Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

32 advisories

Loading
Authorization Bypass Through User-Controlled Key in urijs Moderate
CVE-2022-0613 was published for urijs (npm) Feb 17, 2022
Duplicate Advisory: Improper access control in Directus Moderate
GHSA-q83v-hq3j-4pq3 was published for directus (npm) Aug 15, 2024 withdrawn
dchocoboo Credited to dchocoboo
Directus has an insecure object reference via PATH presets Moderate
CVE-2024-6534 was published for directus (npm) Aug 27, 2024
Clerk-js vulnerable to bypass of OAuth authentication flow by manipulating request at OTP verification stage Moderate
CVE-2025-63700 was published for @clerk/clerk-js (npm) Nov 20, 2025
axios-cache-interceptor Vulnerable to Cache Poisoning via Ignored HTTP Vary Header Moderate
CVE-2025-69202 was published for axios-cache-interceptor (npm) Dec 30, 2025
kishore03109 Credited to kishore03109 and arthurfiorette arthurfiorette arthurfiorette
StudioCMS has Authorization Bypass Through User-Controlled Key Moderate
CVE-2026-24134 was published for studiocms (npm) Jan 27, 2026
FilipeGaudard Credited to FilipeGaudard and Adammatthiesen Adammatthiesen Adammatthiesen
Cloudflare Agents SDK has Insecure Direct Object Reference (IDOR) via Header-Based Email Routing Moderate
CVE-2026-1664 was published for agents (npm) Feb 3, 2026
url-parse incorrectly parses hostname / protocol due to unstripped leading control characters. Moderate
CVE-2022-0691 was published for url-parse (npm) Feb 22, 2022
jhutchings1 Credited to jhutchings1, Kenny2github, y-yagi, Haxatron, and ljharb Kenny2github Kenny2github
y-yagi y-yagi Haxatron Haxatron ljharb ljharb
payload-preferences has Cross-Collection IDOR in Access Control (Multi-Auth Environments) Moderate
CVE-2026-25574 was published for payload (npm) Feb 5, 2026
s2ongmo Credited to s2ongmo
Authorization bypass in url-parse Moderate
CVE-2022-0512 was published for url-parse (npm) Feb 15, 2022
ljharb Credited to ljharb
url-parse Incorrectly parses URLs that include an '@' Moderate
CVE-2022-0639 was published for url-parse (npm) Feb 18, 2022
Haxatron Credited to Haxatron and ljharb ljharb ljharb
NocoDB Missing Ownership Validation in MCP Token Operations Moderate
CVE-2026-28361 was published for nocodb (npm) Mar 2, 2026
bugbunny-research Credited to bugbunny-research
tdjackey Credited to tdjackey
jiseoung Credited to jiseoung
OpenClaw's `system.run` env override filtering allowed dangerous helper-command pivots Moderate
GHSA-j425-whc4-4jgc was published for openclaw (npm) Mar 9, 2026
tdjackey Credited to tdjackey, SnailSploit, and zpbrent SnailSploit SnailSploit
zpbrent zpbrent
OpenClaw: Cross-account sender authorization expansion in `/allowlist ... --store` account scoping Moderate
GHSA-pjvx-rx66-r3fg was published for openclaw (npm) Mar 9, 2026
tdjackey Credited to tdjackey
OneUptime has WhatsApp Resend Verification Authorization Bypass Moderate
CVE-2026-30959 was published for @oneuptime/common (npm) Mar 10, 2026
Aryma-f4 Credited to Aryma-f4
StudioCMS: IDOR — Admin-to-Owner Account Takeover via Password Reset Link Generation Moderate
CVE-2026-32103 was published for studiocms (npm) Mar 12, 2026
FilipeGaudard Credited to FilipeGaudard and Adammatthiesen Adammatthiesen Adammatthiesen
offset Credited to offset and Adammatthiesen Adammatthiesen Adammatthiesen
OpenClaw: Channel commands could bypass account-scoped `configWrites` restrictions Moderate
GHSA-8jhh-jcqg-mj5p was published for openclaw (npm) Mar 13, 2026
tdjackey Credited to tdjackey
n8n's Source Control SSH Configuration Uses StrictHostKeyChecking=no Moderate
CVE-2026-33724 was published for n8n (npm) Mar 25, 2026
kolega-ai-dev Credited to kolega-ai-dev
OpenClaw has a Feishu allowFrom authorization bypass via display-name collision Moderate
CVE-2026-32021 was published for openclaw (npm) Mar 3, 2026
jiseoung Credited to jiseoung
OpenClaw's typed sender-key matching for toolsBySender prevents identity-collision policy bypass Moderate
CVE-2026-32039 was published for openclaw (npm) Mar 3, 2026
jiseoung Credited to jiseoung
OpenClaw ACP client has permission auto-approval bypass via untrusted tool metadata Moderate
CVE-2026-32898 was published for openclaw (npm) Feb 27, 2026
nedlir Credited to nedlir
OpenClaw: Gateway HTTP Session History Route Bypasses Operator Read Scope Moderate
CVE-2026-35657 was published for openclaw (npm) Mar 29, 2026
zpbrent Credited to zpbrent
ProTip! Advisories are also available from the GraphQL API