$ gh advisory list --reviewed

Security advisories

// github advisory database · npm · composer · actions — aggiornato 2026-09-14 12:05 UTC

High 2026-09-11
@mockoon/commons-servernpm

@Mockoon/commons-server: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft

Moderate 2026-09-11
@mockoon/commons-servernpm

@Mockoon/commons-server: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)

High 2026-09-11
shopper/frameworkcomposer

Shopper: Missing authorization on product removal actions in CollectionProducts component

Moderate 2026-09-11
shopper/frameworkcomposer

Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)

High 2026-09-11
shopper/frameworkcomposer

Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component

High 2026-09-11
shopper/frameworkcomposer

Shopper: privilege escalation via improper Livewire admin component authorization

Moderate 2026-09-11
shopper/frameworkcomposer

Shopping privilege escalation through missing authorization in Settings components

Moderate 2026-09-11
shopper/frameworkcomposer

Shopper: Negative discount values accepted and propagated through order calculation pipeline

High 2026-09-11
shopper/frameworkcomposer

Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers

High 2026-09-10
@jhb.software/payload-alt-text-pluginnpm

@jhb.software/payload-alt-text-plugin: Alt Text Endpoint Authorization Bypass via Payload Local API `overrideAccess` Omission

Moderate 2026-09-10
n8nnpm

n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read

Moderate 2026-09-10
n8nnpm

n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints

Moderate 2026-09-10
n8nnpm

n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check

Moderate 2026-09-10
n8nnpm

n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open

Moderate 2026-09-10
n8nnpm

n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers

Moderate 2026-09-10
n8nnpm

n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter

High 2026-09-10
n8nnpm

n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution

High 2026-09-10
@angular/platform-servernpm

Angular: SSR XSS via Unescaped <template> Content Across DocumentFragment Boundaries in Fallback Raw-Content Elements

High 2026-09-10
@angular/platform-servernpm

Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSR

Moderate 2026-09-10
@angular/commonnpm

Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent`

Moderate 2026-09-10
@angular/corenpm

Angular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compiler

High 2026-09-10
pimcore/pimcorecomposer

Pimcore: SQL Injection in Custom Reports via Malicious Report Configuration

High 2026-09-10
n8nnpm

n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node

High 2026-09-10
n8nnpm

n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path

High 2026-09-10
n8nnpm

n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint

High 2026-09-10
n8nnpm

n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution

High 2026-09-10
@eigenpal/docx-editor-corenpm

@eigenpal/docx-editor-react: CSS injection and print-time XSS via unescaped embedded font-family name

GHSA-x7m8-jrm8-hpvx patch: ≥ 1.8.3
High 2026-09-09
functype-mcp-servernpm

functype-mcp-server: MCP `set_functype_version` Package Alias RCE via Unsanitized pnpm install + Dynamic Import

High 2026-09-09
@yeger/turbo-graphnpm

@yeger/turbo-graph: Unauthenticated Network-Exposed Task Execution via /api/run

Moderate 2026-09-08
nodemailernpm

Nodemailer: IDN/Punycode domain allow-list bypass leads to email delivery to an attacker-controlled domain

GHSA-wmmp-3585-3rmp patch: ≥ 9.1.0
High 2026-09-08
nodemailernpm

Nodemailer: Quadratic (O(n²)) time complexity in addressparser allows remote denial of service via a crafted address list

GHSA-2x7j-588g-ccc2 patch: ≥ 9.1.0
Moderate 2026-09-08
nodemailernpm

Nodemailer: Recipient-domain validation bypass via RFC 5322 comment mis-parsing leads to email delivery to an attacker-controlled domain

GHSA-cc9r-2j5m-2m83 patch: ≥ 9.1.0
High 2026-09-08
@typespec/openapi3npm

OpenAPI3 version value escapes `emitterOutputDir` and overwrites YAML/JSON outside the output tree

Critical 2026-09-08
astronpm

Astro: Remote code execution through AVIF image optimization

GHSA-26w7-cxv4-gfx2 patch: ≥ 7.2.8
Moderate 2026-09-08
astronpm

Astro: Authorization bypass from missing path-segment boundary check when stripping the configured base

High 2026-09-08
composer/composercomposer

Composer arbitrary command execution via a malicious package's Perforce source URL

High 2026-09-08
sharpnpm

sharp: Vulnerabilities in libheif: GHSA-g89c-p67h-r497 and GHSA-2jg2-4ch7-h545

GHSA-rgj7-g3m4-5g8c patch: ≥ 0.35.4
Moderate 2026-09-08
phpseclibcomposer

phpseclib — non-constant-time X25519 scalar multiplication permits full private-key recovery

High 2026-09-08
@tiptap/corenpm

Tiptap: Quadratic ReDoS in block and inline Markdown attribute parsing

GHSA-j95f-988m-3j2f patch: ≥ 3.30.5
Moderate 2026-09-08
hononpm

Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory

Critical 2026-09-08
predis/prediscomposer

Predis: Redis command injection and denial of service via CRLF smuggling in pipelined commands on aggregate connections

Critical 2026-09-08
cakephp/cakephpcomposer

CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with PostgresDriver

High 2026-09-08
maatwebsite/excelcomposer

Laravel Excel writes exports outside the configured filesystem disk when given a caller-controlled path

High 2026-09-02
getgrav/gravcomposer

Grav: 2FA Bypass via 'login.regenerate2FASecret' - Secret Rotation During Pending Challenge

Moderate 2026-09-02
getgrav/gravcomposer

Grav: Twig sandbox config exfiltration via grav.offsetGet + dump filter (CVE-2026-44738 bypass)

Moderate 2026-09-02
getkirby/cmscomposer

Kirby: Access to image files outside of the site root via path traversal in the media handling

High 2026-09-02
getgrav/gravcomposer

Grav: Remote code execution via unrestricted callable in Blueprint::dynamicData()

High 2026-09-02
easycorp/easyadmin-bundlecomposer

EasyAdmin custom-action dispatcher bypasses access_control on other routes

Moderate 2026-09-02
livewire/livewirecomposer

Livewire DOM-based cross-site scripting during client-side state handling

High 2026-09-02
Studio-42/elFindercomposer

elFinder: ZIP extraction bypasses uploadDeny MIME filter allowing PHP file upload (RCE)

Moderate 2026-09-02
studio-42/elfindercomposer

elFinder: CSRF in netmount allows forced FTP mounts and server-side FTP connections

Moderate 2026-09-01
filament/filamentcomposer

Filament: Multi-factor authentication (app) codes can still be used after a newer code has been used

Low 2026-09-01
filament/filamentcomposer

Filament: Password validity disclosure for accounts denied panel access on login page

High 2026-09-01
filament/filamentcomposer

Filament: Multi-factor authentication (app) can be bypassed when recovery codes are enabled

High 2026-09-01
league/commonmarkcomposer

league/commonmark: Denial of service via distinctly-named attributes in the Attributes extension

GHSA-8rr7-cvq3-gmfh patch: ≥ 2.10.0
High 2026-09-01
league/commonmarkcomposer

league/commonmark: Denial of service in the SmartPunct and Attributes extensions

GHSA-jjv6-8j6v-6j52 patch: ≥ 2.9.1
High 2026-09-01
league/commonmarkcomposer

league/commonmark XSS: `on*` event-handler filter in `AttributesExtension` bypassed with a U+000C form feed

GHSA-f8fg-pg57-v4j8 patch: ≥ 2.9.1
High 2026-09-01
league/commonmarkcomposer

league/commonmark: Denial of service via crafted code fences, reference links, and emphasis delimiters

GHSA-j8pm-gj4c-rq4x patch: ≥ 2.9.1
High 2026-08-31
getkirby/cmscomposer

Kirby: File upload permissions are not checked during processing of chunk data

High 2026-08-31
getkirby/cmscomposer

Kirby: Access to image files and limited access to JSON files outside of the site root via path traversal in the media handling

High 2026-08-31
studio-42/elfindercomposer

elFinder: SSRF protection bypass via DNS rebinding in the `fsock_get_contents()` fallback

Low 2026-08-28
privatebin/privatebincomposer

PrivateBin has reflected JSON injection in backend responses via unescaped REQUEST_URI

Moderate 2026-08-28
privatebin/privatebincomposer

PrivateBin has stored Cross-Side-Scripting (XSS) vulnerability in attachment download link via dangerous MIME types with required user-interaction

Critical 2026-08-28
pimcore/pimcorecomposer

Pimcore Vulnerable to Remote Code Execution via DataObject Class-Definition Field Name

Critical 2026-08-28
pimcore/pimcorecomposer

Pimcore Hotspotimage getDataFromResource() unrestricted Serialize::unserialize over object-store column (PHP Object Injection, CWE-502)

High 2026-08-28
pimcore/studio-backend-bundlecomposer

Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation

High 2026-08-28
pimcore/studio-backend-bundlecomposer

Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes

High 2026-08-28
pimcore/studio-backend-bundlecomposer

Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass

Critical 2026-08-17
wktk/conflibotactions

conflibot vulnerable to command injection via crafted pull request branch names under pull_request_target

High 2026-06-19
gouef/githubtoplanguagesactions

githubtoplanguages: Command Injection via Issue Title in Discord Notification Workflow

GHSA-c3xh-98xp-6qhf patch: ≥ 1.1.4
Moderate 2026-06-10
anthropics/claude-code-actionactions

Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration

Moderate 2026-05-20
shivammathur/setup-phpactions

Setup PHP: GitHub tokens configured by setup-php may be exposed through pinned affected Composer versions

GHSA-5wxr-w449-57cm patch: ≥ 2.37.1
Moderate 2026-05-20
shivammathur/setup-phpactions

Setup PHP: Command Injection in Repository-Derived PHP Version Resolution

Critical 2026-04-24
@google/gemini-cliactions

Gemini CLI: Remote Code Execution via workspace trust and tool allowlisting bypasses

GHSA-wpqr-6v78-jr5g patch: ≥ 0.39.1
Moderate 2026-04-04
Tiryoh/actions-mkdocsactions

actions-mkdocs: Command Injection via issue title in internal GitHub Actions workflow

GHSA-6p2j-742g-835f patch: ≥ 0.25.0
Critical 2026-03-20
SHAdd0WTAka/Zen-Ai-Pentestactions

Zen-AI-Pentest has Shell Injection via untrusted issue title in ZenClaw Discord Integration workflow

Moderate 2026-03-17
step-security/harden-runneractions

Egress Policy Bypass via DNS over HTTPS (DoH) in Harden-Runner (Community Tier)

Moderate 2026-03-17
step-security/harden-runneractions

Egress Policy Bypass via DNS over TCP in Harden-Runner (Community Tier)

Moderate 2026-02-18
aquasecurity/trivy-actionactions

Trivy Action has a script injection via sourced env file in composite action

High 2026-02-09
super-linter/super-linteractions

Super-linter is vulnerable to command injection via crafted filenames in Super-linter Action

Moderate 2026-02-09
step-security/harden-runneractions

Harden-Runner: Bypassing Logging of Outbound Connections Using sendto, sendmsg, and sendmmsg in Harden-Runner (Community Tier)

Critical 2025-09-29
j178/prek-actionactions

j178/prek-action vulnerable to arbitrary code injection in composite action

GHSA-pwf7-47c3-mfhx patch: ≥ 1.0.6
Low 2025-09-04
pypa/gh-action-pypi-publishactions

PyPI publish GitHub Action vulnerable to injectable expression expansions in action steps

GHSA-vxmw-7h4f-hqxh patch: ≥ 1.13.0
Moderate 2025-08-28
lycheeverse/lychee-actionactions

lychee link checking action affected by arbitrary code injection in composite action

Critical 2025-08-13
m00nl1ght-dev/steam-workshop-deployactions

m00nl1ght-dev/steam-workshop-deploy: Exposure of Version-Control Repository to an Unauthorized Control Sphere and Insufficiently Protected Credentials

GHSA-x6gv-2rvh-qmp6 patch: ≥ 4
High 2025-07-21
RageAgainstThePixel/setup-steamcmdactions

RageAgainstThePixel/setup-steamcmd leaked authentication token in job output logs

GHSA-c5qx-p38x-qf5w patch: ≥ 1.3.0
High 2025-07-21
buildalon/setup-steamcmdactions

buildalon/setup-steamcmd leaked authentication token in job output logs

GHSA-mj96-mh85-r574 patch: ≥ 1.1.0
Critical 2025-05-28
broadinstitute/cromwellactions

Cromwell GitHub Actions Secrets exfiltration via `Issue_comment`

GHSA-phf6-hm3h-x8qp patch: ≥ 90
High 2025-04-02
canonical/get-workflow-version-actionactions

canonical/get-workflow-version-action can leak a partial GITHUB_TOKEN in exception output

High 2025-03-15
tj-actions/changed-filesactions

tj-actions changed-files through 45.0.7 allows remote attackers to discover secrets by reading actions logs.

High 2024-11-25
dawidd6/action-download-artifactactions

Artifact poisoning vulnerability in action-download-artifact v5 and earlier

GHSA-5xr6-xhww-33m4 patch: ≥ 6
Low 2024-11-18
step-security/harden-runneractions

Harden-Runner has a command injection weaknesses in `setup.ts` and `arc-runner.ts`

High 2024-09-03
actions/download-artifactactions

@actions/download-artifact has an Arbitrary File Write via artifact extraction

GHSA-cxww-7g56-2vh6 patch: ≥ 4.1.3
High 2024-08-14
ultralytics/actionsactions

GitHub Actions Script Injection in `ultralytics/actions`

GHSA-7x29-qqmq-v6qc patch: ≥ 0.0.3
Moderate 2024-02-03
rlespinasse/github-slug-actionactions

github-slug-action use of `set-env` Runner commands which are processed via stdout

GHSA-7f32-hm4h-w77q patch: ≥ 1.1.1
High 2024-01-02
tj-actions/verify-changed-filesactions

Potential Actions command injection in output filenames (GHSL-2023-275)

High 2024-01-02
tj-actions/changed-filesactions

tj-actions/changed-files has Potential Actions command injection in output filenames (GHSL-2023-271)

Critical 2023-12-05
tj-actions/branch-namesactions

tj-actions/branch-names's Improper Sanitization of Branch Name Leads to Arbitrary Code Injection

Moderate 2023-08-30
https://github.com/pytorch/pytorch/.github/actions/filter-test-configsactions

Actions expression injection in `filter-test-configs` (`GHSL-2023-181`)