Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

95 advisories

Loading
ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header Moderate
CVE-2026-55087 was published for ep_etherpad-lite (npm) Aug 13, 2026
@backstage/plugin-auth-backend: Unauthenticated OAuth account takeover via `redirect_uri` allowlist bypass Moderate
CVE-2026-73563 was published for @backstage/plugin-auth-backend (npm) Jul 24, 2026
React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass) Moderate
CVE-2026-53669 was published for react-router (npm) Jul 23, 2026
outring Credited to outring
React Router: Open redirect leading to XSS Moderate
CVE-2026-53668 was published for react-router (npm) Jul 23, 2026
SouadSEBAA Credited to SouadSEBAA
@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect Low
CVE-2026-59730 was published for @astrojs/node (npm) Jul 20, 2026
iaohkut-from-NightWolf-Team Credited to iaohkut-from-NightWolf-Team
Waku has an Open Redirect via `unstable_redirect` Helper Low
CVE-2026-49456 was published for waku (npm) Jul 8, 2026
j0hndo Credited to j0hndo
Better Auth has stored XSS in the auth-server origin via javascript: redirect_uri in oidc-provider and mcp High
GHSA-86j7-9j95-vpqj was published for better-auth (npm) Jul 7, 2026
hillalee Credited to hillalee
OpenClaw MCP SSE redirects could forward Authorization headers Moderate
GHSA-9c3v-684m-579c was published for openclaw (npm) Jul 1, 2026
dingliweixlm-byte Credited to dingliweixlm-byte
kulesy Credited to kulesy, sondt99, and dungNHVhust sondt99 sondt99
dungNHVhust dungNHVhust
alcls01111 Credited to alcls01111, cookesan, and sealonohana cookesan cookesan
sealonohana sealonohana
NocoDB: Open Redirect via Hash Fragment in hashRedirect Plugin Moderate
CVE-2026-47377 was published for nocodb (npm) Jun 5, 2026
fg0x0 Credited to fg0x0
sealonohana Credited to sealonohana
osageling Credited to osageling
Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect High
CVE-2026-44503 was published for Microsoft.Kiota.Abstractions (Go) May 7, 2026
MIchaelMainer Credited to MIchaelMainer
Angular SSR has Open Redirect and Request Steering via Encoded X-Forwarded-Prefix Moderate
CVE-2026-44437 was published for @angular/ssr (npm) May 6, 2026
kimkou2024 Credited to kimkou2024, alan-agius4, dgp1130, and AndrewKushnir alan-agius4 alan-agius4
dgp1130 dgp1130 AndrewKushnir AndrewKushnir
Nitro has an Open Redirect via Protocol-Relative URL Bypass in Wildcard Route Rules Moderate
CVE-2026-44372 was published for nitro (npm) May 6, 2026
0x0OZ Credited to 0x0OZ
Duplicate Advisory: OpenClaw: CDP /json/version WebSocket URL could pivot to untrusted second-hop targets Moderate
GHSA-3r56-7hhr-vfg9 was published for openclaw (npm) May 6, 2026 withdrawn
@workos/authkit-session has an Open Redirect via state-derived redirect target Moderate
CVE-2026-42565 was published for @workos/authkit-session (npm) May 5, 2026
kenkunz Credited to kenkunz
Jupyter Notebook Vulnerable to Authentication Token Theft via CommandLinker XSS High
CVE-2026-40171 was published for @jupyter-notebook/help-extension (npm) Apr 30, 2026
dtrops Credited to dtrops, Carreau, Yann-P, krassowski, and jtpio Carreau Carreau
Yann-P Yann-P krassowski krassowski jtpio jtpio
n8n has Open Redirect in MCP OAuth Consent Flow Moderate
CVE-2026-42230 was published for n8n (npm) Apr 29, 2026
ori-ron Credited to ori-ron
OpenClaw: CDP /json/version WebSocket URL could pivot to untrusted second-hop targets Moderate
CVE-2026-43576 was published for openclaw (npm) Apr 17, 2026
nicky-cc Credited to nicky-cc
Saltcorn: Open Redirect in `POST /auth/login` due to incomplete `is_relative_url` validation (backslash bypass) Moderate
CVE-2026-42259 was published for @saltcorn/server (npm) Apr 16, 2026
@adonisjs/http-server has an Open Redirect vulnerability Moderate
CVE-2026-40255 was published for @adonisjs/core (npm) Apr 14, 2026
thetutlage Credited to thetutlage and TheAdamGalloway TheAdamGalloway TheAdamGalloway
next-intl has an open redirect vulnerability Moderate
CVE-2026-40299 was published for next-intl (npm) Apr 10, 2026
joniumGit Credited to joniumGit
Duplicate Advisory: OpenClaw: `fetchWithSsrFGuard` replays unsafe request bodies across cross-origin redirects High
GHSA-pg8g-f2hf-x82m was published for openclaw (npm) Apr 9, 2026 withdrawn
ProTip! Advisories are also available from the GraphQL API