Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

75 advisories

Loading
Claude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio) High
CVE-2026-73222 was published for claude-code-templates (npm) Sep 3, 2026
spartan8806 Credited to spartan8806
@hono/oauth-providers: OAuth state check fails open on omitted state, enabling login CSRF and forced account linking Moderate
CVE-2026-81888 was published for @hono/oauth-providers (npm) Aug 31, 2026
TarPeg007 Credited to TarPeg007
Zwique Credited to Zwique
Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF) High
GHSA-pvcr-8mvp-w8qr was published for @budibase/server (npm) Jul 24, 2026
hypnguyen1209 Credited to hypnguyen1209
React Router: RSC Mode CSRF Bypass Allows Action Execution Before 400 Response High
GHSA-qwww-vcr4-c8h2 was published for react-router (npm) Jul 24, 2026
radityahack Credited to radityahack, AlexGustafsson, erkro1, jochenschmich-aeberle, omgovich, Jojo134, benfranke, ryanthemanuel, yhlee-tw, marshalium, acastlesibm, bosnian, georgevgs, grgrzybek, KsAkira10, and giladmoyal-ai AlexGustafsson AlexGustafsson
erkro1 erkro1 jochenschmich-aeberle jochenschmich-aeberle omgovich omgovich Jojo134 Jojo134 benfranke benfranke ryanthemanuel ryanthemanuel yhlee-tw yhlee-tw marshalium marshalium acastlesibm acastlesibm bosnian bosnian georgevgs georgevgs grgrzybek grgrzybek KsAkira10 KsAkira10 giladmoyal-ai giladmoyal-ai
jlgore Credited to jlgore
webpack-dev-server vulnerable to cross-site request forgery via internal developer endpoints Moderate
CVE-2026-14620 was published for webpack-dev-server (npm) Jul 20, 2026
Pig-Tail Credited to Pig-Tail, bjohansebas, and UlisesGascon bjohansebas bjohansebas
UlisesGascon UlisesGascon
Waku: Cross-Origin CSRF on RSC Server Action Dispatch Moderate
CVE-2026-49455 was published for waku (npm) Jul 8, 2026
j0hndo Credited to j0hndo
Budibase has an Account Impersonation Issue — Chat Identity Link Hijacking via Missing Consent & CSRF High
CVE-2026-50132 was published for @budibase/server (npm) Jun 22, 2026
VishaaLlKumaaRr Credited to VishaaLlKumaaRr
Uni-CLI: Legacy HTTP MCP transport accepted browser-originated localhost requests High
GHSA-v3f4-w7r7-v3hm was published for @zenalexa/unicli (npm) Jun 19, 2026
dodge1218 Credited to dodge1218
Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions Moderate
GHSA-mxjx-28vx-xjjj was published for network-ai (npm) Jun 19, 2026
EchoSkorJjj Credited to EchoSkorJjj
React Router: Potential CSRF via PUT/PATCH/DELETE document requests Low
CVE-2026-53663 was published for @remix-run/server-runtime (npm) Jun 15, 2026
gasbugs Credited to gasbugs
Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker Moderate
CVE-2026-48147 was published for @budibase/backend-core (npm) Jun 12, 2026
b-hermes Credited to b-hermes
Turbo: Login callback CSRF/session fixation Moderate
CVE-2026-45773 was published for turbo (npm) May 19, 2026
DanStuartDept Credited to DanStuartDept, jpleyden98, and ToshB jpleyden98 jpleyden98
ToshB ToshB
dynoxide: DNS rebinding and cross-origin CSRF via MCP HTTP transport High
GHSA-fvh2-gm75-j4j7 was published for dynoxide (npm) May 18, 2026
hicksy Credited to hicksy
Better Auth: OAuth callback accepts mismatched `state` when cookie-backed state storage is used without PKCE Moderate
GHSA-wxw3-q3m9-c3jr was published for better-auth (npm) May 15, 2026
Jvr2022 Credited to Jvr2022 and alavesa alavesa alavesa
OpenClaude MCP OAuth Callback: State Check Bypass via error Param Leads to DoS Moderate
CVE-2026-42073 was published for @gitlawb/openclaude (npm) May 12, 2026
xancyber Credited to xancyber
RedwoodSDK has Same-site CSRF through lack of origin validation in its server actions Moderate
CVE-2026-42190 was published for rwsdk (npm) Apr 24, 2026
mthx Credited to mthx
Duplicate Advisory: OpenClaw: HTTP operator endpoints lack browser-origin validation in trusted-proxy mode Low
GHSA-2xp4-qhr4-xqm2 was published for openclaw (npm) Apr 24, 2026 withdrawn
gabiudrescu Credited to gabiudrescu
RedwoodSDK has a CSRF vulnerability in server function dispatch via GET requests High
CVE-2026-39371 was published for rwsdk (npm) Apr 8, 2026
zebbern Credited to zebbern
OpenClaw: HTTP operator endpoints lack browser-origin validation in trusted-proxy mode Low
CVE-2026-41347 was published for openclaw (npm) Apr 3, 2026
AntAISecurityLab Credited to AntAISecurityLab
Payload has a CSRF Protection Bypass in Authentication Flow Moderate
CVE-2026-34749 was published for payload (npm) Apr 1, 2026
Next.js: null origin can bypass Server Actions CSRF checks Moderate
CVE-2026-27978 was published for next (npm) Mar 17, 2026
Mercurius: Incorrect Content-Type parsing can lead to CSRF attack Moderate
CVE-2025-64166 was published for mercurius (npm) Mar 5, 2026
simone-sanfratello Credited to simone-sanfratello
ProTip! Advisories are also available from the GraphQL API