Every advisory below is published, fixed and credited. Reports still in coordinated disclosure are not listed, named or hinted at until the maintainer ships a fix.
—
Eleven, published, fixed and credited. Descending by CVSS v3.1 base score. Summaries are keyed to the NR column and set below the table.
| NR | Advisory | Package | CVSS | Severity | Weakness | CWE | Base vector | Published | |||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| AV | AC | PR | UI | S | C | I | A | ||||||||
| 01 | CVE-2026-57516 | ray | 8.8 | High | Code injection | 94 | N | L | N | R | U | H | H | H | 2026-07-24 |
| 02 | CVE-2026-45675 | open-webui | 8.1 | High | Privilege escalation | 269 | N | H | N | N | U | H | H | H | 2026-05-14 |
| 03 | GHSA-pqxw-g93w-hj9x | trigger.dev | 8.1 | High | Improper isolation | 653 | N | H | N | N | U | H | H | H | 2026-10-02 |
| 04 | GHSA-jc26-22qp-cgqj | trigger.dev | 7.9 | High | Missing authentication | 306 | A | H | L | N | C | H | H | L | 2026-09-14 |
| 05 | GHSA-3c52-v5v2-3r56 | budibase | 7.7 | High | Server side request forgery | 918 | N | L | L | N | C | H | N | N | 2026-09-17 |
| 06 | CVE-2026-59714 | open-webui | 7.1 | High | Missing authorization | 862 | N | L | L | N | U | N | H | L | 2026-07-24 |
| 07 | GHSA-8p4j-2mm9-rh78 | Tracecat | 6.5 | Medium | Server side request forgery | 918 | N | L | L | N | U | H | N | N | 2026-09-20 |
| 08 | CVE-2026-53577 | io.kestra:kestra | 6.5 | Medium | Incorrect authorization | 863 | N | L | L | N | U | H | N | N | 2026-06-03 |
| 09 | CVE-2026-63342 | github.com/ | 6.3 | Medium | Incorrect authorization | 863 | N | H | L | N | C | H | N | N | 2026-09-22 |
| 10 | GHSA-59h8-w5q6-mfmp | trigger.dev | 5.3 | Medium | Missing authentication | 306 | N | L | N | N | U | N | L | N | 2026-10-02 |
| 11 | CVE-2026-73301 | @budibase/server | 4.3 | Medium | Missing authorization | 862 | N | L | L | N | U | L | N | N | 2026-07-24 |
| 12 | CVE-2026-59715 | open-webui | 3.1 | Low | Missing authentication | 306 | N | H | L | N | U | N | L | N | 2026-07-24 |
Every entry regenerates daily from the GitHub Advisory Database, so this list only ever shows work that is published, fixed and credited.