🤖 AI Dev Tools

Open Source Vulnerabilities Plateau in 2025: New Threats Surge Despite Fewer Alerts

GitHub reviewed just 4,101 advisories in 2025, the lowest since 2021. Don't pop the champagne—new vulnerabilities jumped 19%, and npm malware spiked 69%.

Line chart showing open source vulnerability advisories from 2021 to 2025 with CWE rankings inset

⚡ Key Takeaways

  • Reviewed advisories hit 4,101 in 2025 (lowest since 2021), but new vulnerabilities rose 19%.
  • CWE-79 (XSS) still #1; resource exhaustion and deserialization climbed fast.
  • npm malware advisories up 69%; Go ecosystem overrepresented by 6%.
Published by

DevTools Feed

Ship faster. Build smarter.

Worth sharing?

Get the best Developer Tools stories of the week in your inbox — no noise, no spam.

Originally reported by GitHub Blog

Stay in the loop

The week's most important stories from DevTools Feed, delivered once a week.