Security: serverpod/serverpod
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Google sign-in accepts an access token minted for a different OAuth client, allowing account takeoverGHSA-3hrq-4vpw-386w published
Aug 14, 2026 by marcelomendoncasoaresHigh -
Improper neutralization of string values in Serverpod's ORM allows SQL injection without any raw query APIGHSA-868m-gf4j-xr8g published
Aug 14, 2026 by marcelomendoncasoaresCritical -
Improved security for stored password hashesGHSA-r75m-26cq-mjxc published
Mar 27, 2024 by SandPodLow -
Client accepts any certificateGHSA-h6x7-r5rg-x5fw published
Mar 27, 2024 by SandPodHigh
Learn more about advisories related to serverpod/serverpod in the GitHub Advisory Database