Security advisories I reported that are published, fixed, and credited in the GitHub Advisory Database. Each page carries the full root cause analysis, the vulnerable code, reproduction steps, and the fix, exactly as published in the advisory.
Only published advisories appear here. Reports still in coordinated disclosure are not listed, named, or hinted at until the maintainer ships a fix and the advisory goes live.
| Advisory | Project | CVSS | Class | Writeup |
|---|---|---|---|---|
| GHSA-pqxw-g93w-hj9x | trigger.dev |
9.0 High | CWE-653 | read |
| CVE-2026-57516 | ray |
8.8 High | CWE-94 | read |
| CVE-2026-45675 | open-webui |
8.1 High | CWE-269 | read |
| GHSA-jc26-22qp-cgqj | trigger.dev |
7.9 High | CWE-306 | read |
| GHSA-3c52-v5v2-3r56 | budibase |
7.7 High | CWE-918 | read |
| CVE-2026-59714 | open-webui |
7.1 High | CWE-862 | read |
| CVE-2026-53577 | kestra |
6.5 Medium | CWE-863 | read |
| CVE-2026-63342 | hatchet |
6.3 Medium | CWE-863 | read |
| GHSA-59h8-w5q6-mfmp | trigger.dev |
5.3 Medium | CWE-306 | read |
| CVE-2026-73301 | @budibase/server |
4.3 Medium | CWE-862 | read |
| CVE-2026-59715 | open-webui |
3.1 Low | CWE-306 | read |
Reported by @sfwani. Rebuilt with python scripts/build.py.