Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

6 advisories

Loading
MCP Python SDK: WebSocket server transport does not support Host/Origin validation High
CVE-2026-59950 was published for mcp (pip) Jul 16, 2026
nitish-yaddala Credited to nitish-yaddala, Nadav0077, dodge1218, gistrec, and u-ktdi Nadav0077 Nadav0077
dodge1218 dodge1218 gistrec gistrec u-ktdi u-ktdi
Langroid: handle_message() executes user-supplied tool JSON without sender verification High
CVE-2026-54771 was published for langroid (pip) Jul 6, 2026
u-ktdi Credited to u-ktdi
Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft High
CVE-2026-52805 was published for gogs.io/gogs (Go) Jun 23, 2026
u-ktdi Credited to u-ktdi
u-ktdi Credited to u-ktdi
n8n-MCP: Workflow telemetry sanitizer could retain partial values from URL-shaped node parameters Moderate
CVE-2026-45582 was published for n8n-mcp (npm) May 18, 2026
u-ktdi Credited to u-ktdi
u-ktdi Credited to u-ktdi, dewankpant, shrutilohani, Moaaz-0x, yardenporat353, pucagit, nick-hollon-lc, and localhost-detect dewankpant dewankpant
shrutilohani shrutilohani Moaaz-0x Moaaz-0x yardenporat353 yardenporat353 pucagit pucagit nick-hollon-lc nick-hollon-lc localhost-detect localhost-detect
ProTip! Advisories are also available from the GraphQL API