GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,606
Maven
5,000+
npm
5,000+
NuGet
924
pip
4,831
Pub
13
RubyGems
1,045
Rust
1,256
Swift
53
Unreviewed advisories
All unreviewed
5,000+
64 advisories
Filter by severity
OpenClaw: Discord voice transcript owner-flag omission could expose owner-only tools in mixed-trust channels
Moderate
CVE-2026-32035
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: MS Teams fileConsent/invoke missing conversation binding allowed cross-conversation pending-upload consumption
Moderate
GHSA-j26j-7qc4-3mrf
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw unpaired device identity can bypass operator pairing and self-assign operator scopes with shared auth
Moderate
GHSA-553v-f69r-656j
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw shell-env fallback trusted startup env and could execute attacker-influenced login-shell paths
Moderate
GHSA-5h2c-8v84-qpvr
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw has auth inconsistency on local Browser Extension Relay /extension endpoint
Moderate
GHSA-pfv7-rr5m-qmv6
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw has a Discord `allowFrom` slug-collision authorization bypass
Moderate
GHSA-4cqv-h74h-93j4
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw Loopback CDP probe can leak Gateway token to local listener
Moderate
CVE-2026-22174
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw has a Trusted-proxy Control UI pairing bypass which allows unpaired node sessions
Moderate
CVE-2026-32057
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw has a workspace-only sandbox guard mismatch for @-prefixed absolute paths
Moderate
CVE-2026-32033
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw has a BlueBubbles group allowlist mismatch via DM pairing-store fallback
Moderate
CVE-2026-32006
was published
for
openclaw
(npm)
Mar 3, 2026
In OpenClaw, manually adding sort to tools.exec.safeBins could bypass allowlist approval via --compress-program
Moderate
CVE-2026-32010
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's Synology Chat dmPolicy=allowlist failed open on empty allowedUserIds, allowing unauthorized agent dispatch
Moderate
CVE-2026-31998
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's Signal reaction-only status events could, in limited cases, be enqueued before access checks
Moderate
CVE-2026-32050
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's Zalo group sender allowlist bypass permits unauthorized GROUP dispatch
Moderate
GHSA-534w-2vm4-89xr
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw has Windows Lobster shell fallback command injection in constrained fallback path
Moderate
CVE-2026-31995
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's Node role device-identity bypass allows unauthorized node.event injection
Moderate
CVE-2026-32001
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's image tool bypasses tools.fs.workspaceOnly on sandbox mount paths and exfiltrates out-of-workspace images
Moderate
CVE-2026-32002
was published
for
openclaw
(npm)
Mar 4, 2026
OpenClaw: BlueBubbles (optional plugin) pairing/allowlist mismatch when allowFrom is empty
Moderate
CVE-2026-22170
was published
for
openclaw
(npm)
Mar 4, 2026
OpenClaw's `system.run` env override filtering allowed dangerous helper-command pivots
Moderate
GHSA-j425-whc4-4jgc
was published
for
openclaw
(npm)
Mar 9, 2026
OpenClaw's system.run allowlist approval parsing missed PowerShell encoded-command wrappers
Moderate
GHSA-3h2q-j2v4-6w5r
was published
for
openclaw
(npm)
Mar 9, 2026
OpenClaw: Cross-account sender authorization expansion in `/allowlist ... --store` account scoping
Moderate
GHSA-pjvx-rx66-r3fg
was published
for
openclaw
(npm)
Mar 9, 2026
OpenClaw: `operator.write` chat.send could reach admin-only config writes
Moderate
GHSA-hfpr-jhpq-x4rm
was published
for
openclaw
(npm)
Mar 9, 2026
OpenClaw: system.run allow-always persistence included shell-commented payload tails
Moderate
GHSA-9q2p-vc84-2rwm
was published
for
openclaw
(npm)
Mar 9, 2026
OpenClaw: Sandboxed /acp spawn requests could initialize host ACP sessions
Moderate
CVE-2026-27646
was published
for
openclaw
(npm)
Mar 9, 2026
OpenClaw's system.run approvals did not bind mutable script operands across approval and execution
Moderate
CVE-2026-32921
was published
for
openclaw
(npm)
Mar 12, 2026
ProTip!
Advisories are also available from the
GraphQL API