Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

9 advisories

Loading
matte1782 Credited to matte1782
GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusion Moderate
CVE-2026-48529 was published for github.com/github/github-mcp-server (Go) Jun 25, 2026
hewei-gikaku Credited to hewei-gikaku, matte1782, kerobbi, and JoannaaKL matte1782 matte1782
kerobbi kerobbi JoannaaKL JoannaaKL
hackkim Credited to hackkim and matte1782 matte1782 matte1782
matte1782 Credited to matte1782 and Classic298 Classic298 Classic298
Dex: Token-exchange endpoint is missing AllowedConnectors enforcement High
GHSA-7qjx-gp9h-65qj was published for github.com/dexidp/dex (Go) Jun 9, 2026
matte1782 Credited to matte1782
Kirby CMS's content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions Moderate
CVE-2026-45334 was published for getkirby/cms (Composer) May 27, 2026
matte1782 Credited to matte1782
matte1782 Credited to matte1782 and rdimitrov rdimitrov rdimitrov
Open WebUI vulnerable to stored XSS via OAuth picture claim stored as SVG data URI in profile_image_url High
GHSA-3wgj-c2hg-vm6q was published for open-webui (pip) May 14, 2026
matte1782 Credited to matte1782
ProTip! Advisories are also available from the GraphQL API