Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

31 advisories

Loading
Electron: Sandboxed preload code cache can be poisoned by a compromised renderer High
CVE-2026-102677 was published for electron (npm) Sep 29, 2026
varisys Credited to varisys
Alleysira Credited to Alleysira
libp2p: Gossipsub StrictSign accepts attacker-signed messages as a victim RSA peer ID High
CVE-2026-86038 was published for @libp2p/gossipsub (npm) Sep 17, 2026
Alleysira Credited to Alleysira
Medplum: Improper Validation of Redirect URI in External Auth Callback allows Authorization Code Leakage High
CVE-2026-53728 was published for @medplum/core (npm) Aug 17, 2026
sAjibuu Credited to sAjibuu
Hexix23 Credited to Hexix23, alan-agius4, and JeanMeche alan-agius4 alan-agius4
JeanMeche JeanMeche
Budibase: Chat-Link Handoff Identity Confusion (Same-Tenant Account-Link CSRF) High
GHSA-pvcr-8mvp-w8qr was published for @budibase/server (npm) Jul 24, 2026
hypnguyen1209 Credited to hypnguyen1209
Better Auth: Account takeover via pre-account hijacking on magic-link and email-OTP sign-in High
GHSA-qq9h-g4jm-xgf3 was published for better-auth (npm) Jul 24, 2026
n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login High
GHSA-8342-988q-86cr was published for n8n (npm) Jul 22, 2026
widavies Credited to widavies
Better Auth has an account takeover issue via OAuth auto-link to unverified pre-registered email High
CVE-2026-53516 was published for better-auth (npm) Jul 7, 2026
avrmeduard Credited to avrmeduard
alan-agius4 Credited to alan-agius4, JeanMeche, and josephperrott JeanMeche JeanMeche
josephperrott josephperrott
OpenClaw: Trusted retry endpoint checks could match hostname prefixes High
GHSA-77q5-rr5v-x43q was published for openclaw (npm) Jul 2, 2026
ccy41928-del Credited to ccy41928-del
whrit Credited to whrit
json-web-token library is vulnerable to a JWT algorithm confusion attack High
CVE-2023-48238 was published for json-web-token (npm) Nov 17, 2023
PinkDraconian Credited to PinkDraconian
@hulumi/drift: Orphan reconciler accepted externally supplied execute plans High
GHSA-2ffm-hxrq-qqmm was published for @hulumi/drift (npm) May 21, 2026
OpenClaw: `fetchWithSsrFGuard` replays unsafe request bodies across cross-origin redirects High
CVE-2026-40037 was published for openclaw (npm) Apr 9, 2026
BG0ECV Credited to BG0ECV
OpenClaw: Gemini OAuth exposed the PKCE verifier through the OAuth state parameter High
CVE-2026-34511 was published for openclaw (npm) Apr 4, 2026
BG0ECV Credited to BG0ECV
fast-jwt accepts unknown `crit` header extensions (RFC 7515 violation) High
CVE-2026-35042 was published for fast-jwt (npm) Apr 3, 2026
dmbs335 Credited to dmbs335
OneUptime WhatsApp Webhook Missing Signature Verification High
CVE-2026-33143 was published for oneuptime (npm) Mar 18, 2026
n0rv-TvT Credited to n0rv-TvT
OneUptime has broken access control in GitHub App installation flow that allows unauthorized project binding High
CVE-2026-30920 was published for @oneuptime/common (npm) Mar 9, 2026
maru1009 Credited to maru1009
OpenClaw optional voice-call plugin: webhook verification may be bypassed behind certain proxy configurations High
CVE-2026-28465 was published for @clawdbot/voice-call (npm) Feb 17, 2026
0x5t Credited to 0x5t
Hono is Vulnerable to Authentication Bypass by IP Spoofing in AWS Lambda ALB conninfo High
CVE-2026-27700 was published for hono (npm) Feb 25, 2026
EdamAme-x Credited to EdamAme-x
OpenClaw allows unauthenticated discovery TXT records to steer routing and TLS pinning High
CVE-2026-26327 was published for openclaw (npm) Feb 18, 2026
simecek Credited to simecek and stanislavfortaisle stanislavfortaisle stanislavfortaisle
yueyueL Credited to yueyueL
ProTip! Advisories are also available from the GraphQL API