diff --git a/advisories/github-reviewed/2022/05/GHSA-45mx-g85m-wwm3/GHSA-45mx-g85m-wwm3.json b/advisories/github-reviewed/2022/05/GHSA-45mx-g85m-wwm3/GHSA-45mx-g85m-wwm3.json
new file mode 100644
index 00000000000..9fa8d7198b7
--- /dev/null
+++ b/advisories/github-reviewed/2022/05/GHSA-45mx-g85m-wwm3/GHSA-45mx-g85m-wwm3.json
@@ -0,0 +1,61 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-45mx-g85m-wwm3",
+ "modified": "2024-04-22T23:22:17Z",
+ "published": "2022-05-24T19:10:22Z",
+ "aliases": [
+ "CVE-2021-38148"
+ ],
+ "summary": "Obsidian does not require user confirmation for non-http/https URLs.",
+ "details": "Obsidian before 0.12.12 does not require user confirmation for non-http/https URLs.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+ {
+ "package": {
+ "ecosystem": "npm",
+ "name": "obsidian"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "0"
+ },
+ {
+ "fixed": "0.12.12"
+ }
+ ]
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-38148"
+ },
+ {
+ "type": "PACKAGE",
+ "url": "https://github.com/obsidianmd/obsidian-api"
+ },
+ {
+ "type": "WEB",
+ "url": "https://web.archive.org/web/20210807011714/https://forum.obsidian.md/t/obsidian-release-v0-12-12/21564"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-285"
+ ],
+ "severity": "CRITICAL",
+ "github_reviewed": true,
+ "github_reviewed_at": "2024-04-22T23:22:17Z",
+ "nvd_published_at": "2021-08-07T03:15:00Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2022/05/GHSA-h6xg-rg33-9mf4/GHSA-h6xg-rg33-9mf4.json b/advisories/github-reviewed/2022/05/GHSA-h6xg-rg33-9mf4/GHSA-h6xg-rg33-9mf4.json
new file mode 100644
index 00000000000..e1fab8e2498
--- /dev/null
+++ b/advisories/github-reviewed/2022/05/GHSA-h6xg-rg33-9mf4/GHSA-h6xg-rg33-9mf4.json
@@ -0,0 +1,65 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-h6xg-rg33-9mf4",
+ "modified": "2024-04-22T23:22:36Z",
+ "published": "2022-05-24T19:03:10Z",
+ "aliases": [
+ "CVE-2021-25944"
+ ],
+ "summary": "deep-defaults vulnerable to prototype pollution",
+ "details": "### Overview\nPrototype pollution vulnerability in 'deep-defaults' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution.\n\n### Details\nThe NPM module `deep-defaults` can be abused by Prototype Pollution vulnerability since the function `_deepDefaults()` does not check for the type of object before assigning value to the property. Due to this flaw an attacker could create a non-existent property or able to manipulate the property which leads to Denial of Service or potentially Remote code execution.\n\n### PoC\nThe `_deepDefaults ()` function accepts `dest`, `src` as arguments. Due to the absence of validation on the values passed into the `src` argument, an attacker can supply a malicious value by adjusting the value to include the `__proto__` property. Since there is no validation before assigning the property to check whether the assigned argument is the Object's own property or not, the property `polluted` will be directly be assigned to the new object thereby polluting the Object prototype. Later in the code, if there is a check to validate `polluted` the valued would be substituted as \"Yes! Its Polluted\" as it had been polluted.\n\n```js\nvar deepDefaults = require(\"deep-defaults\")\nvar malicious_payload = '{\"__proto__\":{\"polluted\":\"Yes! Its Polluted\"}}';\nvar obj ={};\nconsole.log(\"Before : \" + {}.polluted);\ndeepDefaults(obj, JSON.parse(malicious_payload));\nconsole.log(\"After : \" + {}.polluted);\n```",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+ {
+ "package": {
+ "ecosystem": "npm",
+ "name": "deep-defaults"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "1.0.0"
+ },
+ {
+ "last_affected": "1.0.5"
+ }
+ ]
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-25944"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/d5/deep-defaults"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/d5/deep-defaults/blob/321d0e2231aa807d54e7f95d75c22048a806923f/lib/index.js#L16"
+ },
+ {
+ "type": "WEB",
+ "url": "https://web.archive.org/web/20210525211925/https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25944"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-1321"
+ ],
+ "severity": "CRITICAL",
+ "github_reviewed": true,
+ "github_reviewed_at": "2024-04-22T23:22:36Z",
+ "nvd_published_at": "2021-05-25T19:15:00Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2022/05/GHSA-hwgp-c653-6684/GHSA-hwgp-c653-6684.json b/advisories/github-reviewed/2022/05/GHSA-hwgp-c653-6684/GHSA-hwgp-c653-6684.json
new file mode 100644
index 00000000000..86481d86154
--- /dev/null
+++ b/advisories/github-reviewed/2022/05/GHSA-hwgp-c653-6684/GHSA-hwgp-c653-6684.json
@@ -0,0 +1,57 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-hwgp-c653-6684",
+ "modified": "2024-04-22T23:23:17Z",
+ "published": "2022-05-24T17:02:45Z",
+ "aliases": [
+ "CVE-2019-19596"
+ ],
+ "summary": "GitBook allows Cross-site Scripting via a local .md file.",
+ "details": "GitBook through 2.6.9 allows Cross-site Scripting via javascript inclusion in a local .md file.",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"
+ }
+ ],
+ "affected": [
+ {
+ "package": {
+ "ecosystem": "npm",
+ "name": "gitbook"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "0"
+ },
+ {
+ "last_affected": "2.6.9"
+ }
+ ]
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-19596"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/ianxtianxt/gitbook-xss"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-79"
+ ],
+ "severity": "MODERATE",
+ "github_reviewed": true,
+ "github_reviewed_at": "2024-04-22T23:23:17Z",
+ "nvd_published_at": "2019-12-05T03:15:00Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/github-reviewed/2022/07/GHSA-5gxc-fxcr-9326/GHSA-5gxc-fxcr-9326.json b/advisories/github-reviewed/2022/07/GHSA-5gxc-fxcr-9326/GHSA-5gxc-fxcr-9326.json
new file mode 100644
index 00000000000..7ed6f6873cf
--- /dev/null
+++ b/advisories/github-reviewed/2022/07/GHSA-5gxc-fxcr-9326/GHSA-5gxc-fxcr-9326.json
@@ -0,0 +1,73 @@
+{
+ "schema_version": "1.4.0",
+ "id": "GHSA-5gxc-fxcr-9326",
+ "modified": "2024-04-22T23:21:54Z",
+ "published": "2022-07-23T00:00:16Z",
+ "aliases": [
+ "CVE-2022-25759"
+ ],
+ "summary": "convert-svg-core vulnerable to remote code injection",
+ "details": "The package convert-svg-core before 0.6.2 is vulnerable to Remote Code Injection via sending an SVG file containing the payload in an `onload` attribute. Puppeteer/Chromium (used by convert-svg-core) will execute any code within that tag, including malicious code.\n\n### PoC\n\n**Payload**\n\n```html\n\n```\nwhere the `id` attribute is the base 64-encoded form of \n\n```js\ndocument.write('');\n```\n\n\n**Attack**\n\n```js\nconst { convert } = require('convert-svg-to-png');\nconst express = require('express');\nconst fileSvg = `[[[payload]]]`;\n// YWxlcnQoMSk=\n// function newContent(){document.open(),document.write('data'),document.close()}\nconst app = express();\napp.get('/poc', async (req, res)=>{\n try {\n const png = await convert(fileSvg);\n res.set('Content-Type', 'image/png');\n res.send(png);\n } catch (e) {\n console.log(e);\n res.send(\"\");\n }\n});\napp.listen(3000, ()=>{\n console.log('started');\n});\n```",
+ "severity": [
+ {
+ "type": "CVSS_V3",
+ "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
+ }
+ ],
+ "affected": [
+ {
+ "package": {
+ "ecosystem": "npm",
+ "name": "convert-svg-core"
+ },
+ "ranges": [
+ {
+ "type": "ECOSYSTEM",
+ "events": [
+ {
+ "introduced": "0"
+ },
+ {
+ "fixed": "0.6.2"
+ }
+ ]
+ }
+ ]
+ }
+ ],
+ "references": [
+ {
+ "type": "ADVISORY",
+ "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-25759"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/neocotic/convert-svg/issues/81"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/neocotic/convert-svg/pull/82"
+ },
+ {
+ "type": "WEB",
+ "url": "https://github.com/neocotic/convert-svg/commit/7e6031ac7427cf82cf312cb4a25040f2e6efe7a5"
+ },
+ {
+ "type": "PACKAGE",
+ "url": "https://github.com/neocotic/convert-svg"
+ },
+ {
+ "type": "WEB",
+ "url": "https://security.snyk.io/vuln/SNYK-JS-CONVERTSVGCORE-2849633"
+ }
+ ],
+ "database_specific": {
+ "cwe_ids": [
+ "CWE-94"
+ ],
+ "severity": "CRITICAL",
+ "github_reviewed": true,
+ "github_reviewed_at": "2024-04-22T23:21:54Z",
+ "nvd_published_at": "2022-07-22T20:15:00Z"
+ }
+}
\ No newline at end of file
diff --git a/advisories/unreviewed/2022/05/GHSA-45mx-g85m-wwm3/GHSA-45mx-g85m-wwm3.json b/advisories/unreviewed/2022/05/GHSA-45mx-g85m-wwm3/GHSA-45mx-g85m-wwm3.json
deleted file mode 100644
index b34fbd8a06a..00000000000
--- a/advisories/unreviewed/2022/05/GHSA-45mx-g85m-wwm3/GHSA-45mx-g85m-wwm3.json
+++ /dev/null
@@ -1,35 +0,0 @@
-{
- "schema_version": "1.4.0",
- "id": "GHSA-45mx-g85m-wwm3",
- "modified": "2022-05-24T19:10:22Z",
- "published": "2022-05-24T19:10:22Z",
- "aliases": [
- "CVE-2021-38148"
- ],
- "details": "Obsidian before 0.12.12 does not require user confirmation for non-http/https URLs.",
- "severity": [
-
- ],
- "affected": [
-
- ],
- "references": [
- {
- "type": "ADVISORY",
- "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-38148"
- },
- {
- "type": "WEB",
- "url": "https://forum.obsidian.md/t/obsidian-release-v0-12-12/21564"
- }
- ],
- "database_specific": {
- "cwe_ids": [
-
- ],
- "severity": "CRITICAL",
- "github_reviewed": false,
- "github_reviewed_at": null,
- "nvd_published_at": "2021-08-07T03:15:00Z"
- }
-}
\ No newline at end of file
diff --git a/advisories/unreviewed/2022/05/GHSA-h6xg-rg33-9mf4/GHSA-h6xg-rg33-9mf4.json b/advisories/unreviewed/2022/05/GHSA-h6xg-rg33-9mf4/GHSA-h6xg-rg33-9mf4.json
deleted file mode 100644
index 662877ee3ca..00000000000
--- a/advisories/unreviewed/2022/05/GHSA-h6xg-rg33-9mf4/GHSA-h6xg-rg33-9mf4.json
+++ /dev/null
@@ -1,38 +0,0 @@
-{
- "schema_version": "1.4.0",
- "id": "GHSA-h6xg-rg33-9mf4",
- "modified": "2023-08-08T15:31:18Z",
- "published": "2022-05-24T19:03:10Z",
- "aliases": [
- "CVE-2021-25944"
- ],
- "details": "Prototype pollution vulnerability in 'deep-defaults' versions 1.0.0 through 1.0.5 allows attacker to cause a denial of service and may lead to remote code execution.",
- "severity": [
- {
- "type": "CVSS_V3",
- "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
- }
- ],
- "affected": [
-
- ],
- "references": [
- {
- "type": "ADVISORY",
- "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-25944"
- },
- {
- "type": "WEB",
- "url": "https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25944"
- }
- ],
- "database_specific": {
- "cwe_ids": [
-
- ],
- "severity": "CRITICAL",
- "github_reviewed": false,
- "github_reviewed_at": null,
- "nvd_published_at": "2021-05-25T19:15:00Z"
- }
-}
\ No newline at end of file
diff --git a/advisories/unreviewed/2022/05/GHSA-hwgp-c653-6684/GHSA-hwgp-c653-6684.json b/advisories/unreviewed/2022/05/GHSA-hwgp-c653-6684/GHSA-hwgp-c653-6684.json
deleted file mode 100644
index 05c5d9b705a..00000000000
--- a/advisories/unreviewed/2022/05/GHSA-hwgp-c653-6684/GHSA-hwgp-c653-6684.json
+++ /dev/null
@@ -1,35 +0,0 @@
-{
- "schema_version": "1.4.0",
- "id": "GHSA-hwgp-c653-6684",
- "modified": "2022-05-24T17:02:45Z",
- "published": "2022-05-24T17:02:45Z",
- "aliases": [
- "CVE-2019-19596"
- ],
- "details": "GitBook through 2.6.9 allows XSS via a local .md file.",
- "severity": [
-
- ],
- "affected": [
-
- ],
- "references": [
- {
- "type": "ADVISORY",
- "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-19596"
- },
- {
- "type": "WEB",
- "url": "https://github.com/ianxtianxt/gitbook-xss"
- }
- ],
- "database_specific": {
- "cwe_ids": [
-
- ],
- "severity": "LOW",
- "github_reviewed": false,
- "github_reviewed_at": null,
- "nvd_published_at": "2019-12-05T03:15:00Z"
- }
-}
\ No newline at end of file
diff --git a/advisories/unreviewed/2022/07/GHSA-5gxc-fxcr-9326/GHSA-5gxc-fxcr-9326.json b/advisories/unreviewed/2022/07/GHSA-5gxc-fxcr-9326/GHSA-5gxc-fxcr-9326.json
deleted file mode 100644
index a629b8904b0..00000000000
--- a/advisories/unreviewed/2022/07/GHSA-5gxc-fxcr-9326/GHSA-5gxc-fxcr-9326.json
+++ /dev/null
@@ -1,50 +0,0 @@
-{
- "schema_version": "1.4.0",
- "id": "GHSA-5gxc-fxcr-9326",
- "modified": "2022-07-26T00:01:04Z",
- "published": "2022-07-23T00:00:16Z",
- "aliases": [
- "CVE-2022-25759"
- ],
- "details": "The package convert-svg-core before 0.6.2 are vulnerable to Remote Code Injection via sending an SVG file containing the payload.",
- "severity": [
- {
- "type": "CVSS_V3",
- "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
- }
- ],
- "affected": [
-
- ],
- "references": [
- {
- "type": "ADVISORY",
- "url": "https://nvd.nist.gov/vuln/detail/CVE-2022-25759"
- },
- {
- "type": "WEB",
- "url": "https://github.com/neocotic/convert-svg/issues/81"
- },
- {
- "type": "WEB",
- "url": "https://github.com/neocotic/convert-svg/pull/82"
- },
- {
- "type": "WEB",
- "url": "https://github.com/neocotic/convert-svg/commit/7e6031ac7427cf82cf312cb4a25040f2e6efe7a5"
- },
- {
- "type": "WEB",
- "url": "https://security.snyk.io/vuln/SNYK-JS-CONVERTSVGCORE-2849633"
- }
- ],
- "database_specific": {
- "cwe_ids": [
- "CWE-94"
- ],
- "severity": "CRITICAL",
- "github_reviewed": false,
- "github_reviewed_at": null,
- "nvd_published_at": "2022-07-22T20:15:00Z"
- }
-}
\ No newline at end of file