GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
49
GitHub Actions
50
Go
3,606
Maven
5,000+
npm
5,000+
NuGet
924
pip
4,831
Pub
13
RubyGems
1,045
Rust
1,256
Swift
53
Unreviewed advisories
All unreviewed
5,000+
136 advisories
Filter by severity
OpenClaw: Discord text `/approve` bypasses `channels.discord.execApprovals.approvers` and allows non-approvers to resolve pending exec approvals
High
CVE-2026-41303
was published
for
openclaw
(npm)
Mar 31, 2026
OpenClaw: Discord voice transcript owner-flag omission could expose owner-only tools in mixed-trust channels
Moderate
CVE-2026-32035
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: SSRF via Unguarded `fetch()` in Marketplace Plugin Download and Ollama Model Discovery
Moderate
CVE-2026-41302
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw has a CWD `.env` environment variable injection which bypasses host-env policy and allows config takeover
Critical
CVE-2026-41294
was published
for
openclaw
(npm)
Apr 1, 2026
OpenClaw: Browser interaction routes could pivot into local CDP and regain file reads
Moderate
GHSA-qmwg-qprg-3j38
was published
for
openclaw
(npm)
Apr 17, 2026
OpenClaw: Feishu webhook reads and parses unauthenticated request bodies before signature validation
Moderate
CVE-2026-35640
was published
for
openclaw
(npm)
Mar 29, 2026
OpenClaw Bypasses DM Policy Separation via Synology Chat Webhook Path Collision
Moderate
CVE-2026-35635
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw: Non-owner command-authorized sender can change the owner-only `/send` session delivery policy
Moderate
CVE-2026-35620
was published
for
openclaw
(npm)
Mar 30, 2026
OpenClaw: `browser.request` still allows `POST /reset-profile` through the `operator.write` surface
High
CVE-2026-35653
was published
for
openclaw
(npm)
Mar 30, 2026
OpenClaw: Authenticated `/hooks/wake` and mapped `wake` payloads are promoted into the trusted `System:` prompt channel
High
GHSA-jf56-mccx-5f3f
was published
for
openclaw
(npm)
Apr 9, 2026
OpenClaw: Lower-trust background runtime output is injected into trusted `System:` events, and local async exec completion misses the intended `exec-event` downgrade
High
GHSA-gfmx-pph7-g46x
was published
for
openclaw
(npm)
Apr 9, 2026
OpenClaw's config env vars allowed startup env injection into service runtime
Moderate
CVE-2026-22177
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw: OpenShell `mirror` mode can convert untrusted sandbox files into explicitly enabled workspace hooks and execute them on the host during gateway startup
Moderate
GHSA-42mx-vp8m-j7qh
was published
for
openclaw
(npm)
Apr 7, 2026
OpenClaw: `session_status` still bypasses configured `tools.sessions.visibility` for unsandboxed invocations
Moderate
GHSA-fwjq-xwfj-gv75
was published
for
openclaw
(npm)
Apr 7, 2026
OpenClaw: Unavailable local auth SecretRefs could fall through to remote credentials in local mode
Low
CVE-2026-32970
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Plugin subagent routes could bypass gateway authorization with synthetic admin scopes
Critical
CVE-2026-32916
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw's skills-install-download can be redirected outside the tools root by rebinding the validated base path
Moderate
CVE-2026-33574
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw: Node-host approvals could show misleading shell payloads instead of the executed argv
High
CVE-2026-32971
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw's system.run approvals did not bind mutable script operands across approval and execution
Moderate
CVE-2026-32921
was published
for
openclaw
(npm)
Mar 12, 2026
OpenClaw: Unbound interpreter and runtime commands could bypass node-host approval integrity
High
CVE-2026-32979
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Unrecognized script runners could bypass `system.run` approval integrity
High
CVE-2026-32978
was published
for
openclaw
(npm)
Mar 13, 2026
OpenClaw: Unbound bootstrap setup codes allow privilege escalation during pairing
High
GHSA-gg9v-mgcp-v6m7
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Host exec environment sanitization misses package, registry, Docker, compiler, and TLS override variables
Moderate
GHSA-cg7q-fg22-4g98
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Incomplete host-env-security-policy allows untrusted model to substitute compiler binaries via env overrides
High
GHSA-g8xp-qx39-9jq9
was published
for
openclaw
(npm)
Apr 3, 2026
OpenClaw: Self-Whitelisting in appendLocalMediaParentRoots Allows Arbitrary File Read & Credential Exfiltration
High
GHSA-57gh-m6rq-54cf
was published
for
openclaw
(npm)
Apr 3, 2026
ProTip!
Advisories are also available from the
GraphQL API