Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

2 advisories

Loading
Budibase auth session cookies are set with httpOnly:false — any XSS can lead to full account takeover High
CVE-2026-42239 was published for @budibase/backend-core (npm) Apr 24, 2026
AyushParkara Credited to AyushParkara
PenPot MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE High
CVE-2026-45805 was published for @penpot/mcp (npm) May 19, 2026
AyushParkara Credited to AyushParkara and overgrowncarrot1 overgrowncarrot1 overgrowncarrot1
ProTip! Advisories are also available from the GraphQL API