GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,948
Maven
5,000+
npm
5,000+
NuGet
969
pip
5,000+
Pub
13
RubyGems
1,062
Rust
1,383
Swift
56
Unreviewed advisories
All unreviewed
5,000+
31 advisories
Filter by severity
OpenClaw: MSTeams thread history bypasses sender allowlist via Graph API
Low
CVE-2026-41365
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: Device-Paired Node Skips Node Scope Gate → Host RCE.md
High
CVE-2026-41352
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Telnyx Webhook Replay Detection Bypass via Base64 Signature Re-encoding
Moderate
CVE-2026-41351
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: HTTP operator endpoints lack browser-origin validation in trusted-proxy mode
Low
CVE-2026-41347
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Matrix thread root and reply context bypass sender allowlist
Low
CVE-2026-41376
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: Tlon media downloads can bypass core safety limits and exhaust disk
Moderate
CVE-2026-41408
was published
for
openclaw
(npm)
Apr 7, 2026
OpenClaw: OpenShell Mirror Sync — Sandbox Escape via Unrestricted File Sync + Symlink Traversal
High
CVE-2026-41397
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: SSH sandbox tar upload follows symlinks, enabling arbitrary file write on remote host
High
CVE-2026-41364
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: MS Teams webhook parses body before JWT validation, enabling unauthenticated resource exhaustion
High
CVE-2026-41405
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Feishu thread history and quoted messages bypass sender allowlist
Moderate
CVE-2026-41406
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: Paired node escalates to gateway RCE via unrestricted node.event agent dispatch
High
CVE-2026-41378
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw runs Discord audio preflight transcription before member authorization
Moderate
CVE-2026-41374
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Slack thread context could include messages from non-allowlisted senders
Low
CVE-2026-41358
was published
for
openclaw
(npm)
May 4, 2026
OpenClaw: `/phone arm`/`/phone disarm` Bypasses `operator.admin` Scope Check for External Channels
Moderate
CVE-2026-41375
was published
for
openclaw
(npm)
Apr 7, 2026
OpenClaw: Host exec environment overrides miss proxy, TLS, Docker, and Git TLS controls
Moderate
CVE-2026-41330
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Telegram audio preflight transcription enables resource consumption by unauthorized senders
Moderate
CVE-2026-41331
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Sandbox escape via TOCTOU race in remote FS bridge readFile
Critical
CVE-2026-41296
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Marketplace Plugin Download Follows Redirects Without SSRF Protection
Moderate
CVE-2026-41297
was published
for
openclaw
(npm)
Apr 7, 2026
OpenClaw: Heartbeat context inheritance bypasses sandbox via senderIsOwner escalation
Critical
CVE-2026-41329
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: /pair approve command path omitted caller scope subsetting and reopened device pairing escalation
Critical
CVE-2026-33579
was published
for
openclaw
(npm)
Mar 31, 2026
OpenClaw's Nextcloud Talk webhook missing rate limiting on shared secret authentication
Moderate
CVE-2026-33580
was published
for
openclaw
(npm)
Mar 31, 2026
OpenClaw affected by SSRF via unguarded image download in fal provider
Low
CVE-2026-34504
was published
for
openclaw
(npm)
Apr 1, 2026
OpenClaw: node.pair.approve missing callerScopes validation allows low-privilege operator to approve malicious nodes
Moderate
CVE-2026-33577
was published
for
openclaw
(npm)
Apr 1, 2026
OpenClaw: Zalo channel downloads media before sender authorization
Moderate
CVE-2026-33576
was published
for
openclaw
(npm)
Mar 31, 2026
OpenClaw's message tool media parameter bypasses tool policy filesystem isolation
High
CVE-2026-33581
was published
for
openclaw
(npm)
Mar 31, 2026
ProTip!
Advisories are also available from the
GraphQL API