Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4 advisories

Loading
Trigger.dev: V1 coordinator default-secret unauth Socket.IO Critical
GHSA-gg6r-gp4c-89hp was published for trigger.dev (npm) Oct 2, 2026
lissy93 Credited to lissy93
NotAFlightRisk Credited to NotAFlightRisk and lissy93 lissy93 lissy93
js-yaml: Exponential parsing time in flow collections leads to denial of service High
CVE-2026-73643 was published for js-yaml (npm) Jul 24, 2026
lissy93 Credited to lissy93
Express XSS Sanitizer: allowedTags/allowedAttributes bypass leads to permissive sanitization (XSS risk) High
CVE-2026-33979 was published for express-xss-sanitizer (npm) Mar 27, 2026
lissy93 Credited to lissy93
ProTip! Advisories are also available from the GraphQL API