豆豆友情提示:这是一个非官方 GitHub 代理镜像,主要用于网络测试或访问加速。请勿在此进行登录、注册或处理任何敏感信息。进行这些操作请务必访问官方网站 github.com。 Raw 内容也通过此代理提供。
Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

7 advisories

Loading
Flowise: Weak Default Token Hash Secret Moderate
GHSA-m7mq-85xj-9x33 was published for flowise (npm) Apr 16, 2026
kolega-ai-dev Credited to kolega-ai-dev
Flowise: Weak Default Express Session Secret Moderate
GHSA-2qqc-p94c-hxwh was published for flowise (npm) Apr 16, 2026
kolega-ai-dev Credited to kolega-ai-dev
Flowise: Weak Default JWT Secrets Moderate
GHSA-cc4f-hjpj-g9p8 was published for flowise (npm) Apr 16, 2026
kolega-ai-dev Credited to kolega-ai-dev
n8n's Source Control SSH Configuration Uses StrictHostKeyChecking=no Moderate
CVE-2026-33724 was published for n8n (npm) Mar 25, 2026
kolega-ai-dev Credited to kolega-ai-dev
Langflow is Missing Ownership Verification in API Key Deletion (IDOR) High
CVE-2026-33053 was published for langflow (pip) Mar 18, 2026
FaizanKolega Credited to FaizanKolega, kolega-ai-dev, andifilhohub, and erichare kolega-ai-dev kolega-ai-dev
andifilhohub andifilhohub erichare erichare
Flowise has Insufficient Password Salt Rounds Moderate
GHSA-x2g5-fvc2-gqvp was published for flowise (npm) Mar 5, 2026
kolega-ai-dev Credited to kolega-ai-dev
NocoDB has Blind SSRF via Unvalidated HEAD Request in uploadViaURL Functionality Moderate
CVE-2026-24767 was published for nocodb (npm) Jan 28, 2026
kolega-ai-dev Credited to kolega-ai-dev
ProTip! Advisories are also available from the GraphQL API