GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
70
GitHub Actions
52
Go
3,948
Maven
5,000+
npm
5,000+
NuGet
969
pip
5,000+
Pub
13
RubyGems
1,062
Rust
1,383
Swift
56
Unreviewed advisories
All unreviewed
5,000+
32 advisories
Filter by severity
Authorization Bypass Through User-Controlled Key in urijs
Moderate
CVE-2022-0613
was published
for
urijs
(npm)
Feb 17, 2022
Duplicate Advisory: Improper access control in Directus
Moderate
GHSA-q83v-hq3j-4pq3
was published
for
directus
(npm)
Aug 15, 2024
•
withdrawn
Directus has an insecure object reference via PATH presets
Moderate
CVE-2024-6534
was published
for
directus
(npm)
Aug 27, 2024
Clerk-js vulnerable to bypass of OAuth authentication flow by manipulating request at OTP verification stage
Moderate
CVE-2025-63700
was published
for
@clerk/clerk-js
(npm)
Nov 20, 2025
axios-cache-interceptor Vulnerable to Cache Poisoning via Ignored HTTP Vary Header
Moderate
CVE-2025-69202
was published
for
axios-cache-interceptor
(npm)
Dec 30, 2025
StudioCMS has Authorization Bypass Through User-Controlled Key
Moderate
CVE-2026-24134
was published
for
studiocms
(npm)
Jan 27, 2026
Cloudflare Agents SDK has Insecure Direct Object Reference (IDOR) via Header-Based Email Routing
Moderate
CVE-2026-1664
was published
for
agents
(npm)
Feb 3, 2026
url-parse incorrectly parses hostname / protocol due to unstripped leading control characters.
Moderate
CVE-2022-0691
was published
for
url-parse
(npm)
Feb 22, 2022
payload-preferences has Cross-Collection IDOR in Access Control (Multi-Auth Environments)
Moderate
CVE-2026-25574
was published
for
payload
(npm)
Feb 5, 2026
Authorization bypass in url-parse
Moderate
CVE-2022-0512
was published
for
url-parse
(npm)
Feb 15, 2022
url-parse Incorrectly parses URLs that include an '@'
Moderate
CVE-2022-0639
was published
for
url-parse
(npm)
Feb 18, 2022
NocoDB Missing Ownership Validation in MCP Token Operations
Moderate
CVE-2026-28361
was published
for
nocodb
(npm)
Mar 2, 2026
OpenClaw: MS Teams fileConsent/invoke missing conversation binding allowed cross-conversation pending-upload consumption
Moderate
GHSA-j26j-7qc4-3mrf
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's elevated allowFrom accepted broader identity signals than specified within sender-scoped authorization
Moderate
GHSA-f6h3-846h-2r8w
was published
for
openclaw
(npm)
Mar 4, 2026
OpenClaw's `system.run` env override filtering allowed dangerous helper-command pivots
Moderate
GHSA-j425-whc4-4jgc
was published
for
openclaw
(npm)
Mar 9, 2026
OpenClaw: Cross-account sender authorization expansion in `/allowlist ... --store` account scoping
Moderate
GHSA-pjvx-rx66-r3fg
was published
for
openclaw
(npm)
Mar 9, 2026
OneUptime has WhatsApp Resend Verification Authorization Bypass
Moderate
CVE-2026-30959
was published
for
@oneuptime/common
(npm)
Mar 10, 2026
StudioCMS: IDOR — Admin-to-Owner Account Takeover via Password Reset Link Generation
Moderate
CVE-2026-32103
was published
for
studiocms
(npm)
Mar 12, 2026
StudioCMS: IDOR in User Notification Preferences Allows Any Authenticated User to Modify Any User's Settings
Moderate
CVE-2026-32104
was published
for
studiocms
(npm)
Mar 12, 2026
OpenClaw: Channel commands could bypass account-scoped `configWrites` restrictions
Moderate
GHSA-8jhh-jcqg-mj5p
was published
for
openclaw
(npm)
Mar 13, 2026
n8n's Source Control SSH Configuration Uses StrictHostKeyChecking=no
Moderate
CVE-2026-33724
was published
for
n8n
(npm)
Mar 25, 2026
OpenClaw has a Feishu allowFrom authorization bypass via display-name collision
Moderate
CVE-2026-32021
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's typed sender-key matching for toolsBySender prevents identity-collision policy bypass
Moderate
CVE-2026-32039
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw ACP client has permission auto-approval bypass via untrusted tool metadata
Moderate
CVE-2026-32898
was published
for
openclaw
(npm)
Feb 27, 2026
OpenClaw: Gateway HTTP Session History Route Bypasses Operator Read Scope
Moderate
CVE-2026-35657
was published
for
openclaw
(npm)
Mar 29, 2026
ProTip!
Advisories are also available from the
GraphQL API