GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,606
Maven
5,000+
npm
5,000+
NuGet
924
pip
4,831
Pub
13
RubyGems
1,045
Rust
1,256
Swift
53
Unreviewed advisories
All unreviewed
5,000+
57 advisories
Filter by severity
RedwoodSDK has Same-site CSRF through lack of origin validation in its server actions
Moderate
GHSA-m2m6-cff5-3w7c
was published
for
rwsdk
(npm)
Apr 24, 2026
engram: HTTP server CORS wildcard + auth-off-by-default enables CSRF graph exfiltration and persistent indirect prompt injection
High
GHSA-2r2p-4cgf-hv7h
was published
for
engramx
(npm)
Apr 22, 2026
RedwoodSDK has a CSRF vulnerability in server function dispatch via GET requests
High
CVE-2026-39371
was published
for
rwsdk
(npm)
Apr 8, 2026
OpenClaw: HTTP operator endpoints lack browser-origin validation in trusted-proxy mode
Moderate
GHSA-mhr7-2xmv-4c4q
was published
for
openclaw
(npm)
Apr 3, 2026
Payload has a CSRF Protection Bypass in Authentication Flow
Moderate
CVE-2026-34749
was published
for
payload
(npm)
Apr 1, 2026
Next.js: null origin can bypass Server Actions CSRF checks
Moderate
CVE-2026-27978
was published
for
next
(npm)
Mar 17, 2026
Mercurius: Incorrect Content-Type parsing can lead to CSRF attack
Moderate
CVE-2025-64166
was published
for
mercurius
(npm)
Mar 5, 2026
Ghost has incomplete CSRF protections around OTC use
High
CVE-2026-29784
was published
for
ghost
(npm)
Mar 5, 2026
Parse Dashboard is Missing CSRF Protection for its Agent Endpoint
High
CVE-2026-27609
was published
for
parse-dashboard
(npm)
Feb 25, 2026
OpenClaw Chutes manual OAuth state validation bypass can cause credential substitution
Moderate
CVE-2026-28477
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw affected by cross-site request forgery (CSRF) through loopback browser mutation endpoints
High
CVE-2026-26317
was published
for
clawdbot
(npm)
Feb 18, 2026
unity-cli Exposes Plaintext Credentials in Debug Logs (sign-package command)
Moderate
CVE-2026-25918
was published
for
@rage-against-the-pixel/unity-cli
(npm)
Feb 10, 2026
Qwik City CSRF protection middleware does not work properly for content type header with parameters (eg. multipart/form-data)
Moderate
CVE-2026-25155
was published
for
@builder.io/qwik-city
(npm)
Feb 3, 2026
Qwik City has a CSRF Protection Bypass via Content-Type Header Validation
Moderate
CVE-2026-25151
was published
for
@builder.io/qwik-city
(npm)
Feb 3, 2026
React Router has CSRF issue in Action/Server Action Request Processing
Moderate
CVE-2026-22030
was published
for
@remix-run/server-runtime
(npm)
Jan 8, 2026
Apollo Embedded Sandbox and Explorer vulnerable to CSRF via window.postMessage origin-validation bypass
High
CVE-2025-59845
was published
for
@apollo/explorer
(npm)
Sep 26, 2025
@nestjs/devtools-integration: CSRF to Sandbox Escape Allows for RCE against JS Developers
Critical
CVE-2025-54782
was published
for
@nestjs/devtools-integration
(npm)
Aug 1, 2025
Bootstrap Multiselect Vulnerable to CSRF and Reflective XSS via Arbitrary POST Data
Moderate
CVE-2025-47204
was published
for
bootstrap-multiselect
(npm)
May 13, 2025
Atro CSRF Middleware Bypass (security.checkOrigin)
Moderate
CVE-2024-56140
was published
for
astro
(npm)
Dec 18, 2024
Avenwu Whistle Cross-Site Request Forgery (CSRF)
High
CVE-2024-55500
was published
for
whistle
(npm)
Dec 10, 2024
Hono allows bypass of CSRF Middleware by a request without Content-Type header.
Moderate
CVE-2024-48913
was published
for
hono
(npm)
Oct 15, 2024
Withdrawn Advisory: Lunary Cross-Site Request Forgery (CSRF) vulnerability
Moderate
CVE-2024-6862
was published
for
@lunary/backend
(npm)
Sep 13, 2024
•
withdrawn
Hono CSRF middleware can be bypassed using crafted Content-Type header
Low
CVE-2024-43787
was published
for
hono
(npm)
Aug 22, 2024
Firebase vulnerable to CRSF attack
Low
CVE-2024-4128
was published
for
firebase-tools
(npm)
May 2, 2024
ProTip!
Advisories are also available from the
GraphQL API