions passed to the evaluate function
High
CVE-2025-12735
was published
for
expr-eval
(npm)
Nov 5, 2025
Claude Code can execute commands prior to the startup trust dialog
High
CVE-2025-59536
was published
for
@anthropic-ai/claude-code
(npm)
Oct 3, 2025
MCP Inspector is Vulnerable to Potential Command Execution via XSS When Connecting to an Untrusted MCP Server
High
CVE-2025-58444
was published
for
@modelcontextprotocol/inspector
(npm)
Sep 8, 2025
Claude Code vulnerable to arbitrary code execution caused by maliciously configured git email
High
CVE-2025-59041
was published
for
@anthropic-ai/claude-code
(npm)
Sep 10, 2025
Claude Code rg vulnerability does not protect against approval prompt bypass
High
CVE-2025-58764
was published
for
@anthropic-ai/claude-code
(npm)
Sep 10, 2025
Claude Code Vulnerable to Arbitrary Code Execution Due to Insufficient Startup Warning
High
GHSA-ph6w-f82w-28w6
was published
for
@anthropic-ai/claude-code
(npm)
Sep 3, 2025
ejson shell parser in MongoDB Compass maybe bypassed
High
CVE-2024-6376
was published
for
@mongodb-js/connection-form
(npm)
Jul 1, 2024
JSONPath Plus allows Remote Code Execution
High
CVE-2025-1302
was published
for
jsonpath-plus
(npm)
Feb 15, 2025
Remote Code Execution on click of <a> Link in markdown preview
High
CVE-2024-49362
was published
for
joplin
(npm)
Nov 14, 2024
Systeminformation has command injection vulnerability in getWindowsIEEE8021x (SSID)
High
CVE-2024-56334
was published
for
systeminformation
(npm)
Dec 20, 2024
lilconfig Code Injection vulnerability
High
CVE-2024-21537
was published
for
lilconfig
(npm)
Oct 31, 2024
OS Command Injection in Snyk gradle plugin
High
CVE-2024-48964
was published
for
snyk-gradle-plugin
(npm)
Oct 23, 2024
Remote command execution in promptr
High
CVE-2024-46489
was published
for
@ifnotnowwhen/promptr
(npm)
Sep 25, 2024
squirrelly Code Injection vulnerability
High
CVE-2024-40453
was published
for
squirrelly
(npm)
Aug 21, 2024
Flowise vulnerable to code injection via api/v1
High
CVE-2024-31621
was published
for
flowise
(npm)
Apr 29, 2024
Badger Database Prototype Pollution
High
CVE-2024-36581
was published
for
@abw/badger-database
(npm)
Jun 17, 2024
javascript-deobfuscator crafted payload can lead to code execution
High
CVE-2024-36120
was published
for
js-deobfuscator
(npm)
Jun 4, 2024
ProTip!
Advisories are also available from the
GraphQL API