GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
41
GitHub Actions
42
Go
3,114
Maven
5,000+
npm
5,000+
NuGet
826
pip
4,428
Pub
12
RubyGems
988
Rust
1,171
Swift
50
Unreviewed advisories
All unreviewed
5,000+
88 advisories
Filter by severity
OpenClaw: BlueBubbles (optional plugin) pairing/allowlist mismatch when allowFrom is empty
Moderate
GHSA-jwf4-8wf4-jf2m
was published
for
openclaw
(npm)
Mar 4, 2026
OpenClaw: Hardlink alias checks could bypass workspace-only file boundaries in specific configurations
High
GHSA-3jx4-q2m7-r496
was published
for
openclaw
(npm)
Mar 4, 2026
OpenClaw's image tool bypasses tools.fs.workspaceOnly on sandbox mount paths and exfiltrates out-of-workspace images
Moderate
GHSA-q6qf-4p5j-r25g
was published
for
openclaw
(npm)
Mar 4, 2026
OpenClaw has cross-account DM pairing authorization bypass via unscoped pairing store access
Low
GHSA-vjp8-wprm-2jw9
was published
for
openclaw
(npm)
Mar 4, 2026
OpenClaw: Slack interactive callbacks could skip configured sender checks in some shared-workspace flows
High
GHSA-x2ff-j5c2-ggpr
was published
for
openclaw
(npm)
Mar 4, 2026
OpenClaw's Node role device-identity bypass allows unauthorized node.event injection
Moderate
GHSA-rv2q-f2h5-6xmg
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw has Windows Lobster shell fallback command injection in constrained fallback path
Moderate
GHSA-fg3m-vhrr-8gj6
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's Zalo group sender allowlist bypass permits unauthorized GROUP dispatch
Moderate
GHSA-534w-2vm4-89xr
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's exec allowlist wrapper analysis did not unwrap env/shell dispatch chains
High
GHSA-jj82-76v6-933r
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's Signal reaction-only status events could, in limited cases, be enqueued before access checks
Moderate
GHSA-792q-qw95-f446
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's sandbox bind validation could bypass allowed-root and blocked-path checks via symlink-parent missing-leaf paths
High
GHSA-m8v2-6wwh-r4gc
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: Zip extraction symlink traversal could write outside destination
High
GHSA-jxrq-8fm4-9p58
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's tools.exec.safeBins generic fallback allowed interpreter-style inline payload execution in allowlist mode
Low
GHSA-8mf7-vv8w-hjr2
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's Synology Chat dmPolicy=allowlist failed open on empty allowedUserIds, allowing unauthorized agent dispatch
Moderate
GHSA-gw85-xp4q-5gp9
was published
for
openclaw
(npm)
Mar 3, 2026
In OpenClaw, manually adding sort to tools.exec.safeBins could bypass allowlist approval via --compress-program
High
GHSA-4gc7-qcvf-38wg
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw has a BlueBubbles group allowlist mismatch via DM pairing-store fallback
Moderate
GHSA-25pw-4h6w-qwvm
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's voice-call Twilio replay dedupe now bound to authenticated webhook identity
Low
GHSA-gcj7-r3hg-m7w6
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: Microsoft Teams media fetch paths bypass shared SSRF guard model
Low
GHSA-7qf6-h84j-8fq4
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's non-default autoAllowSkills setting could bypass on-miss exec prompt
High
GHSA-7ff8-xjh3-mgh6
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's shell startup env injection bypasses system.run allowlist intent (RCE class)
High
GHSA-xgf2-vxv2-rrmg
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's runtime /debug override path accepted prototype-reserved keys
Low
GHSA-62f6-mrcj-v8h5
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw has a workspace-only sandbox guard mismatch for @-prefixed absolute paths
Moderate
GHSA-27cr-4p5m-74rj
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw affected by BASH_ENV / ENV startup-file injection into spawned shell commands
High
GHSA-w9cg-v44m-4qv8
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: Sandbox media fallback tmp symlink alias bypass allows host file reads outside sandboxRoot
High
GHSA-xmv6-r34m-62p4
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw Improperly Neutralizes Line Breaks in systemd Unit Generation Enables Local Command Execution (Linux)
High
GHSA-vffc-f7r7-rx2w
was published
for
openclaw
(npm)
Mar 3, 2026
ProTip!
Advisories are also available from the
GraphQL API