GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,455
Maven
5,000+
npm
5,000+
NuGet
1,090
pip
5,000+
Pub
13
RubyGems
1,135
Rust
1,509
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
43 advisories
Filter by severity
Gittensory: Missing contributor-scoped access control on profile endpoint and MCP tool leaks miner financial data
Moderate
GHSA-382c-vx95-w3p5
was published
for
@jsonbored/gittensory-mcp
(npm)
Jul 9, 2026
OpenClaw's browser act interactions could bypass private-network navigation checks
Moderate
CVE-2026-53812
was published
for
openclaw
(npm)
Jul 2, 2026
OpenClaw: Bundle MCP loopback could miss its exec denylist on session spawn
Moderate
GHSA-qh2f-99mv-mrcf
was published
for
openclaw
(npm)
Jul 2, 2026
n8n: Wrong OAuth Scope On Evaluations Test Run Creation Endpoint
Moderate
GHSA-hv7x-3x78-gx53
was published
for
n8n
(npm)
Jun 16, 2026
NocoDB: Hidden LTAR Column Exposure in Public Shared-View Relation Endpoints
Moderate
CVE-2026-47279
was published
for
nocodb
(npm)
Jun 5, 2026
Nuxt's route middleware is not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`
Moderate
CVE-2026-47200
was published
for
@nuxt/nitro-server
(npm)
May 29, 2026
@koa/router has an Access Control Bypass
Moderate
CVE-2026-9495
was published
for
@koa/router
(npm)
May 26, 2026
OpenClaw: iOS A2UI bridge trusted generic local-network pages for agent.request dispatch
Moderate
CVE-2026-41398
was published
for
openclaw
(npm)
Apr 7, 2026
Signal K Server: Unauthenticated Source Priorities Manipulation
Moderate
CVE-2026-33951
was published
for
signalk-server
(npm)
Apr 3, 2026
OpenClaw: Gateway `operator.write` can reach admin-only persisted `verboseLevel` via `chat.send` `/verbose`
Moderate
CVE-2026-41344
was published
for
openclaw
(npm)
Mar 31, 2026
OpenClaw has a Gateway HTTP /v1/models Route Bypasses Operator Read Scope
Moderate
CVE-2026-35619
was published
for
openclaw
(npm)
Mar 30, 2026
OpenClaw: Discord guild reaction ingress could bypass users and roles allowlists
Moderate
GHSA-9vvh-2768-c8vp
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Sandboxed /acp spawn requests could initialize host ACP sessions
Moderate
CVE-2026-27646
was published
for
openclaw
(npm)
Mar 9, 2026
OpenClaw's image tool bypasses tools.fs.workspaceOnly on sandbox mount paths and exfiltrates out-of-workspace images
Moderate
CVE-2026-32002
was published
for
openclaw
(npm)
Mar 4, 2026
OpenClaw's Zalo group sender allowlist bypass permits unauthorized GROUP dispatch
Moderate
GHSA-534w-2vm4-89xr
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's Synology Chat dmPolicy=allowlist failed open on empty allowedUserIds, allowing unauthorized agent dispatch
Moderate
CVE-2026-31998
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's dispatch-wrapper depth-cap mismatch can bypass shell-wrapper approval gating in system.run allowlist mode
Moderate
CVE-2026-32023
was published
for
openclaw
(npm)
Mar 3, 2026
Temporary path handling could write outside OpenClaw temp boundary
Moderate
CVE-2026-32026
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw has a sandbox network isolation bypass via docker.network=container:<id>
Moderate
CVE-2026-32038
was published
for
openclaw
(npm)
Mar 2, 2026
OpenClaw's sandboxed sessions_spawn now enforces sandbox inheritance for cross-agent spawns
Moderate
CVE-2026-32048
was published
for
openclaw
(npm)
Mar 2, 2026
n8n has an SSO Enforcement Bypass in its Self-Service Settings API
Moderate
GHSA-vjf3-2gpj-233v
was published
for
n8n
(npm)
Feb 26, 2026
OpenClaw Telegram allowlist authorization accepted mutable usernames
Moderate
CVE-2026-28480
was published
for
clawdbot
(npm)
Feb 18, 2026
OpenClaw iMessage group allowlist authorization inherited DM pairing-store identities
Moderate
CVE-2026-26328
was published
for
clawdbot
(npm)
Feb 18, 2026
OpenClaw's Chrome extension relay binds publicly due to wildcard treated as loopback
Moderate
CVE-2026-28395
was published
for
openclaw
(npm)
Feb 17, 2026
Hono has an Arbitrary Key Read in Serve static Middleware (Cloudflare Workers Adapter)
Moderate
CVE-2026-24473
was published
for
hono
(npm)
Jan 27, 2026
ProTip!
Advisories are also available from the
GraphQL API