$ gh advisory list --reviewed

Security advisories

// github advisory database · npm · composer · actions — aggiornato 2026-08-14 07:26 UTC

High 2026-08-13
@trigger.dev/corenpm

Trigger.dev: Prototype pollution via run metadata operations → process-wide cross-tenant DoS

Moderate 2026-08-13
ep_etherpad-litenpm

ep_etherpad-lite: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token

Moderate 2026-08-13
ep_etherpad-litenpm

ep_etherpad-lite: Import/export uses Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwrite

Moderate 2026-08-13
ep_etherpad-litenpm

ep_etherpad-lite: Cache-poisoning Cross-site Scripting and Open Redirect via x-proxy-path Header

High 2026-08-13
pimcore/pimcorecomposer

Pimcore: ClassDefinition UID regex missing end anchor allows SQL injection via Block.php unquoted table name

Moderate 2026-08-12
thorsten/phpmyfaqcomposer

phpMyFAQ: SQL LIKE Wildcard Injection in Chat User Search Allows Authenticated User Enumeration

GHSA-6pvm-2vjj-rx4w CVE-2026-47132 patch: ≥ 4.2.0-alpha
Moderate 2026-08-12
librenms/librenmscomposer

LibreNMS: Reflected XSS via Proxmox instance/vmid GET parameters injected into document.title JavaScript assignment

High 2026-08-12
winter/wn-backend-modulecomposer

Winter: Authenticated backend users can bypass Users controller permission checks

Moderate 2026-08-12
winter/wn-cms-modulecomposer

Winter: Broken access control in `Cms\Controllers\Index` allows cross-template actions and unauthorized asset uploads

Moderate 2026-08-12
winter/wn-backend-modulecomposer

Winter: SQL Injection in Backend Filter Widget numberrange Scope via numbersFromAjax

Moderate 2026-08-11
nuxtnpm

Duplicate Advisory: Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint

Critical 2026-08-07
crypto-jsnpm

crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain

Moderate 2026-08-07
hononpm

Hono: `memo()` retains SSR output across requests, leading to cross-user data disclosure

Critical 2026-08-07
codeigniter4/frameworkcomposer

CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules

High 2026-08-07
codeigniter4/frameworkcomposer

CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames

Critical 2026-08-07
codeigniter4/frameworkcomposer

CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions

Moderate 2026-08-07
codeigniter4/frameworkcomposer

CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure()

Moderate 2026-08-07
api-platform/corecomposer

API Platform Core: Relation IRIs are not type-checked: a related resource can be denormalised as the wrong resource type (type confusion)

Moderate 2026-08-07
@sveltejs/kitnpm

SvelteKit: ReDoS (O(n^2)) in content negotiation — unauthenticated DoS via the Accept header

Moderate 2026-08-07
nuxtnpm

Nuxt dev server discloses project root and workspace UUID via the Chrome DevTools workspace endpoint

Moderate 2026-08-07
dompurifynpm

DOMPurify: IN_PLACE hook removal leaves a detached subtree executable, causing XSS

GHSA-55q2-fjhq-7xh7 patch: ≥ 3.4.13
Critical 2026-08-07
craftcms/cmscomposer

Craft CMS: Passkey login accepts replayed WebAuthn assertions

GHSA-wg23-69c2-gjc8 patch: ≥ 5.10.5
Moderate 2026-08-06
craftcms/cmscomposer

Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts

GHSA-957r-qf9p-67xw patch: ≥ 5.10.6
Moderate 2026-08-06
craftcms/cmscomposer

Craft CMS: Authenticated leak of secret environment variables

GHSA-596p-6jv8-775v patch: ≥ 5.10.6
Moderate 2026-08-06
craftcms/cmscomposer

Craft CMS:Authorization bypass: view-only Categories user can modify category structure via structures/move-element

GHSA-xxpx-f366-4xpq patch: ≥ 5.10.6
Moderate 2026-08-06
craftcms/cmscomposer

Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics

GHSA-rvmm-v933-jgxq patch: ≥ 4.18.1
Low 2026-08-06
craftcms/cmscomposer

Craft CMS: Incorrect path validation could potentially lead to path traversal

GHSA-7hxc-f267-h5q7 patch: ≥ 5.10.6
Moderate 2026-08-06
craftcms/cmscomposer

Craft CMS: Stored XSS in the control panel via unescaped draft name

GHSA-2rp4-x2j7-qmcc patch: ≥ 5.10.8
High 2026-08-06
squizlabs/php_codesniffercomposer

PHP_CodeSniffer gitblame report command injection via crafted filename

Moderate 2026-08-06
re2npm

node-re2: Out-of-bounds heap read in `replace`/`split` via a `Buffer` ending in a truncated multi-byte UTF-8 character → adjacent heap memory disclosed to JavaScript

Moderate 2026-08-06
re2npm

node-re2: String.prototype.replace(re2, template) aborts the Node process (uncatchable ToLocalChecked on empty MaybeLocal) when the result exceeds V8's max string length

High 2026-08-06
ngx-extended-pdf-viewernpm

ngx-extended-pdf-viewer bundles a version of pdf.js vulnerable to CVE-2026-16633

GHSA-w9hm-4m3m-fxmm patch: ≥ 29.0.0-rc.3
High 2026-08-06
craftcms/cmscomposer

Craft CMS: Arbitrary user password reset leading to administrator account takeover

GHSA-p8x7-9vfw-p7vc patch: ≥ 5.10.8
High 2026-08-06
craftcms/cmscomposer

Craft CMS: Authenticated RCE through Twig sandbox escape

GHSA-f5wm-88jv-g5hx patch: ≥ 5.10.7
Moderate 2026-08-06
craftcms/cmscomposer

Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets

High 2026-08-06
craftcms/cmscomposer

Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass

GHSA-265m-7826-wjqm patch: ≥ 5.10.6
Moderate 2026-08-06
league/commonmarkcomposer

league/commonmark: Denial of service via deeply nested XML output

GHSA-mj63-m3rc-8ppr patch: ≥ 2.9.0
High 2026-08-06
league/commonmarkcomposer

league/commonmark: Denial of service via colliding heading slugs

GHSA-mh25-x5hq-wrqp patch: ≥ 2.9.0
High 2026-08-06
league/commonmarkcomposer

league/commonmark: Denial of service via duplicate footnote definitions

GHSA-jfm3-95jq-q3rf patch: ≥ 2.9.0
High 2026-08-06
league/commonmarkcomposer

league/commonmark: Denial of service via adjacent inline attribute blocks

GHSA-g2gp-3wwq-f4ph patch: ≥ 2.9.0
High 2026-08-06
league/commonmarkcomposer

league/commonmark: Quadratic-time denial of service when parsing crafted Markdown

Moderate 2026-08-06
league/commonmarkcomposer

league/commonmark: AttributesExtension href/src unsafe-link filter bypass via embedded control bytes

High 2026-08-06
js-yamlnpm

JS-YAML: Quadratic CPU consumption in !!omap resolution (3.x and 4.x) — CVE-2026-59870 fix not backported

GHSA-5p4m-2wfm-xmqj patch: ≥ 4.3.1
Moderate 2026-08-06
statamic/cmscomposer

Statamic: Stored Cross-Site Scripting in Automagic Form Notification Email Template

Moderate 2026-08-06
statamic/cmscomposer

Statamic: Missing file upload validation on frontend forms allows uploading disallowed file types

Moderate 2026-08-06
statamic/cmscomposer

Statamic: Missing authorization on navigation endpoint allows disclosure of restricted entries

Moderate 2026-08-06
statamic/cmscomposer

Statamic: Unsafe method invocation via Antlers template resolution allows data destruction

High 2026-08-06
statamic/cmscomposer

Statamic: Account takeover via OAuth email matching without email-verification check

Moderate 2026-08-06
statamic/cmscomposer

Statamic: Missing authorization on Control Panel endpoint allows disclosure of user existence

High 2026-08-05
nuxtnpm

Nuxt: Unauthenticated CPU exhaustion parsing and hashing the Nuxt island endpoint body before hash validation

High 2026-08-05
nuxtnpm

Nuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island Props

Critical 2026-08-05
@nuxt/devtoolsnpm

Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host

High 2026-08-05
nuxtnpm

Nuxt runtime payload cache discloses another user's SSR data across users and to unauthenticated clients

High 2026-08-05
nuxtnpm

Nuxt route rules silently dropped for mixed-case paths, bypassing appMiddleware auth gates (incomplete fix for CVE-2026-53721)

High 2026-08-05
nuxtnpm

Nuxt: Unauthenticated out-of-memory crash via unbounded v-for expansion in island rendering

High 2026-08-05
electronnpm

Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path

Moderate 2026-08-05
electronnpm

Electron: window.open features string controls some window options considered privileged

Moderate 2026-08-05
electronnpm

Electron: ProtocolResponse.url reuses the default session cache instead of the registering session

High 2026-08-05
electronnpm

Electron: Custom protocol with supportFetchAPI but not corsEnabled allows cross-origin reads

Moderate 2026-08-05
electronnpm

Electron: Permission Check Handler Receives Main Frame Origin Instead of Requesting Iframe Origin

High 2026-08-01
guzzlehttp/guzzlecomposer

Duplicate Advisory: Guzzle: Host-only cookie scope is not preserved

High 2026-08-01
guzzlehttp/guzzlecomposer

Duplicate Advisory: Guzzle: URI fragments disclosed in redirect Referer headers

Moderate 2026-08-01
guzzlehttp/guzzlecomposer

Duplicate Advisory: Guzzle: Unbounded response cookies risk denial of service

Moderate 2026-08-01
guzzlehttp/guzzlecomposer

Duplicate Advisory: Guzzle: Proxy-Authorization headers can be sent to origin servers

Moderate 2026-07-31
wp-graphql/wp-graphqlcomposer

WPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that leaks user existence + profile (defeats explicit anti-enumeration design)

High 2026-07-31
redaxo/sourcecomposer

Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers

High 2026-06-19
gouef/githubtoplanguagesactions

githubtoplanguages: Command Injection via Issue Title in Discord Notification Workflow

GHSA-c3xh-98xp-6qhf patch: ≥ 1.1.4
Moderate 2026-06-10
anthropics/claude-code-actionactions

Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration

Moderate 2026-05-20
shivammathur/setup-phpactions

Setup PHP: GitHub tokens configured by setup-php may be exposed through pinned affected Composer versions

GHSA-5wxr-w449-57cm patch: ≥ 2.37.1
Moderate 2026-05-20
shivammathur/setup-phpactions

Setup PHP: Command Injection in Repository-Derived PHP Version Resolution

Critical 2026-04-24
@google/gemini-cliactions

Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses

GHSA-wpqr-6v78-jr5g patch: ≥ 0.39.1
Moderate 2026-04-04
Tiryoh/actions-mkdocsactions

actions-mkdocs: Command Injection via issue title in internal GitHub Actions workflow

GHSA-6p2j-742g-835f patch: ≥ 0.25.0
Critical 2026-03-20
SHAdd0WTAka/Zen-Ai-Pentestactions

Zen-AI-Pentest has Shell Injection via untrusted issue title in ZenClaw Discord Integration workflow

Moderate 2026-03-17
step-security/harden-runneractions

Egress Policy Bypass via DNS over HTTPS (DoH) in Harden-Runner (Community Tier)

Moderate 2026-03-17
step-security/harden-runneractions

Egress Policy Bypass via DNS over TCP in Harden-Runner (Community Tier)

Moderate 2026-02-18
aquasecurity/trivy-actionactions

Trivy Action has a script injection via sourced env file in composite action

High 2026-02-09
super-linter/super-linteractions

Super-linter is vulnerable to command injection via crafted filenames in Super-linter Action

Moderate 2026-02-09
step-security/harden-runneractions

Harden-Runner: Bypassing Logging of Outbound Connections Using sendto, sendmsg, and sendmmsg in Harden-Runner (Community Tier)

Critical 2025-09-29
j178/prek-actionactions

j178/prek-action vulnerable to arbitrary code injection in composite action

GHSA-pwf7-47c3-mfhx patch: ≥ 1.0.6
Low 2025-09-04
pypa/gh-action-pypi-publishactions

PyPI publish GitHub Action vulnerable to injectable expression expansions in action steps

GHSA-vxmw-7h4f-hqxh patch: ≥ 1.13.0
Moderate 2025-08-28
lycheeverse/lychee-actionactions

lychee link checking action affected by arbitrary code injection in composite action

Critical 2025-08-13
m00nl1ght-dev/steam-workshop-deployactions

m00nl1ght-dev/steam-workshop-deploy: Exposure of Version-Control Repository to an Unauthorized Control Sphere and Insufficiently Protected Credentials

GHSA-x6gv-2rvh-qmp6 patch: ≥ 4
High 2025-07-21
RageAgainstThePixel/setup-steamcmdactions

RageAgainstThePixel/setup-steamcmd leaked authentication token in job output logs

GHSA-c5qx-p38x-qf5w patch: ≥ 1.3.0
High 2025-07-21
buildalon/setup-steamcmdactions

buildalon/setup-steamcmd leaked authentication token in job output logs

GHSA-mj96-mh85-r574 patch: ≥ 1.1.0
Critical 2025-05-28
broadinstitute/cromwellactions

Cromwell GitHub Actions Secrets exfiltration via `Issue_comment`

GHSA-phf6-hm3h-x8qp patch: ≥ 90
High 2025-04-02
canonical/get-workflow-version-actionactions

canonical/get-workflow-version-action can leak a partial GITHUB_TOKEN in exception output

High 2025-03-15
tj-actions/changed-filesactions

tj-actions changed-files through 45.0.7 allows remote attackers to discover secrets by reading actions logs.

High 2024-11-25
dawidd6/action-download-artifactactions

Artifact poisoning vulnerability in action-download-artifact v5 and earlier

GHSA-5xr6-xhww-33m4 patch: ≥ 6
Low 2024-11-18
step-security/harden-runneractions

Harden-Runner has a command injection weaknesses in `setup.ts` and `arc-runner.ts`

High 2024-09-03
actions/download-artifactactions

@actions/download-artifact has an Arbitrary File Write via artifact extraction

GHSA-cxww-7g56-2vh6 patch: ≥ 4.1.3
High 2024-08-14
ultralytics/actionsactions

GitHub Actions Script Injection in `ultralytics/actions`

GHSA-7x29-qqmq-v6qc patch: ≥ 0.0.3
Moderate 2024-02-03
rlespinasse/github-slug-actionactions

github-slug-action use of `set-env` Runner commands which are processed via stdout

GHSA-7f32-hm4h-w77q patch: ≥ 1.1.1
High 2024-01-02
tj-actions/verify-changed-filesactions

Potential Actions command injection in output filenames (GHSL-2023-275)

High 2024-01-02
tj-actions/changed-filesactions

tj-actions/changed-files has Potential Actions command injection in output filenames (GHSL-2023-271)

Critical 2023-12-05
tj-actions/branch-namesactions

tj-actions/branch-names's Improper Sanitization of Branch Name Leads to Arbitrary Code Injection

Moderate 2023-08-30
https://github.com/pytorch/pytorch/.github/actions/filter-test-configsactions

Actions expression injection in `filter-test-configs` (`GHSL-2023-181`)