GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
86
GitHub Actions
54
Go
4,175
Maven
5,000+
npm
5,000+
NuGet
1,019
pip
5,000+
Pub
13
RubyGems
1,102
Rust
1,421
Swift
61
Unreviewed advisories
All unreviewed
5,000+
19 advisories
Filter by severity
Cube Core is vulnerable to privilege escalation via a specially crafted request
High
CVE-2026-25958
was published
for
@cubejs-backend/server-core
(npm)
Feb 10, 2026
OpenClaw: Command hijacking via unsafe PATH handling (bootstrapping + node-host PATH overrides)
High
CVE-2026-29610
was published
for
openclaw
(npm)
Feb 18, 2026
OpenClaw's Zalouser allowlist authorization matched mutable group names by default
Moderate
GHSA-f5mf-3r52-r83w
was published
for
openclaw
(npm)
Mar 13, 2026
Claude Code has a Workspace Trust Dialog Bypass via Repo-Controlled Settings File
High
CVE-2026-33068
was published
for
@anthropic-ai/claude-code
(npm)
Mar 19, 2026
Duplicate Advisory: OpenClaw has a Trusted-proxy Control UI pairing bypass which allows unpaired node sessions
Moderate
GHSA-xh9j-mpc9-2m9p
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
Duplicate Advisory: OpenClaw ACP client has permission auto-approval bypass via untrusted tool metadata
Moderate
GHSA-rcx4-77x4-hjx5
was published
for
openclaw
(npm)
Mar 21, 2026
•
withdrawn
OpenClaw improperly parses X-Forwarded-For behind trusted proxies allows client IP spoofing in security decisions
Moderate
CVE-2026-32029
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw has a Trusted-proxy Control UI pairing bypass which allows unpaired node sessions
Moderate
CVE-2026-32057
was published
for
openclaw
(npm)
Mar 3, 2026
OpenClaw's Conflicting Tool Identity Hints Bypass Dangerous-Tool Prompting
Moderate
CVE-2026-35655
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw: Synology Chat reply delivery could be rebound through username-based user resolution.
Moderate
CVE-2026-35670
was published
for
openclaw
(npm)
Mar 26, 2026
Duplicate Advisory: OpenClaw: Google Chat Authz Bypass via Group Policy Rebinding with Mutable Space displayName
Low
GHSA-j42q-r6qx-xrfp
was published
for
openclaw
(npm)
Apr 10, 2026
•
withdrawn
OpenClaw: Google Chat Authz Bypass via Group Policy Rebinding with Mutable Space displayName
Low
CVE-2026-35617
was published
for
openclaw
(npm)
Mar 29, 2026
Duplicate Advisory: OpenClaw: Nextcloud Talk room allowlist matched colliding room names instead of stable room tokens
Low
GHSA-5f7h-p83x-5vc2
was published
for
openclaw
(npm)
Apr 10, 2026
•
withdrawn
OpenClaw: Nextcloud Talk room allowlist matched colliding room names instead of stable room tokens
Low
CVE-2026-35624
was published
for
openclaw
(npm)
Mar 26, 2026
OpenClaw: Gateway chat.send ACP-only provenance guard could be bypassed by client identity spoofing
High
CVE-2026-41299
was published
for
openclaw
(npm)
Mar 31, 2026
OpenClaw: PIP_INDEX_URL and UV_INDEX_URL bypass host exec env sanitization and redirect Python package-index traffic
High
CVE-2026-41391
was published
for
openclaw
(npm)
Apr 2, 2026
OpenClaw: diffs viewer misclassifies proxied remote requests as loopback when `allowRemoteViewer` is disabled
Moderate
CVE-2026-41403
was published
for
openclaw
(npm)
Apr 3, 2026
SillyTavern has Authentication Bypass via SSO Header Injection
Critical
CVE-2026-44649
was published
for
sillytavern
(npm)
May 12, 2026
Duplicate Advisory: BlueBubbles sender policy could match mutable conversation identifiers
Low
GHSA-8hj2-w4c9-fjfq
was published
for
openclaw
(npm)
Jun 16, 2026
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API