GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,963
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,036
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
192 advisories
Filter by severity
Kottster app reinitialization can be re-triggered allowing command injection in development mode
High
CVE-2025-62713
was published
for
@kottster/server
(npm)
Oct 23, 2025
Command Injection Vulnerability
High
CVE-2021-21315
was published
for
systeminformation
(npm)
Feb 16, 2021
Remote Code Execution Vulnerability in NPM mongo-express
Critical
CVE-2019-10758
was published
for
mongo-express
(npm)
Dec 30, 2019
`git-comiters` Command Injection vulnerability
High
CVE-2025-59831
was published
for
git-commiters
(npm)
Sep 22, 2025
n8n: Execute Command Node Allows Authenticated Users to Run Arbitrary Commands on Host
High
GHSA-365g-vjw2-grx8
was published
for
n8n
(npm)
Oct 9, 2025
check-branches is vulnerable to command Injection
Critical
CVE-2025-11148
was published
for
check-branches
(npm)
Sep 30, 2025
Command Injection in adb-mcp MCP Server
Critical
CVE-2025-59834
was published
for
adb-mcp
(npm)
Sep 24, 2025
Claude Code vulnerable to arbitrary code execution caused by maliciously configured git email
High
CVE-2025-59041
was published
for
@anthropic-ai/claude-code
(npm)
Sep 10, 2025
Flowise has unsandboxed remote code execution via Custom MCP
High
GHSA-6933-jpx5-q87q
was published
for
flowise
(npm)
Sep 15, 2025
wong2 mcp-cli Command Injection Vulnerability
Low
CVE-2025-9262
was published
for
@wong2/mcp-cli
(npm)
Aug 21, 2025
@akoskm/create-mcp-server-stdio is vulnerable to MCP Server Command Injection through `exec` API
Critical
CVE-2025-54994
was published
for
@akoskm/create-mcp-server-stdio
(npm)
Sep 8, 2025
Flowise OS command remote code execution
Critical
CVE-2025-8943
was published
for
flowise
(npm)
Aug 14, 2025
Claude Code's Permissive Default Allowlist Enables Unauthorized File Read and Network Exfiltration in Claude Code
High
CVE-2025-55284
was published
for
@anthropic-ai/claude-code
(npm)
Aug 18, 2025
Withdrawn Advisory: bun vulnerable to OS Command Injection
High
CVE-2025-8022
was published
for
bun
(npm)
Jul 23, 2025
•
withdrawn
Claude Code echo command allowed bypass of user approval prompt for command execution
High
CVE-2025-54795
was published
for
@anthropic-ai/claude-code
(npm)
Aug 4, 2025
@nestjs/devtools-integration: CSRF to Sandbox Escape Allows for RCE against JS Developers
Critical
CVE-2025-54782
was published
for
@nestjs/devtools-integration
(npm)
Aug 1, 2025
GitHub Kanban MCP Server vulnerable to Command Injection
High
CVE-2025-53818
was published
for
@sunwood-ai-labs/github-kanban-mcp-server
(npm)
Jul 15, 2025
mcp-remote exposed to OS command injection via untrusted MCP server connections
Critical
CVE-2025-6514
was published
for
mcp-remote
(npm)
Jul 9, 2025
iOS Simulator MCP Command Injection allowed via exec API
Moderate
CVE-2025-52573
was published
for
ios-simulator-mcp
(npm)
Jun 26, 2025
HaxCMS-PHP Command Injection Vulnerability
High
CVE-2025-49141
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jun 9, 2025
cycle-import-check vulnerable to Command Injection
Critical
CVE-2022-24377
was published
for
cycle-import-check
(npm)
Dec 14, 2022
exec-local-bin vulnerable to Command Injection
Critical
CVE-2022-25923
was published
for
exec-local-bin
(npm)
Jan 6, 2023
global-modules-path Command Injection vulnerability
Critical
CVE-2022-21191
was published
for
global-modules-path
(npm)
Jan 13, 2023
Command Injection in puppet-facter
High
CVE-2022-25350
was published
for
puppet-facter
(npm)
Jan 26, 2023
ProTip!
Advisories are also available from the
GraphQL API