Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

34,180 advisories

Loading
Electron: window.open features string controls some window options considered privileged Moderate
CVE-2026-70607 was published for electron (npm) Aug 5, 2026
Electron: ProtocolResponse.url reuses the default session cache instead of the registering session Moderate
CVE-2026-70606 was published for electron (npm) Aug 5, 2026
rushitgit Credited to rushitgit
Electron: HTTP redirect followed into local file loader Moderate
CVE-2026-70605 was published for electron (npm) Aug 5, 2026
Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads High
CVE-2026-70604 was published for electron (npm) Aug 5, 2026
proxydom Credited to proxydom
Electron: Extension tab APIs operate across session boundaries Moderate
CVE-2026-70602 was published for electron (npm) Aug 5, 2026
Electron: shell.openPath path validation bypass via embedded null byte Moderate
CVE-2026-70603 was published for electron (npm) Aug 5, 2026
yassine-doyensec Credited to yassine-doyensec, ikkisoft, and maxence-Doyensec ikkisoft ikkisoft
maxence-Doyensec maxence-Doyensec
Electron: Context isolation bypass via Function.prototype.bind hijack High
CVE-2026-70601 was published for electron (npm) Aug 5, 2026
Electron: Cross-origin iframe can position native autofill popup Low
CVE-2026-70600 was published for electron (npm) Aug 5, 2026
Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin Moderate
CVE-2026-70599 was published for electron (npm) Aug 5, 2026
offset Credited to offset
Electron: Off-screen rendering trusts GPU-supplied geometry over shared-memory size Low
CVE-2026-70598 was published for electron (npm) Aug 5, 2026
Electron: Parent process code-sign check is spoofable Moderate
CVE-2026-70597 was published for electron (npm) Aug 5, 2026
Ghost Content API filter bypass reveals private fields Moderate
CVE-2026-53949 was published for ghost (npm) Aug 5, 2026
Ghost: Cross-Site Scripting in Feature Image Captions Moderate
CVE-2026-70596 was published for ghost (npm) Aug 5, 2026
itamarperetz Credited to itamarperetz
Ghost: Server-Side Request Forgery Mitigation Issue Moderate
CVE-2026-70595 was published for ghost (npm) Aug 5, 2026
Ghost: Paid gift memberships obtainable at minimal cost via the donations feature Moderate
CVE-2026-59817 was published for ghost (npm) Aug 4, 2026
sane100400 Credited to sane100400 and P4P3R-HAK P4P3R-HAK P4P3R-HAK
Ghost: Member existence leak via magic link sign-in response Moderate
CVE-2026-53947 was published for ghost (npm) Aug 4, 2026
XSS in Ghost's ActivityPub client High
CVE-2026-53950 was published for @tryghost/activitypub (npm) Aug 4, 2026
bgeesaman Credited to bgeesaman
Ghost: Session Fixation in Ghost Admin Moderate
CVE-2026-70594 was published for ghost (npm) Aug 4, 2026
Ghost: Theme Upload Path Traversal Moderate
CVE-2026-70593 was published for ghost (npm) Aug 4, 2026
Ghost: Database Backup Path Traversal Moderate
CVE-2026-70592 was published for ghost (npm) Aug 4, 2026
Ghost: Server-Side Request Forgery in Image Fetching Moderate
CVE-2026-70591 was published for ghost (npm) Aug 4, 2026
koyokr Credited to koyokr
Ghost: Blind Password Hash Disclosure in Ghost Admin API Moderate
CVE-2026-70590 was published for ghost (npm) Aug 4, 2026
Ghost: Mobiledoc image-size fetch SSRF Moderate
CVE-2026-53946 was published for ghost (npm) Aug 4, 2026
Ghost: Server-side request forgery via DNS rebinding in external request handling Moderate
CVE-2026-53945 was published for ghost (npm) Aug 4, 2026
l3tchupkt Credited to l3tchupkt
Ghost: Private IP filtering bypass to make server-side requests to internal services Moderate
CVE-2026-53944 was published for ghost (npm) Aug 4, 2026
l3tchupkt Credited to l3tchupkt
ProTip! Advisories are also available from the GraphQL API